Limitless, Rewind and always-on recorders
Wearable and desktop recorders capture continuously, including colleagues and customers who never agreed to be recorded.
What that means for the register
This week
Prohibit on premises and in customer settings unless a lawyer has said otherwise.
What holding it is evidence for
Requirement text and artefacts from a human-verified corpus licensed to Agent Register.
Agents that execute without approval ISO 42001 A.6.2.6 · ISO 42001 A.9.4 · ISO 42001 A.6.2.8 · EU AI Act Art.14 · EU AI Act Art.26 · EU AI Act Art.12
ISO 42001 A.6.2.6 AI system operation and monitoringAI systems shall be operated and monitored according to organizational and operational requirements throughout their lifetime. Operational guidance shall be available to operators.
ISO 42001 A.9.4 Intended use of the AI systemThe organization shall ensure that the AI system is used according to the intended uses of the AI system and its accompanying documentation.
ISO 42001 A.6.2.8 AI system event loggingEvent logs shall be generated and recorded during AI system operations to enable monitoring, accountability, and incident investigation.
EU AI Act Art.14 Human oversightHigh-risk AI systems shall be designed and developed in such a way that they can be effectively overseen by natural persons during the period in which they are in use. Oversight measures shall enable persons to understand the relevant capacities and limitations and monitor operation, remain aware of...
EU AI Act Art.26 Obligations of deployers of high-risk AI systemsDeployers shall use high-risk AI systems in accordance with the IFU; assign human oversight to appropriately competent natural persons; ensure input data is relevant and sufficiently representative; monitor operation and inform the provider of risks/incidents; retain automatically generated logs for...
EU AI Act Art.12 Record-keeping (logs)High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system, ensuring a level of traceability appropriate to the intended purpose; logging capabilities for biometric remote-identification AI systems include the period of each use, the ref...
Data leaving the tenant to a model vendor ISO 42001 A.10.3 · ISO 42001 A.4.3 · ISO 42001 A.7.3 · ISO 42001 A.10.2 · EU AI Act Art.10 · EU AI Act Art.25
ISO 42001 A.10.3 SuppliersEstablish a process ensuring that the organization's use of services, products or materials provided by suppliers aligns with its approach to the responsible development and use of AI systems.
ISO 42001 A.4.3 Data resourcesAs part of identifying resources, the organization shall document information about the data resources utilized for the AI system.
ISO 42001 A.7.3 Acquisition of dataThe organization shall determine and document details about the acquisition and selection of data used in AI systems, including provenance and consent where applicable.
ISO 42001 A.10.2 Allocating responsibilitiesEnsure responsibilities across the AI system life cycle are allocated between the organization, its partners, suppliers, customers and third parties.
EU AI Act Art.10 Data and data governanceHigh-risk AI systems that make use of techniques involving the training of AI models shall use training, validation and testing data that meet the quality criteria in Art.10(2)-(5): appropriate data governance, examination for possible biases, identification of data gaps/shortcomings, statistically ...
EU AI Act Art.25 Responsibilities along the AI value chainDistributors/importers/deployers/other third parties become providers when they place on the market or put into service under their own name or trademark, substantially modify the system, or modify the intended purpose making it high-risk. The original provider shall cooperate with the new provider,...
No human in the loop by default ISO 42001 A.6.2.6 · ISO 42001 A.3.3 · ISO 42001 A.8.3 · EU AI Act Art.14 · EU AI Act Art.26
ISO 42001 A.6.2.6 AI system operation and monitoringAI systems shall be operated and monitored according to organizational and operational requirements throughout their lifetime. Operational guidance shall be available to operators.
ISO 42001 A.3.3 Reporting of concernsA process shall be established to enable reporting of concerns about AI systems' development, deployment, or use.
ISO 42001 A.8.3 External reportingThe organization shall provide mechanisms for external interested parties to report concerns or impacts.
EU AI Act Art.14 Human oversightHigh-risk AI systems shall be designed and developed in such a way that they can be effectively overseen by natural persons during the period in which they are in use. Oversight measures shall enable persons to understand the relevant capacities and limitations and monitor operation, remain aware of...
EU AI Act Art.26 Obligations of deployers of high-risk AI systemsDeployers shall use high-risk AI systems in accordance with the IFU; assign human oversight to appropriately competent natural persons; ensure input data is relevant and sufficiently representative; monitor operation and inform the provider of risks/incidents; retain automatically generated logs for...
Consumer tools on personal accounts ISO 42001 A.9.2 · ISO 42001 A.2.2 · ISO 42001 A.9.3 · EU AI Act Art.4 · EU AI Act Art.26
ISO 42001 A.9.2 Processes for responsible use of AI systemsThe organization shall define and document processes for the responsible use of AI systems, including processes for the use by employees of AI systems provided by third parties.
ISO 42001 A.2.2 AI policyThe organization shall document a policy for the development, deployment, or use of AI systems that aligns with the organization's strategic direction.
ISO 42001 A.9.3 Objectives for responsible use of AI systemThe organization shall identify and document objectives to guide the responsible use of AI systems.
EU AI Act Art.4 AI literacyProviders and deployers of AI systems must take measures to ensure, to their best extent, a sufficient level of AI literacy among their own staff and any other persons who deal with the operation and use of AI systems on their behalf. The measures must be calibrated to those persons' technical knowl...
EU AI Act Art.26 Obligations of deployers of high-risk AI systemsDeployers shall use high-risk AI systems in accordance with the IFU; assign human oversight to appropriately competent natural persons; ensure input data is relevant and sufficiently representative; monitor operation and inform the provider of risks/incidents; retain automatically generated logs for...
Do this for every tool your teams use
Paste the list and get this classification for every entry at once, with the owner column, the findings per department, and the controls the register is evidence for. Ten entries free, no account.
Build my agent register