Agent Register
Every agent · Model APIs and frameworks · Microsoft

Azure OpenAI Service

Model access hosted in your Azure subscription under the Azure terms; abuse monitoring may retain prompts unless exempted.

executes autonomously
acts on
no
human in the loop by default
no
data leaves the tenant by default
Whatever the calling code sends, inside the Azure subscription
reaches by default

What that means for the register

It executes on its own, so it needs the controls of an account that acts: a log you can read, a scope in writing, and a person who can switch it off. Data stays inside your tenant by default. Pasted with only its name it lands as control until an owner is named.

This week

Record the deployment, region and the abuse-monitoring status.

What holding it is evidence for

Requirement text and artefacts from a human-verified corpus licensed to Agent Register.

Agents that execute without approval ISO 42001 A.6.2.6 · ISO 42001 A.9.4 · ISO 42001 A.6.2.8 · EU AI Act Art.14 · EU AI Act Art.26 · EU AI Act Art.12
ISO 42001 A.6.2.6 AI system operation and monitoring

AI systems shall be operated and monitored according to organizational and operational requirements throughout their lifetime. Operational guidance shall be available to operators.

Evidence an auditor accepts: Operations runbooks; Monitoring dashboards; Incident logs
ISO 42001 A.9.4 Intended use of the AI system

The organization shall ensure that the AI system is used according to the intended uses of the AI system and its accompanying documentation.

Evidence an auditor accepts: Intended use statements; Use case approval records; Monitoring of use
ISO 42001 A.6.2.8 AI system event logging

Event logs shall be generated and recorded during AI system operations to enable monitoring, accountability, and incident investigation.

Evidence an auditor accepts: Logging standards; Log samples; Log retention policy
EU AI Act Art.14 Human oversight

High-risk AI systems shall be designed and developed in such a way that they can be effectively overseen by natural persons during the period in which they are in use. Oversight measures shall enable persons to understand the relevant capacities and limitations and monitor operation, remain aware of...

Evidence an auditor accepts: Human-oversight design (UI, controls, alerts); Oversight-personnel training and authority
EU AI Act Art.26 Obligations of deployers of high-risk AI systems

Deployers shall use high-risk AI systems in accordance with the IFU; assign human oversight to appropriately competent natural persons; ensure input data is relevant and sufficiently representative; monitor operation and inform the provider of risks/incidents; retain automatically generated logs for...

Evidence an auditor accepts: Deployer monitoring records; Logs retained at least 6 months; DPIA where applicable
EU AI Act Art.12 Record-keeping (logs)

High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system, ensuring a level of traceability appropriate to the intended purpose; logging capabilities for biometric remote-identification AI systems include the period of each use, the ref...

Evidence an auditor accepts: Logging capability design evidence; Log-retention policy aligned with the intended purpose
Raw model API access from code ISO 42001 A.6.1.3 · ISO 42001 A.6.2.2 · ISO 42001 A.6.2.4 · ISO 42001 A.10.3 · EU AI Act Art.25 · EU AI Act Art.12 · EU AI Act Art.15
ISO 42001 A.6.1.3 Processes for responsible design and development of AI systems

The organization shall define and document specific processes for the responsible design and development of AI systems.

Evidence an auditor accepts: AI development lifecycle (AI SDLC) procedure; Design review records; Stage gates and reviews
ISO 42001 A.6.2.2 AI system requirements and specification

Requirements and specifications shall be defined for new or substantially modified AI systems, including responsible AI requirements.

Evidence an auditor accepts: Requirements specifications; Acceptance criteria; Functional and non-functional requirements
ISO 42001 A.6.2.4 AI system verification and validation

AI systems shall be verified and validated, and the results documented. Verification confirms requirements are met; validation confirms intended use is achieved.

Evidence an auditor accepts: V&V plans; Test results; Acceptance reports
ISO 42001 A.10.3 Suppliers

Establish a process ensuring that the organization's use of services, products or materials provided by suppliers aligns with its approach to the responsible development and use of AI systems.

Evidence an auditor accepts: supplier assessment criteria covering responsible AI; completed assessments for AI suppliers including model, dataset and component providers; contract terms binding suppliers to the organization's AI requirements
EU AI Act Art.25 Responsibilities along the AI value chain

Distributors/importers/deployers/other third parties become providers when they place on the market or put into service under their own name or trademark, substantially modify the system, or modify the intended purpose making it high-risk. The original provider shall cooperate with the new provider,...

Evidence an auditor accepts: Documented allocation of provider status across the value chain; Cooperation agreements between original and new providers
EU AI Act Art.12 Record-keeping (logs)

High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system, ensuring a level of traceability appropriate to the intended purpose; logging capabilities for biometric remote-identification AI systems include the period of each use, the ref...

Evidence an auditor accepts: Logging capability design evidence; Log-retention policy aligned with the intended purpose
EU AI Act Art.15 Accuracy, robustness and cybersecurity

High-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and shall perform consistently in those respects throughout their lifecycle. Resilience to errors, faults and inconsistencies; protection against atte...

Evidence an auditor accepts: Accuracy/robustness measurements relevant to the intended purpose; Adversarial/data-poisoning threat modelling and mitigation; Cybersecurity controls aligned with state-of-the-art
No human in the loop by default ISO 42001 A.6.2.6 · ISO 42001 A.3.3 · ISO 42001 A.8.3 · EU AI Act Art.14 · EU AI Act Art.26
ISO 42001 A.6.2.6 AI system operation and monitoring

AI systems shall be operated and monitored according to organizational and operational requirements throughout their lifetime. Operational guidance shall be available to operators.

Evidence an auditor accepts: Operations runbooks; Monitoring dashboards; Incident logs
ISO 42001 A.3.3 Reporting of concerns

A process shall be established to enable reporting of concerns about AI systems' development, deployment, or use.

Evidence an auditor accepts: Concern reporting procedure; Whistleblower channel evidence; Concern register
ISO 42001 A.8.3 External reporting

The organization shall provide mechanisms for external interested parties to report concerns or impacts.

Evidence an auditor accepts: External reporting channels; Concern register; Public-facing contact (email, form)
EU AI Act Art.14 Human oversight

High-risk AI systems shall be designed and developed in such a way that they can be effectively overseen by natural persons during the period in which they are in use. Oversight measures shall enable persons to understand the relevant capacities and limitations and monitor operation, remain aware of...

Evidence an auditor accepts: Human-oversight design (UI, controls, alerts); Oversight-personnel training and authority
EU AI Act Art.26 Obligations of deployers of high-risk AI systems

Deployers shall use high-risk AI systems in accordance with the IFU; assign human oversight to appropriately competent natural persons; ensure input data is relevant and sufficiently representative; monitor operation and inform the provider of risks/incidents; retain automatically generated logs for...

Evidence an auditor accepts: Deployer monitoring records; Logs retained at least 6 months; DPIA where applicable

Do this for every tool your teams use

Paste the list and get this classification for every entry at once, with the owner column, the findings per department, and the controls the register is evidence for. Ten entries free, no account.

Build my agent register

Gemini API and Vertex AI · Amazon Bedrock