AI Use Case Registry: Template & Required Fields 2026
Last updated on August 10, 2026 at 14:23 PM.An AI application register is a structured overview of all AI tools deployed within an organisation, including details on purpose, accountability, risk classification, approval status, and review date. The EU AI Act sets a hard compliance deadline of 2 August 2026 for high-risk AI systems, the GDPR already requires demonstrable documentation for automated processing of personal data – and the Bitkom 2026 study shows that only 21% of companies using AI have a formal AI strategy in place. The register closes this gap between operational use and regulatory obligation. The following article provides a ready-to-use register structure for Excel, Notion, or SharePoint, complete with column logic, responsibilities, and review cadence.

Building an AI application register quickly reveals that documentation is only the visible part. Beneath it lies the question of whether the entire AI deployment actually rests on a data-protection-compliant foundation. Shadow AI – meaning AI tools circulating within the organisation without formal approval – is not a fringe issue but the real risk. How this situation can be transformed into a robust, GDPR-compliant AI governance framework through audits, clear policies, and secure integrations shows the path from mere inventory to demonstrable compliance. This is where the register and its implementation come full circle.
Why the AI documentation obligation is now an operational priority
Companies cannot afford to wait – the deadline is fixed and the fines are non-negotiable. 41% of German companies are actively using AI – double the figure from 2025. At the same time, violations of the EU AI Act carry penalties of up to €35 million or 7% of global annual turnover. The GDPR adds its own fine framework of up to €20 million or 4% of annual turnover. Any organisation running twelve AI applications today without documenting a single one is sitting on a compliance risk that can be quantified in euros.
The registration obligation under Art. 49 EU AI Act requires high-risk AI systems to be entered into the EU database before being placed on the market. The GDPR demands a Data Protection Impact Assessment for automated decision-making under Art. 35. Both obligations hit the same organisation, affect the same systems – and can be served by a single register.
EU AI Act and GDPR – where documentation obligations overlap
Both regulatory frameworks require purpose limitation, accountability, and transparency. The overlap is large enough to map into a single documentation structure rather than maintaining two parallel systems. The differences lie in the level of detail and the intended audience of the documentation.
| Requirement | EU AI Act | GDPR |
|---|---|---|
| Purpose limitation | Document intended use (Art. 9) | Define and document processing purpose (Art. 5(1)(b)) |
| Accountability | Providers and deployers with clear obligations (Art. 16, 26) | Controller as defined in Art. 4(7) |
| Transparency | Labelling obligation for AI-generated content (Art. 50) | Information obligations towards data subjects (Art. 13, 14) |
| Risk assessment | Risk management system for high-risk AI (Art. 9) | Data Protection Impact Assessment (Art. 35) |
What belongs in an AI application register? – Core fields and definitions
An AI application register needs seven mandatory fields that together carry the compliance proof. Each field answers a regulatory question: What is deployed? For what purpose? Who is accountable? What data flows through it? Is it approved? Does the output need to be labelled? When is the next review?
The seven columns in detail
- Tool/AI system: Name, version number, and provider. Without versioning, an audit cannot verify which state the system was in at the time of approval.
- Purpose: The specific use case and the data categories involved. A customer-service chatbot processes different data than a sales scoring model – the risk classification depends on it.
- Responsible person (AI Officer): Role, contact details, and decision-making authority. Without a named responsible party, there is no point of contact for supervisory authorities.
- Content type: Personal data, synthetic content, or decision support. This distinction determines whether GDPR obligations apply and which risk tier the EU AI Act assigns.
- Approval status: Draft → reviewed → approved → blocked. Only approved systems may be used in production.
Two additional fields belong in the body of each entry: The labelling decision records whether the output must be marked as AI-generated – Art. 50 EU AI Act requires this for interactions with individuals. The review date defines the next scheduled review and prevents a once-approved system from running undocumented for years.
| Tool | Purpose | Responsible | Content type | Approval status | Labelling | Review date |
|---|---|---|---|---|---|---|
| Chatbot v3.2 (Provider A) | Customer service, FAQ handling | Head of Customer Experience | Personal data (name, enquiry) | Approved | Yes – interaction with individuals | 01.10.2026 |
| Image generator v1.8 (Provider B) | Marketing visuals, social media | Head of Marketing | Synthetic content | Reviewed | Yes – synthetic media | 15.09.2026 |
| Predictive analytics model (in-house) | Sales forecasting, lead scoring | Head of Sales | Decision support, CRM data | Approved | No – no person-facing interaction | 01.01.2027 |
Excel, Notion, or SharePoint – which tool fits which company size?
The choice of tool depends on three factors: team size, existing IT landscape, and collaboration needs. A five-person team with three AI applications does not need SharePoint. A corporation with 80 systems across multiple locations will not get far with an Excel file on a network drive. This is not a technical decision – it is an organisational one.
| Criterion | Excel | Notion | SharePoint |
|---|---|---|---|
| Barrier to entry | Low – existing licence is sufficient | Medium – familiarisation with databases required | High – admin configuration needed |
| Collaboration | Limited – file conflicts with concurrent access | Good – real-time editing, comments | Very good – workflows, notifications |
| Versioning | Manual or via SharePoint storage | Automatic, page-based | Automatic, document-based |
| Access control | No granular management | Page-level, team spaces | Granular down to field level |
| Scalability | Practical up to approx. 20 entries | Practical up to approx. 100 entries | Enterprise-grade |
Worked example: effort for the initial build
A mid-sized company with 12 AI applications can calculate the effort concretely. Each entry requires research (provider, version, data flows), alignment with the business unit, and the actual documentation.
| Work step | Effort per entry | Total effort (12 entries) |
|---|---|---|
| Inventory and research | 2 hours | 24 hours |
| Alignment with business unit | 1 hour | 12 hours |
| Documentation and risk classification | 1.5 hours | 18 hours |
| Review by DPO/Compliance | 0.5 hours | 6 hours |
| Total | 5 hours | 60 hours (7.5 person-days) |
At 7.5 person-days for the initial build, we are talking about less than two working weeks for one person. This is not a transformation project – it is a sprint.
Clarifying responsibilities – who maintains the AI inventory?
Responsibility for the AI inventory does not rest with the IT department alone. The IAPP AI Governance Report shows that 77% of organisations are already working on AI governance – and that accountability is typically split between data protection, compliance, and the business units. Assigning the register solely to IT produces a technical list without risk assessment.
Three roles carry the register: The Data Protection Officer reviews each entry for GDPR compliance. The AI Officer (or Compliance Lead) is responsible for risk classification under the EU AI Act and approves or blocks systems. The business unit reports new tools, provides information on purpose and data flows, and confirms the accuracy of existing entries.
The review cadence determines whether the register stays alive or becomes outdated. Quarterly reviews are the minimum standard – supplemented by event-driven reviews when new tools are introduced, versions change, or data flows are modified. A register without a review date is a document, not a governance instrument.
Approval status and labelling decision – everyday compliance proof
A documented approval process simplifies the burden of proof towards supervisory authorities because it demonstrates that every system was consciously evaluated rather than silently tolerated. The approval status is the field in the register that turns an inventory list into a compliance record.
A register answers the question of which AI is running within the organisation. It does not yet answer the question of whether that deployment is legally sound. This is precisely where a structured assessment of AI use against data-protection-compliant foundations comes in – with audits that uncover uncontrolled shadow AI, policies that assign accountability, and integrations that secure operations. Those who treat the register as a starting point rather than an end goal come out ahead.
| Status | Meaning | Responsible | Next step |
|---|---|---|---|
| Draft | System identified, documentation started | Business unit | Handover to AI Officer |
| Reviewed | Risk classification and GDPR check completed | AI Officer + DPO | Approval decision |
| Approved | Production use permitted | AI Officer | Regular review per scheduled date |
| Blocked | Use prohibited (risk, violation, contract end) | AI Officer | Deactivation and documentation of reasons |
The labelling decision belongs to every entry. Art. 50 EU AI Act requires that individuals be informed when they interact with an AI system. This applies equally to chatbots, synthetic media, and deepfakes. The decision "labelling yes/no" is made once per system, documented in the register, and confirmed at every review.
Good to know: Even AI systems classified as low-risk are subject to transparency obligations when they interact with individuals. The labelling requirement is not tied to the high-risk classification.
Template download as a starting point – from blank page to auditable register
An AI documentation template eliminates the conceptual overhead and delivers the structure that holds up in an audit. Pre-filled columns with dropdown fields for approval status, automatic reminders for review dates, and an integrated risk matrix make the difference between an empty spreadsheet and a functional governance tool.
The practical value lies in standardisation: every business unit reports new AI systems in the same format, the AI Officer reviews against the same criteria, and the Data Protection Officer finds GDPR-relevant information in the same place. That sounds trivial – but it is precisely this triviality that is missing in organisations that treat AI governance as a project rather than a process.
A documented AI governance structure makes compliance plannable and reduces liability risk. Organisations that prefer not to build this internally can have the development supported by a specialised agency such as Crispy Content®.
How the AI application register will evolve by 2027
The Capgemini 2026 study shows that companies are allocating around 5% of their annual budget to AI. More budget means more applications; more applications mean more complex registers. What works today with twelve entries in an Excel spreadsheet will hit its limits in 2027 with 40 or 60 systems.
Three developments are emerging: First, AI discovery tools will automate the inventory process – scanning the IT landscape for AI components and flagging unknown systems. Second, registers will integrate into existing GRC platforms (Governance, Risk, Compliance), so that AI risks appear alongside IT security and data protection risks in a single interface. Third, the EU database under Art. 71 AI Act requires machine-readable formats – registers will evolve towards structured data exports that enable regulatory audits without manual preparation.
| Year | AI adoption in German companies | Year-on-year change |
|---|---|---|
| 2024 | 17% | Baseline |
| 2025 | 20% | +3 percentage points |
| 2026 | 41% | +21 percentage points (doubled) |
The doubling within a single year makes one thing clear: today's register must be built for tomorrow's scale.
Documenting AI use – the first step towards auditable AI governance
An AI application register is not bureaucratic busywork. It is the operational foundation for three things at once: compliance proof for supervisory authorities, risk management as AI penetration grows, and strategic steering of AI use across the organisation. Filling in seven columns today builds the structure on which governance decisions will stand tomorrow. Methods provide guarantees – and a register is nothing more than the method for delivering on a promise to regulators, customers, and your own organisation.
Sources
- Bitkom e.V. (2026): Künstliche Intelligenz in Deutschland – Studienbericht 2026. URL: https://www.bitkom.org/Bitkom/Publikationen/Kuenstliche-Intelligenz-in-Deutschland (accessed 20.07.2026).
- IAPP (2025): AI Governance Profession Report 2025. URL: https://iapp.org/resources/article/ai-governance-profession-report (accessed 20.07.2026).
- EU / artificialintelligenceact.eu (2024): Article 49 – Registration. Regulation (EU) 2024/1689. URL: https://artificialintelligenceact.eu/de/article/49/ (accessed 20.07.2026).
- Capgemini Research Institute (2026): The multi-year AI advantage: Building the enterprise of tomorrow. URL: https://www.capgemini.com/insights/research-library/ai-perspectives-2026/ (accessed 20.07.2026).
- GDPR Register (2026): EU AI Act Compliance 2026 – Timeline, High-Risk AI Guide. URL: https://www.gdprregister.eu/regulations/eu-ai-act-compliance/ (accessed 20.07.2026).
- WKO – Wirtschaftskammer Österreich (2025): AI Act: Pflichten für Unternehmen. URL: https://www.wko.at/digitalisierung/ai-act-eu (accessed 20.07.2026).
Gerrit Grunert
Gerrit Grunert is the founder and CEO of Crispy Content®. In 2019, he published his book "Methodical Content Marketing" published by Springer Gabler, as well as the series of online courses "Making Content." In his free time, Gerrit is a passionate guitar collector, likes reading books by Stefan Zweig, and listening to music from the day before yesterday.