AI Use-Case Governance Register
Chapter 13's obligations become operational through one unglamorous artifact: a register with a row for every AI use case, filled in at intake and updated at each review. Ten fields cover what boards, auditors, and (for EU-touching deployments) regulators ask.
| # | Field | The question it answers |
|---|---|---|
| 1 | Use case & owner | What does it do, and who is accountable by name? |
| 2 | Autonomy class | Assistant, Automation, or Agent (Chapter 7 behavioral test)? What actions can it take alone? |
| 3 | Data touched | Personal data? Confidential data? Which tier of vendor agreement covers it? |
| 4 | EU AI Act tier | Prohibited / high-risk / limited / minimal, and in which jurisdictions it operates (incl. US state exposure). |
| 5 | Injection surface | Does it process untrusted content? Does the lethal trifecta apply (Chapter 3)? |
| 6 | Eval & pass rate | Link to the A.2 eval; current pass rate; date last run. |
| 7 | Human oversight | Where is the human in the loop, and what do they see when overriding? |
| 8 | Monitoring | What is logged, who reviews it, on what cadence, and what triggers escalation? |
| 9 | Labeling | Is output disclosed as AI-generated where required (EU transparency, China labeling rules)? |
| 10 | Review & sunset | Next scheduled review; conditions for decommissioning. |
Run intake as a fifteen-minute conversation, not a compliance ambush: the goal is that filling the row is easier than avoiding it. A register like this is also the fastest possible answer to the two questions executives increasingly face from boards: "where are we using AI?" and "how do we know it is behaving?" If Chapter 14 gave you the offense, this page is the defense, and organizations that run both are the ones for which the technology compounds instead of surprises.
This template is part of the FDE Toolkit in GenAI for Business. The method behind it is in Chapter 14: Working Like a Forward Deployed Engineer.