An AI register is already partly outdated on the day it's delivered. There's a new tool, someone has extended an existing subscription with an AI feature, a team has stopped doing something that was on the list. A register is not a document you finish. It's a process that keeps running, or it grinds to a halt within a few months.
The question "how do you keep it up to date" is therefore more important than "how do you draw it up". An initial inventory is a snapshot. The value lies in what happens afterward.
The main cause is not carelessness. It's that AI spreads differently than other software. A new tool often doesn't require a purchasing process, IT approval, or a budget round. Someone signs up with a work email address and starts using it. No one is required to report that, and no one feels obliged to — especially not if the expectation is that reporting is equivalent to a ban. What happens with employees who use a tool that no one has approved determines whether those reports ever come in.
In addition, the nature of existing tools changes. A package that had no AI functionality last year may have it this year, enabled by default in an update. IT's vendor list doesn't change as a result, but the risk profile of those same tools does.
Keeping something up to date requires a recurring rhythm rather than a one-off action. That rhythm consists of a few elements that recur:
A standing question to teams, at a fixed moment, about what has been added or changed. Not as a control question, but as part of a recurring meeting — quarterly review, team meeting, performance cycle. The question must be low-threshold enough to get an honest answer.
A signal from procurement or IT management when a new subscription is taken out or an existing contract is renewed. Not every signal leads to an adjustment of the register, but every signal should be reviewed.
A reassessment of existing items at the moment the context changes: a tool gets a new feature, a team starts using an AI application for a different purpose than the one for which it was classified. How often that reassessment is needed depends on the risk level of the application and on how quickly the environment changes — more on that on the page describing how often you should reclassify.
No approach captures everything. A register that relies entirely on self-reporting will, by definition, miss what people don't report — out of ignorance, convenience, or because they don't realize a tool falls under the definition of AI. A register that relies entirely on IT signals will miss what is purchased outside of IT, which by now is the largest part of shadow AI.
The realistic approach combines both, knowing that the combination is not complete either. A well-maintained register is an approximation that comes closer to reality than no register at all, not a guarantee that everything is included.
There is also an organizational pitfall: a second process placed alongside an existing process is often simply ignored, even if it is mandatory on paper. Why that happens and how to avoid it is described on the page about why a second process alongside the existing one gets ignored. The underlying lesson is that updating holds up most easily when it's built into existing routines, not when it becomes a new, separate obligation.
An up-to-date register ultimately depends on people who understand why reporting is useful and what happens with their report. That touches on a broader point about what AI literacy means for employees: those who don't know what falls under the definition of AI also won't report what should be reported. And those who are afraid of a sanction won't report at all — not even what falls under the definition.
That also includes the conversation about company data. An employee who pastes customer data or internal documents into a free chat window is often not using a prohibited tool in the strict sense — that tool may not be listed anywhere as "prohibited". The risk lies in the use, not only in its presence on a list. What can be done about that is described on the page about what you do about company data in a free chat window.
A final element of a living register is oversight of what's already in it. An application that required human review at the time of classification can lose that review in practice without the register reflecting it. What oversight means in practice, and how that differs from oversight on paper, is described on the page about what human oversight means in practice.
An up-to-date register tells you what's running and at what risk. It doesn't tell you which part of the underlying work is actually done or taken over by AI, and which part remains with people. That question lies one level deeper: not which tools exist, but how much of a concrete task AI can handle. The work scan from FTE TO AI calculates that per task, providing a picture that complements the register — one states what exists, the other what it actually does.
Vraag maar. Governance begint bij weten wat er draait — ook wat niemand heeft goedgekeurd.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.