Agent Register
Every agent · Other · various

Character.AI, Poe and other consumer chat apps

Consumer companion and multi-model chat apps have no place in a company register except as things to block; anything typed into them is gone.

drafts for a human
acts on
yes
human in the loop by default
yes
data leaves the tenant by default
Whatever the person types
reaches by default

What that means for the register

It drafts and a person decides, so the loop is real; what it can read is the question. Data leaves your tenant to the vendor by default. Pasted with only its name it lands as control until an owner is named, and the paste says whether it runs on a managed plan.

This week

Block on managed devices and networks.

What holding it is evidence for

Requirement text and artefacts from a human-verified corpus licensed to Agent Register.

Data leaving the tenant to a model vendor ISO 42001 A.10.3 · ISO 42001 A.4.3 · ISO 42001 A.7.3 · ISO 42001 A.10.2 · EU AI Act Art.10 · EU AI Act Art.25
ISO 42001 A.10.3 Suppliers

Establish a process ensuring that the organization's use of services, products or materials provided by suppliers aligns with its approach to the responsible development and use of AI systems.

Evidence an auditor accepts: supplier assessment criteria covering responsible AI; completed assessments for AI suppliers including model, dataset and component providers; contract terms binding suppliers to the organization's AI requirements
ISO 42001 A.4.3 Data resources

As part of identifying resources, the organization shall document information about the data resources utilized for the AI system.

Evidence an auditor accepts: Data inventory; Data lineage records; Datasheets
ISO 42001 A.7.3 Acquisition of data

The organization shall determine and document details about the acquisition and selection of data used in AI systems, including provenance and consent where applicable.

Evidence an auditor accepts: Data acquisition records; Provenance documentation; Consent records
ISO 42001 A.10.2 Allocating responsibilities

Ensure responsibilities across the AI system life cycle are allocated between the organization, its partners, suppliers, customers and third parties.

Evidence an auditor accepts: RACI or equivalent covering each life cycle stage and each external party; contract clauses that state who is accountable for what; evidence the allocation is reviewed when the arrangement changes
EU AI Act Art.10 Data and data governance

High-risk AI systems that make use of techniques involving the training of AI models shall use training, validation and testing data that meet the quality criteria in Art.10(2)-(5): appropriate data governance, examination for possible biases, identification of data gaps/shortcomings, statistically ...

Evidence an auditor accepts: Data governance procedures; Bias examination records and remediation; Data-quality assessment per dataset
EU AI Act Art.25 Responsibilities along the AI value chain

Distributors/importers/deployers/other third parties become providers when they place on the market or put into service under their own name or trademark, substantially modify the system, or modify the intended purpose making it high-risk. The original provider shall cooperate with the new provider,...

Evidence an auditor accepts: Documented allocation of provider status across the value chain; Cooperation agreements between original and new providers
Consumer tools on personal accounts ISO 42001 A.9.2 · ISO 42001 A.2.2 · ISO 42001 A.9.3 · EU AI Act Art.4 · EU AI Act Art.26
ISO 42001 A.9.2 Processes for responsible use of AI systems

The organization shall define and document processes for the responsible use of AI systems, including processes for the use by employees of AI systems provided by third parties.

Evidence an auditor accepts: Responsible use procedure; Acceptable use policy for AI; Training records
ISO 42001 A.2.2 AI policy

The organization shall document a policy for the development, deployment, or use of AI systems that aligns with the organization's strategic direction.

Evidence an auditor accepts: AI policy; Approval records; AI-specific policy (distinct from general IT policy)
ISO 42001 A.9.3 Objectives for responsible use of AI system

The organization shall identify and document objectives to guide the responsible use of AI systems.

Evidence an auditor accepts: Responsible use objectives; Objectives covering human oversight, escalation, prohibited uses; Linkage to risk treatment
EU AI Act Art.4 AI literacy

Providers and deployers of AI systems must take measures to ensure, to their best extent, a sufficient level of AI literacy among their own staff and any other persons who deal with the operation and use of AI systems on their behalf. The measures must be calibrated to those persons' technical knowl...

Evidence an auditor accepts: A register of the staff and contracted persons who operate or use AI systems on the organisation's behalf; Training content differentiated by role, prior technical knowledge and the deployment context; Attendance, completion and comprehension records per cohort
EU AI Act Art.26 Obligations of deployers of high-risk AI systems

Deployers shall use high-risk AI systems in accordance with the IFU; assign human oversight to appropriately competent natural persons; ensure input data is relevant and sufficiently representative; monitor operation and inform the provider of risks/incidents; retain automatically generated logs for...

Evidence an auditor accepts: Deployer monitoring records; Logs retained at least 6 months; DPIA where applicable

Do this for every tool your teams use

Paste the list and get this classification for every entry at once, with the owner column, the findings per department, and the controls the register is evidence for. Ten entries free, no account.

Build my agent register

Runway · Meta AI