Back to blog
Artificial intelligenceGovernanceETIAutomation

AI Use Register: A Step-by-Step Rollout for Mid-Sized Firms

Published on September 24, 2026by Pierre Coulanges8 min read
AI Use Register: A Step-by-Step Rollout for Mid-Sized Firms
Photo: Joshua Hoehne / Unsplash

On September 3, 2026, the French Directorate General for Enterprise reported 54 use cases and 88 solution providers within the Osez l’IA programme in its first annual review of the initiative. This acceleration creates a practical governance question: who knows exactly where AI is being used, which data it receives and who is accountable for the outcome? This playbook turns the principles covered in our article on AI governance in smaller businesses into an operational register for making decisions and prioritising investment.

The starting point

Consider an illustrative scenario: marketing uses generative AI to draft content, customer service tests a summarisation tool, HR receives applications filtered by software, and a business team is building an agent that can write data into the CRM. Management sees several initiatives but has no document connecting tools to business processes, data, human decisions and controls.

The operational target is to obtain a validated first register and an action plan within four weeks, using a schedule tailored through a structured IT project management engagement. Management should then be able to identify the active use, accountable owner, data involved, affected decision, human control and business metric without commissioning another internal survey.

An AI use register is not, by itself, a general legal requirement for every company. It is nevertheless a practical governance and evidence tool aligned with the European Commission’s AI Pact, which promotes the mapping of systems likely to be considered high-risk, and the NIST AI Risk Management Framework, which explicitly recommends mechanisms for inventorying AI systems.

Prerequisites

Before creating a spreadsheet, application or automated form, assemble the following:

  • An executive sponsor: the CEO, COO or CIO who can authorise, restrict or stop a use case.
  • A register owner: an IT project manager, CIO or transformation lead responsible for consolidating information and tracking decisions.
  • Control functions: the DPO, security lead, legal team, procurement and business representatives, involved according to the risk involved.
  • Existing sources: supplier contracts, SaaS expenses, SSO connections, OAuth permissions, the GDPR processing register, automation platforms and current projects.
  • A common decision rule: approved, approved with conditions, remediation required, restricted experiment or stopped.
  • A shared repository: a structured database, SharePoint list or internal application with access rights, change history and a named owner.

Do not automatically merge the AI register with the GDPR processing register. The French data protection authority describes the record of processing activities as a document focused on personal-data processing. An AI use may involve no personal data while still creating contractual, security or operational risks. The records should be connected when relevant, not turned into one unmanageable document.

The step-by-step process

1. Define scope and accountability

Who does what: the sponsor appoints the register owner, validates the business units in scope and defines what must be recorded: purchased tools, AI features embedded in existing software, internal models, assistants and agents able to execute actions. The project manager documents the roles in a responsibility matrix.

Realistic duration: half a day for the initial workshop, under the proposed schedule for our IT project management service.

Deliverable: a scope note identifying contributors, information sources, confidentiality rules and final decision authority. Executive accountability must be explicit: the NIST AI governance framework assigns senior leadership responsibility for decisions concerning AI system risks.

2. Discover declared and undeclared uses

Who does what: the project manager sends a short form to business managers while IT, procurement and finance reconcile the answers with contracts, expenditure, connected applications and automation platforms. Search for use cases, not just product names: the same service may be used to rewrite an email or influence candidate selection, creating very different risks.

Realistic duration: three to five working days for the initial collection, based on a project schedule linked to our automation and process optimisation service.

Deliverable: a raw inventory showing the department, purpose, tool, provider, proposed owner and actual status: idea, experiment, production or retired. Do not use employees’ individual browsing histories as a shortcut; rely on process owners and legitimate administrative records.

3. Describe the business process around each AI use

Who does what: the business owner explains the trigger, input data, task assigned to AI, output produced and subsequent human or automated action. The project manager turns this sequence into a record that the DPO, security lead and management can understand.

Realistic duration: sixty to ninety minutes per business team, using the workshop format from our process audit and mapping service.

Deliverable: a use-case record connected to the relevant process. It should identify data categories, authorised users, possible reuse of prompts by the supplier, human oversight and rollback arrangements. Our process mapping playbook provides a practical way to document actual work rather than theoretical procedures.

4. Classify risks and requirements

Who does what: the project manager brings in the DPO, security and legal teams only where their expertise is needed. The review checks prohibited practices, potential high-risk classification, transparency duties, personal and confidential data, supplier dependency and the system’s ability to act on business applications.

Realistic duration: two to three working days to consolidate the initial wave, as part of a project governance and compliance engagement.

Deliverable: a documented risk rating and required treatment measures. Some AI Act transparency obligations have applied since August 2, 2026, including duties to inform people when they directly interact with certain AI systems, as explained in the European Commission’s guidelines on AI transparency obligations. Where personal data is involved, the French data protection authority recommends risk analysis and clear governance, including a data protection impact assessment when regulatory conditions require one.

5. Make a decision for each use case

Who does what: the sponsor convenes the register owner and relevant control functions. Each use receives a status, an accountable owner and any required conditions: prohibited prompt data, mandatory human validation, an isolated environment, restricted write permissions or a supplier contract review.

Realistic duration: two hours for the initial decision meeting, under the governance model defined through our IT project management service.

Deliverable: a dated decision log stating the rationale, remediation actions, accountable person and next review trigger. An agent able to modify CRM or ERP records should not receive the same permissions as an assistant that summarises text. The French cybersecurity agency’s security recommendations for generative AI systems emphasise the caution required when integrating AI into an existing information system.

6. Turn the register into a living workflow

Who does what: the project manager and automation team create a declaration form connected to the register. The workflow routes the record to the appropriate functions, stores the decision and sends reminders for overdue actions. AI may help summarise a submission, but it must not approve itself.

Realistic duration: three to five working days for a straightforward workflow, depending on the scope covered by our Automation & Optimisation service.

Deliverable: a versioned register, an approval workflow and a management dashboard. Power Automate is a natural fit for a Microsoft 365 environment, while n8n or Make can connect heterogeneous applications and agents. Our guide to choosing between an AI suite, automation platform or custom development provides a framework for this architecture decision.

How to measure whether it works

  • Coverage ratio: validated use-case records divided by all identified uses. The denominator must include findings from IT and procurement, not only voluntary declarations.
  • Decision lead time: median duration between submission and assignment of a status. The workflow should calculate it automatically from timestamps.
  • Risk-treatment rate: completed remediation actions divided by actions that have reached their due date. An action without an owner or closure evidence remains open.
  • Value-management rate: active uses with a baseline, business indicator and post-deployment measurement divided by all active uses. The measurement method can follow our playbook for validating a profitable first AI workflow.

Mistakes that derail the project

  • Creating a software licence list: risk depends on the purpose, data and action performed, not merely on the product.
  • Running a one-off email survey: uses change as tools and teams evolve. Declaration must become part of procurement, access requests and project governance.
  • Classifying the tool before understanding the process: writing assistance and AI-supported HR decisions require different controls, even when supplied by the same vendor.
  • Publishing a policy without an operational owner: banning confidential data is ineffective if nobody controls settings, permissions and contracts.
  • Automating approval too early: stabilise the questions and decision criteria first. Automate the routing, not the legal or business judgement.
  • Promising ROI without a baseline: record workload, human effort and cost before production. Otherwise, the register can document risk but cannot prioritise investment.

Getting support

D1 Consulting can handle scoping, business interviews, register design, the risk matrix, decision governance and workflow implementation in Power Automate, n8n or Make. Our Automation & Optimisation service builds the workflow and associated agents, while our IT Project Management service organises accountability, testing, decisions and the transition to operations.

👉 Book a free 30-minute diagnostic to leave with the scope of your AI register, its accountable owners and the first workflow to implement.

An automation or digital transformation project?

Let's discuss your challenges and see how we can support you.

Contact us
AI Use Register: A Step-by-Step Rollout for Mid-Sized Firms | D1 Consulting