Intercom Fin
Answers customers directly without a human seeing the reply; with procedures it can also take actions such as refunds or account changes through integrations. Its answers are your statements to customers.
What that means for the register
This week
Review the procedures it can execute and set a handover rule for anything financial or account-changing.
What holding it is evidence for
Requirement text and artefacts from a human-verified corpus licensed to Agent Register.
Agents that execute without approval ISO 42001 A.6.2.6 · ISO 42001 A.9.4 · ISO 42001 A.6.2.8 · EU AI Act Art.14 · EU AI Act Art.26 · EU AI Act Art.12
ISO 42001 A.6.2.6 AI system operation and monitoringAI systems shall be operated and monitored according to organizational and operational requirements throughout their lifetime. Operational guidance shall be available to operators.
ISO 42001 A.9.4 Intended use of the AI systemThe organization shall ensure that the AI system is used according to the intended uses of the AI system and its accompanying documentation.
ISO 42001 A.6.2.8 AI system event loggingEvent logs shall be generated and recorded during AI system operations to enable monitoring, accountability, and incident investigation.
EU AI Act Art.14 Human oversightHigh-risk AI systems shall be designed and developed in such a way that they can be effectively overseen by natural persons during the period in which they are in use. Oversight measures shall enable persons to understand the relevant capacities and limitations and monitor operation, remain aware of...
EU AI Act Art.26 Obligations of deployers of high-risk AI systemsDeployers shall use high-risk AI systems in accordance with the IFU; assign human oversight to appropriately competent natural persons; ensure input data is relevant and sufficiently representative; monitor operation and inform the provider of risks/incidents; retain automatically generated logs for...
EU AI Act Art.12 Record-keeping (logs)High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system, ensuring a level of traceability appropriate to the intended purpose; logging capabilities for biometric remote-identification AI systems include the period of each use, the ref...
Broad system reach or write access to a system of record ISO 42001 A.4.4 · ISO 42001 A.4.5 · ISO 42001 A.6.2.5 · ISO 42001 A.5.2 · EU AI Act Art.15 · EU AI Act Art.9
ISO 42001 A.4.4 Tooling resourcesThe organization shall document information about the tooling resources utilized for the AI system.
ISO 42001 A.4.5 System and computing resourcesThe organization shall document information about the system and computing resources utilized.
ISO 42001 A.6.2.5 AI system deploymentThe organization shall document a deployment plan and ensure requirements are met before deployment.
ISO 42001 A.5.2 AI system impact assessment processThe organization shall establish a process to assess the potential consequences of the AI system for individuals or groups and societies.
EU AI Act Art.15 Accuracy, robustness and cybersecurityHigh-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and shall perform consistently in those respects throughout their lifecycle. Resilience to errors, faults and inconsistencies; protection against atte...
EU AI Act Art.9 Risk management systemProviders shall establish, implement, document and maintain a risk management system as a continuous iterative process planned and run throughout the entire lifecycle of a high-risk AI system, including identification and analysis of known and reasonably foreseeable risks, estimation/evaluation of r...
Customer-facing or people-affecting without supervision ISO 42001 A.8.2 · ISO 42001 A.5.4 · ISO 42001 A.8.4 · EU AI Act Art.50 · EU AI Act Art.6 · EU AI Act Art.86 · EU AI Act Art.27
ISO 42001 A.8.2 System documentation and information for usersThe organization shall determine and provide the necessary information for users of the AI system.
ISO 42001 A.5.4 Assessing AI system impact on individuals or groupsThe organization shall assess and document the potential impacts of AI systems to individuals or groups of individuals throughout the system's life cycle.
ISO 42001 A.8.4 Communication of incidentsThe organization shall determine and document a plan for communicating incidents to relevant interested parties.
EU AI Act Art.50 Transparency obligations for providers and deployers of certain AI systemsProviders and deployers of certain AI systems (incl those interacting with natural persons, emotion recognition, biometric categorisation, generative AI producing synthetic content, deepfakes, and AI-generated/manipulated text for public-interest information) shall inform users that they are interac...
EU AI Act Art.6 Classification rules for high-risk AI systemsDetermine and record, for each AI system, whether it is high-risk. A system is high-risk where it is intended to be used as a safety component of, or is itself, a product covered by the Union harmonisation legislation listed in Annex I and that product must undergo third-party conformity assessment,...
EU AI Act Art.86 Right to explanation of individual decision-makingA deployer must, at the request of an affected person who has been subject to a decision the deployer took on the basis of the output of an Annex III high-risk AI system other than one listed under Annex III point 2, and which produces legal effects or similarly significantly affects that person in ...
EU AI Act Art.27 Fundamental rights impact assessment for high-risk AI systemsBefore deploying a high-risk AI system referred to in Art.6(2) (Annex III), public-law-governed deployers (and certain private deployers providing public services + financial services) shall perform a fundamental rights impact assessment (FRIA) describing the deployment context, the categories of af...
Data leaving the tenant to a model vendor ISO 42001 A.10.3 · ISO 42001 A.4.3 · ISO 42001 A.7.3 · ISO 42001 A.10.2 · EU AI Act Art.10 · EU AI Act Art.25
ISO 42001 A.10.3 SuppliersEstablish a process ensuring that the organization's use of services, products or materials provided by suppliers aligns with its approach to the responsible development and use of AI systems.
ISO 42001 A.4.3 Data resourcesAs part of identifying resources, the organization shall document information about the data resources utilized for the AI system.
ISO 42001 A.7.3 Acquisition of dataThe organization shall determine and document details about the acquisition and selection of data used in AI systems, including provenance and consent where applicable.
ISO 42001 A.10.2 Allocating responsibilitiesEnsure responsibilities across the AI system life cycle are allocated between the organization, its partners, suppliers, customers and third parties.
EU AI Act Art.10 Data and data governanceHigh-risk AI systems that make use of techniques involving the training of AI models shall use training, validation and testing data that meet the quality criteria in Art.10(2)-(5): appropriate data governance, examination for possible biases, identification of data gaps/shortcomings, statistically ...
EU AI Act Art.25 Responsibilities along the AI value chainDistributors/importers/deployers/other third parties become providers when they place on the market or put into service under their own name or trademark, substantially modify the system, or modify the intended purpose making it high-risk. The original provider shall cooperate with the new provider,...
No human in the loop by default ISO 42001 A.6.2.6 · ISO 42001 A.3.3 · ISO 42001 A.8.3 · EU AI Act Art.14 · EU AI Act Art.26
ISO 42001 A.6.2.6 AI system operation and monitoringAI systems shall be operated and monitored according to organizational and operational requirements throughout their lifetime. Operational guidance shall be available to operators.
ISO 42001 A.3.3 Reporting of concernsA process shall be established to enable reporting of concerns about AI systems' development, deployment, or use.
ISO 42001 A.8.3 External reportingThe organization shall provide mechanisms for external interested parties to report concerns or impacts.
EU AI Act Art.14 Human oversightHigh-risk AI systems shall be designed and developed in such a way that they can be effectively overseen by natural persons during the period in which they are in use. Oversight measures shall enable persons to understand the relevant capacities and limitations and monitor operation, remain aware of...
EU AI Act Art.26 Obligations of deployers of high-risk AI systemsDeployers shall use high-risk AI systems in accordance with the IFU; assign human oversight to appropriately competent natural persons; ensure input data is relevant and sufficiently representative; monitor operation and inform the provider of risks/incidents; retain automatically generated logs for...
Do this for every tool your teams use
Paste the list and get this classification for every entry at once, with the owner column, the findings per department, and the controls the register is evidence for. Ten entries free, no account.
Build my agent registerLimitless, Rewind and always-on recorders · Zendesk AI agents