Deployed AI systems and providers are registered and classified.
Baseline
Applies to every organization that uses AI, regardless of size or sector.
Why
AI enters organizations in many ways; it can be procured, employees can sign up for AI tooling directly, it can be integrated into existing tools by suppliers, etc. This may lead to a situation in which AI tools are used without the organization's approval, bypassing security and privacy requirements in place. If multiple rules regarding what data may enter which AI are in place, the absence of a central register may lead to confusion and questions.
How
Registers of AI systems should contain each system's name, provider, and what kinds of data may be processed in this system (if all AI systems follow the same rules, this can be stated once). The register should ideally be integrated into existing software/IT registers and be updated as part of the organization's existing IT inventory processes. Unapproved AI systems ('Shadow AI') found within the organization should be logged alongside unapproved platforms or software ('Shadow IT').
Sources
- NIST AI RMF GOVERN 1.6
- ISO/IEC 42001 A.4.3
- ISO/IEC 42001 A.4.4