Registry
Planned content
  • Tool name, vendor
  • Approved use case
  • Risk tier, 1 Low to 4 Prohibited
  • Permitted access level, approved user roles
  • Data classes permitted, specific prohibitions
  • Tool owner
  • Approval date, next review date
  • Status: approved, de-listed, prohibited
Deliberately open. §5.2.B makes every employee responsible for checking the registry before using any AI tool, so read access is not behind CISO access. Editing is.