AI systems register — deployment status, risk classification, human involvement and the derived approval position of ADM-flagged privacy subjects.

Last updated: August 06, 2026 by Steve

AI Systems Register Report

The AI Systems Register report is the tenant-wide inventory of automated decision-making: every privacy subject whose type is flagged as an AI/ADM system — deployment status, risk classification, human involvement, mandatory-control gaps, and whether the system is currently approved. It answers, without opening a single subject, "which of our AI systems can operate right now, and which can't."

AI systems register report

What This Report Shows

For every subject whose subject type is marked as an automated decision-making (ADM) system:

  • Deployment status — where the system sits in its lifecycle (before production, deployed, retired, and the states in between).
  • Risk classification — the pack-seeded tier the system has been assigned, from the generic four-tier set or a statutory class from your jurisdiction packs.
  • Human involvement — the recorded level of human oversight in the system's decisions.
  • Mandatory-control gaps — controls linked to the subject as Mandatory that aren't yet marked Implemented in the Controls library.
  • The derived approval position — see below.

The Derived Approval Position

A system's approval status is never typed in — it is derived: a system is "approved" exactly while an assessment on its subject is In Effect, and nothing else. The moment the governing assessment lapses, is superseded, or was never completed, the system falls out of approval automatically. This keeps the register honest — approval can't drift out of sync with the assessment record because there's nothing to edit separately; re-running or updating the assessment is the only way to change it.

Reading the As-Of Banner

Like the other register reports, AI Systems Register describes a current position, not activity inside the period selected at the top of the panel — a system whose assessment lapsed last quarter is unapproved today regardless of what date range is showing.

Who Uses This Report

This report is built for AI governance work: the office (privacy, security, or a dedicated AI governance function) that needs a single defensible answer to "what automated decision-making is running, under what oversight, and is it authorized." It is also the natural source for ADM directive reporting — the kind of inventory obligations like Canada's Directive on Automated Decision-Making or an EU AI Act system inventory expect an organization to be able to produce on demand.

  • Privacy Subject Details — the AI/ADM system register section on an individual subject, including its data-source inventory.
  • Privacy Subjects — the subject directory, and where a type is flagged as an ADM system.
  • Controls Library — the shared control catalogue mandatory-control gaps are measured against.
  • Reports — the reports menu this report opens from.