Register AI use cases before use, and existing uses as soon as practicable, registering the remainder progressively through governance, change or review cycles; registration is required where AI introduces elevated risk, significant operational reliance or impact on people, decisions or services, or involves personal and sensitive information, including AI that automates or materially influences consequential decisions, AI embedded in operational workflows, systems or public-facing services, autonomous or semi-autonomous AI interactions, and uses of highly sensitive or security-classified information beyond approved purposes. Routine productivity, drafting, summarisation, coding support and exploratory use of approved tools within guardrails and with meaningful human oversight generally need no registration; when unsure, start the registration (precautionary approach). Third-party suppliers using AI in their services are handled through procurement, contracting and supplier assurance instead.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.