One register entry, every register.
Fill one entry for an AI system or an agent. It is checked against the published schema, kept in a register in this browser, exported as JSON, CSV or a Markdown public summary, and mapped field by field to the UK ATRS, a Canada AIA, the EU database, a model card and an ISO/IEC 42001 SoA.
Indicative, not legal advice and not a conformity claim. Nothing you enter leaves your browser.
JavaScript is off or has not loaded, so the form, the checks, the register and the exports are not available. The questions, the criteria and the guide below still work as a worksheet you can read and fill in by hand.
Built from 04. The stack (five layers) of the Body of Knowledge. Runs entirely in this page: no account and no upload.
One task from the everyday practice of AI governance, defined and compared.
Fix these fields
This entry
| Field | This entry | UK ATRS v4.0 | Canada AIA | EU database (Annex VIII) | Model or system card | ISO/IEC 42001 SoA (verify) |
|---|
The register
Entries you add stay in this browser (local storage) until you clear them; nothing is sent anywhere. Import a register exported earlier, or a CSV from a spreadsheet, to add entries in bulk; each one is checked against its schema.
| Id | Name | Kind | Checks | Actions |
|---|
No entries yet. Fill the form and choose "Add to the register", or import a file.
A JSON record, a list of records or a register exported here; or a CSV with one entry per row. Read in this browser and added to the register.
Import report
How to use it
- Choose what you are registering: an AI system or an agent. Each kind has its own published schema, and the entry is checked against it. The entry is the anchor every other record of the system is filed against, the inventory of Layer 02 [9].
- Fill the core first: id, version, owner, scope and expiry are required. The deploy pipeline is the natural writer of those fields; intake adds the classification.
- Fill the public record once if the system appears in any public register: the crosswalk below shows where each of its fields goes.
- Choose "Check the entry". Problems are listed at the top, each linked to its field. Then add the entry to the register, download it, or start the next one.
By hand, without JavaScript
Use the human templates, which name every field with its description:
ai system entry template (schema: ai-system-register-entry.v1.json
)
and agent entry template (schema: agent-register-entry.v1.json
)
. The field lists below follow the form's sections.
AI system entry: 42 fields in 5 sections
Identity and ownership
- Registry id (required):
id - Version (required):
version - Name :
name - Accountable owner (team or role) (required):
owner - Entry expires on (required):
expiry - Last reviewed on :
last_reviewed - Use-case record id :
use_case_record
Purpose and scope
- Intended purpose :
purpose - Declared scope (required):
scope - Kind of AI artefact :
system_type - Lifecycle stage :
lifecycle_stage - People affected :
affected_persons - Where it is used :
jurisdictions - Processes personal data :
personal_data - Human oversight mode :
human_oversight
Classification and registration
- Role under the EU AI Act :
role - EU AI Act category :
risk_classification.eu_ai_act_category - Annex III point relied on :
risk_classification.annex_iii_point - Internal risk tier :
risk_classification.internal_tier - Why this classification :
risk_classification.rationale - Signed classification decision (link) :
risk_classification.classification_record - Decided on :
risk_classification.decided_at - Registration in the EU database applies :
eu_database_registration.required - EU database registration id :
eu_database_registration.registration_id - Registered on :
eu_database_registration.registered_at
Components and evidence
- Components :
components - AIBOM (link) :
aibom - Evidence links :
evidence
Public record
- Responsible organisation :
public_record.organisation - Contact email (a role mailbox) :
public_record.contact_email - Address and other contact details :
public_record.address - Public web page :
public_record.website_url - One-sentence description :
public_record.one_sentence_description - Plain-language description :
public_record.description - Information used (data, inputs) and operating logic :
public_record.data_and_logic - Trade name and unambiguous reference :
public_record.trade_name - Market status :
public_record.market_status - Region whose public it affects :
public_record.region - Authorised representative :
public_record.authorised_representative - Notified-body certificate :
public_record.certificate - EU declaration of conformity (link) :
public_record.declaration_of_conformity - Electronic instructions for use (link) :
public_record.instructions_for_use
Agent entry: 46 fields in 6 sections
Identity and ownership
- Agent id (required):
id - Version (required):
version - Name :
name - Accountable owner (team) (required):
owner - Entry expires on (required):
expiry - Status :
status - First registered at :
registered_at
Purpose, scope and autonomy
- What the agent is for :
purpose - Declared scope (required):
scope - Parent AI system (registry id) :
parent_system - Base models :
base_models - Highest autonomy allowed :
autonomy_level - Action log location and retention :
logging
Workload identity
- Identity type :
workload_identity.type - Identifier :
workload_identity.identifier - Issuer :
workload_identity.issuer - Credential lifetime (seconds) :
workload_identity.credential_ttl_seconds
Tools, data and delegation
- Tools :
tools - Data access :
data_access - May create sub-agents :
delegation.can_spawn_agents - May delegate to (agent ids) :
delegation.can_delegate_to
Oversight, limits and kill switch
- Oversight mode :
human_oversight.mode - Actions that always need approval :
human_oversight.approval_required_for - Overseer role :
human_oversight.overseer_role - Spend limit currency (ISO 4217) :
spend_limit.currency - Spend limit amount :
spend_limit.amount - Spend limit period :
spend_limit.period - Kill switch: how the agent is stopped :
kill_switch.mechanism - Kill switch: who can pull it :
kill_switch.owner - Kill switch: last tested on :
kill_switch.last_drill - Runtime policy cards (ids) :
runtime_policies - Eval suites that gate releases (ids) :
eval_suites
Public record
- Responsible organisation :
public_record.organisation - Contact email (a role mailbox) :
public_record.contact_email - Address and other contact details :
public_record.address - Public web page :
public_record.website_url - One-sentence description :
public_record.one_sentence_description - Plain-language description :
public_record.description - Information used (data, inputs) and operating logic :
public_record.data_and_logic - Trade name and unambiguous reference :
public_record.trade_name - Market status :
public_record.market_status - Region whose public it affects :
public_record.region - Authorised representative :
public_record.authorised_representative - Notified-body certificate :
public_record.certificate - EU declaration of conformity (link) :
public_record.declaration_of_conformity - Electronic instructions for use (link) :
public_record.instructions_for_use
One record, five regimes
Each regime asks for much the same facts under its own names. Write them once in the register, then copy them across with this crosswalk. Field names are copied from each source as of 2026-09-24; an empty cell means the regime has no field for it. The mapping is illustrative, not a claim of conformity.
- UK ATRS, template v4.0 [3]: Tier 1 (Section 1, Summary information, for the general public) has four fields, 1.1 Name, 1.2 Description, 1.3 Website URL and 1.4 Contact email; Section 0 holds the record's metadata (0.1 Title to 0.5 One sentence description); Tier 2 (sections 2.1 to 2.5) is for specialist readers.
- Canada AIA [4]: the Project Details questions and the section names of the questionnaire. Its answers produce an impact level (I to IV) under the Directive on Automated Decision-Making [5], which is the regime's own classification.
- EU database, Annex VIII of the EU AI Act
[1]: Section A for providers of high-risk systems
(
Art. 49(1)), Section B for providers relying on theArt. 6(3)filter (Art. 49(2)) and Section C for deployers that register underArt. 49(3). The Digital Omnibus deleted Section B points 7 (summary of grounds) and 9 (Member States) [2]. - Model or system card: the Hugging Face model card template headings [6] and the CycloneDX 1.7 model card fields [7]; the model card builder writes both.
- ISO/IEC 42001 Statement of Applicability [8]: the SoA lists the Annex A controls with the justification for including or excluding each and whether it is implemented (verify the clause wording). A register entry does not make an SoA; it supplies the evidence and the justification for the rows named in the last column.
| Register field | UK ATRS v4.0 | Canada AIA | EU database (Annex VIII) | Model or system card | ISO/IEC 42001 SoA (verify) |
|---|---|---|---|---|---|
| Name name | 0.1 Title; 1.1 Name | Project Title | A.4, B.4 trade name and unambiguous reference | HF "Model Card for {model_id}"; CycloneDX component name | No direct field |
| Registry id id | No direct field | Project ID from IT Plan | A.4, B.4 reference allowing identification and traceability | CycloneDX component bom-ref | No direct field |
| Version version | 2.4.2.2 Model version | No direct field | A.4 (part of the unambiguous reference) | CycloneDX component version | No direct field |
| One-sentence description public_record.one_sentence_description | 0.5 One sentence description | No direct field | No direct field | HF model summary (the line under the title) | No direct field |
| Plain-language description public_record.description | 1.2 Description; 2.2.1 Detailed description | Provide a project description | A.5 description of the intended purpose and of the components and functions | HF "Model Description"; CycloneDX component description | No direct field |
| Intended purpose purpose | 1.2 Description (what the tool is, why it is used) | Reasons for Automation (section) | A.5, B.5 intended purpose | HF "Direct Use"; CycloneDX modelCard.considerations.useCases | A.9 row (intended use): justification |
| Responsible organisation public_record.organisation | 0.2 Organisation name; 2.1.1 Organisation or department | Department | A.1, B.1 provider; C.1 deployer (name, address, contact details) | HF "Developed by"; CycloneDX component supplier | No direct field |
| Address and contact details public_record.address | No direct field | No direct field | A.1, B.1, C.1 (address and contact details); A.2, B.2, C.2 for whoever submits on the provider's or deployer's behalf | No direct field | No direct field |
| Contact email public_record.contact_email | 1.4 Contact email | No direct field | A.1, B.1, C.1 (contact details) | HF "Model Card Contact" | No direct field |
| Public web page public_record.website_url | 1.3 Website URL | No direct field | A.13 URL for additional information (optional) | HF "Model Sources"; CycloneDX externalReferences (website) | No direct field |
| Accountable owner owner | 2.1.2 Team; 2.1.3 Senior responsible owner | Name of ADM responsible for the program; Branch | No direct field | HF "Model Card Authors" | A.3 row (roles and responsibilities): owner |
| Lifecycle stage lifecycle_stage | 0.3 Phase | Project Phase (Design or Implementation) | No direct field | No direct field | A.6 row (life cycle): implementation status |
| Market status public_record.market_status | No direct field | No direct field | A.7, B.8 status of the AI system | No direct field | No direct field |
| Region public_record.region | 0.4 Region | No direct field | No direct field | No direct field | No direct field |
| Where it is used jurisdictions | No direct field | No direct field | A.10 Member States (the B.9 list was deleted by Reg. (EU) 2026/1744) | HF "Language(s)" only for languages, not places | No direct field |
| EU AI Act classification risk_classification.eu_ai_act_category + risk_classification.annex_iii_point | No direct field | Impact level I to IV, from the Risk Profile and Impact Assessment answers | Section A (high-risk) or Section B (Art. 6(3) filter); B.6 conditions relied on | No direct field | Justification for inclusion or exclusion of controls |
| Why this classification risk_classification.rationale | No direct field | No direct field | B.6 (the B.7 summary of grounds was deleted by Reg. (EU) 2026/1744) | No direct field | Justification for inclusion or exclusion of controls |
| Information used and operating logic public_record.data_and_logic | 2.4.1.2 System-level input; 2.4.1.3 System-level output; 2.4.3.1 Development data description | About the Data; About the Algorithm (sections) | A.6 information used (data, inputs) and operating logic | HF "Training Data"; CycloneDX modelCard.modelParameters (datasets, inputs, outputs) | A.7 row (data for AI systems): evidence |
| Components and AIBOM components + aibom | 2.4.1.5 Models; 2.1.4 Third party involvement | About The System: "Who developed the system?" | No direct field | CycloneDX components (the ML-BOM itself) | A.4 row (resources) and A.10 row (suppliers): evidence |
| Human oversight mode human_oversight | 2.3.2 Human review | De-risking and Mitigation Measures (section) | A.12 via the instructions for use | System card: human oversight measures (Art. 13(3)(d)) | A.9 row (use of AI systems): evidence |
| People affected affected_persons | 2.5.2 Risks and mitigations | Impact Assessment (section) | C.4 summary of the FRIA findings (deployers) | CycloneDX modelCard.considerations.fairnessAssessments (groupAtRisk) | A.5 row (impact assessment): evidence |
| Processes personal data personal_data | 2.4.3.4 Sensitive attributes; 2.4.4.2 Sensitive attributes | About the Data (section) | C.5 summary of the DPIA (deployers, where applicable) | No direct field | A.7 row (data for AI systems): justification |
| Trade name public_record.trade_name | No direct field | No direct field | A.4, B.4 trade name | No direct field | No direct field |
| Authorised representative public_record.authorised_representative | No direct field | No direct field | A.3, B.3 authorised representative | No direct field | No direct field |
| Notified-body certificate public_record.certificate | No direct field | No direct field | A.8 certificate type, number, expiry and notified body; A.9 scanned copy | No direct field | No direct field |
| EU declaration of conformity public_record.declaration_of_conformity | No direct field | No direct field | A.11 copy of the EU declaration of conformity | No direct field | No direct field |
| Instructions for use public_record.instructions_for_use | No direct field | No direct field | A.12 electronic instructions for use (not for Annex III points 1, 6 and 7) | System card: instructions for use (Art. 13) | A.8 row (information for interested parties): evidence |
| EU database registration id eu_database_registration.registration_id | No direct field | No direct field | The registration itself; C.3 URL of the provider's entry (deployers) | No direct field | No direct field |
| Evidence links evidence | 2.5.1 Impact assessments | No direct field | C.4 FRIA summary and C.5 DPIA summary (deployers) | HF "More Information"; CycloneDX externalReferences | Implementation status and evidence of the applicable controls |
Bulk import and export
- JSON. One record, a list of records, or an object with an
entrieslist. A record's$schemasays which kind it is; without one, agent-only fields (workload identity, tools, kill switch) mark an agent. - CSV (RFC 4180). The header row holds the field names, nested ones with dots
(
risk_classification.internal_tier,public_record.contact_email); an optionalkindcolumn sayssystemoragent. A list of text goes in one cell, separated by;; a list of records (components, tools, data access) goes in one cell as JSON. Booleans readtrue/falseoryes/no. - The register CSV export uses the same shape, so an export imports back unchanged. Exported text that a spreadsheet would run as a formula gets a leading apostrophe, which the import removes.
- Every imported entry is checked: the import report lists each entry that does not validate, with its first problems, and the register table shows the count for every entry.
What this is not
It is not a registration in the EU database, an ATRS submission or a completed AIA: each regime's own form and process decide. The crosswalk says where a field goes; it does not say that a regime applies to your system. Drafts stay in this browser and are not in the link you copy, because an entry can hold internal detail. The mappings are illustrative, not a claim of conformity.
Sources
- [1] Regulation (EU) 2024/1689 (Artificial Intelligence Act), Art. 49 (registration) and Annex VIII, Sections A (providers of high-risk systems, points 1 to 13), B (systems relying on Art. 6(3), points 1 to 9) and C (deployers, points 1 to 5), consolidated text of 2026-07-27. EUR-Lex refused automated access on 2026-09-24; the wording was read on the Commission's AI Act Service Desk, which reproduces the Official Journal text. Publications Office of the EU (EUR-Lex). 2026-07-27. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#anx_VIII (verified: primary)
- [2] Regulation (EU) 2026/1744 (Digital Omnibus on AI), deleting Annex VIII, Section B, points 7 (summary of grounds) and 9 (Member States). Publications Office of the EU (EUR-Lex). 2026-07-24. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng (verified: primary)
- [3] Algorithmic Transparency Recording Standard (ATRS) template, version 4.0: Section 0 metadata (0.1 Title to 0.5 One sentence description), Tier 1 Section 1 Summary (1.1 Name, 1.2 Description, 1.3 Website URL, 1.4 Contact email) and the Tier 2 sections 2.1 to 2.5. Department for Science, Innovation and Technology, GOV.UK. 2025-05-08. https://www.gov.uk/government/publications/algorithmic-transparency-template (verified: primary)
- [4] Algorithmic Impact Assessment tool, questionnaire source (survey-enfr.json, version 1.0.1): Project Details fields (Project Title, Project ID from IT Plan, Department, Branch, Name of ADM responsible for the program, Project Phase, project description) and the section names. Government of Canada, canada-ca/aia-eia-js on GitHub. 2025-10-03. https://github.com/canada-ca/aia-eia-js (verified: primary)
- [5] Directive on Automated Decision-Making (an Algorithmic Impact Assessment completed and published before production; impact levels I to IV). Treasury Board of Canada Secretariat. 2025-06-24. https://www.tbs-sct.canada.ca/pol/doc-eng.aspx?id=32592 (verified: primary)
- [6] Model card template (section headings: Model Details, Uses, Bias, Risks, and Limitations, Training Details, Evaluation, Environmental Impact, Model Card Contact). Hugging Face, huggingface_hub. 2026. https://github.com/huggingface/huggingface_hub/blob/main/src/huggingface_hub/templates/modelcard_template.md (verified: primary)
- [7] CycloneDX specification 1.7, JSON reference (component of type machine-learning-model; modelCard with modelParameters, quantitativeAnalysis and considerations). OWASP CycloneDX, Ecma TC54. 2025-10-21. https://cyclonedx.org/docs/1.7/json/ (verified: primary)
- [8] ISO/IEC 42001:2023, AI management systems (Annex A control areas A.2 to A.10; the Statement of Applicability of clause 6.1.3). ISO/IEC. 2023-12. The SoA column wording was not opened: verify it against the standard. https://www.iso.org/standard/81230.html (verified: primary)
- [9] 04. The stack, Layer 02: Inventory & Transparency, and the Agent Registry pattern: the registry entry this builder writes. AI Governance Engineering Body of Knowledge. 2026-09-24. https://aigovernanceengineer.com/bok/the-stack#layer-02-inventory--transparency (verified: primary)