Claude Code
A terminal agent that reads, edits and runs. Every file write and shell command asks for permission by default; permissions can be granted per tool, per session or turned off. What it reads is sent to the model provider.
What that means for the register
This week
Decide which permission mode is allowed on machines with production access and put it in the developer standard.
What holding it is evidence for
Requirement text and artefacts from a human-verified corpus licensed to Agent Register.
Broad system reach or write access to a system of record ISO 42001 A.4.4 · ISO 42001 A.4.5 · ISO 42001 A.6.2.5 · ISO 42001 A.5.2 · EU AI Act Art.15 · EU AI Act Art.9
ISO 42001 A.4.4 Tooling resourcesThe organization shall document information about the tooling resources utilized for the AI system.
ISO 42001 A.4.5 System and computing resourcesThe organization shall document information about the system and computing resources utilized.
ISO 42001 A.6.2.5 AI system deploymentThe organization shall document a deployment plan and ensure requirements are met before deployment.
ISO 42001 A.5.2 AI system impact assessment processThe organization shall establish a process to assess the potential consequences of the AI system for individuals or groups and societies.
EU AI Act Art.15 Accuracy, robustness and cybersecurityHigh-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and shall perform consistently in those respects throughout their lifecycle. Resilience to errors, faults and inconsistencies; protection against atte...
EU AI Act Art.9 Risk management systemProviders shall establish, implement, document and maintain a risk management system as a continuous iterative process planned and run throughout the entire lifecycle of a high-risk AI system, including identification and analysis of known and reasonably foreseeable risks, estimation/evaluation of r...
Data leaving the tenant to a model vendor ISO 42001 A.10.3 · ISO 42001 A.4.3 · ISO 42001 A.7.3 · ISO 42001 A.10.2 · EU AI Act Art.10 · EU AI Act Art.25
ISO 42001 A.10.3 SuppliersEstablish a process ensuring that the organization's use of services, products or materials provided by suppliers aligns with its approach to the responsible development and use of AI systems.
ISO 42001 A.4.3 Data resourcesAs part of identifying resources, the organization shall document information about the data resources utilized for the AI system.
ISO 42001 A.7.3 Acquisition of dataThe organization shall determine and document details about the acquisition and selection of data used in AI systems, including provenance and consent where applicable.
ISO 42001 A.10.2 Allocating responsibilitiesEnsure responsibilities across the AI system life cycle are allocated between the organization, its partners, suppliers, customers and third parties.
EU AI Act Art.10 Data and data governanceHigh-risk AI systems that make use of techniques involving the training of AI models shall use training, validation and testing data that meet the quality criteria in Art.10(2)-(5): appropriate data governance, examination for possible biases, identification of data gaps/shortcomings, statistically ...
EU AI Act Art.25 Responsibilities along the AI value chainDistributors/importers/deployers/other third parties become providers when they place on the market or put into service under their own name or trademark, substantially modify the system, or modify the intended purpose making it high-risk. The original provider shall cooperate with the new provider,...
Do this for every tool your teams use
Paste the list and get this classification for every entry at once, with the owner column, the findings per department, and the controls the register is evidence for. Ten entries free, no account.
Build my agent register