GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

AIG-039 Responsible and Intended Use of AI Systems

Tier 1+AIProviderDeployerGPAI Model ProviderManaged Service Provider

Description

A documented process governs how the organisation uses the AI systems it operates, whether it built them or obtained them from someone else. A use register records, for each system in use, the purpose it is used for, the uses the accompanying instructions permit and exclude, the objectives the use is meant to meet and the owner accountable for staying inside them. No entry in the register sits outside the stated intended purpose without an exception record carrying a justification, an owner and an expiry date. Personnel are given rules for acceptable use of AI systems in their work and their acknowledgement is recorded. Where the organisation supplies the input data an AI system acts on, the relevance and representativeness of that data against the stated purpose is checked before use and the check is recorded.

Rationale

AIG-032 assesses a third-party AI system before it is integrated and captures the scope constraints the provider imposes. AIG-039 is the ongoing half: the register that says what each system is actually used for and the exception record when that use drifts outside those constraints. AIG-034 is the same relationship seen from the other side, where the organisation is the provider writing the instructions a customer has to stay inside. AIG-001 states the principles; AIG-039 applies them to the organisation's own use. The input data check is inference-time data the organisation controls, which is a different artefact from the training data management in AIG-012: a retrieval corpus, an uploaded document set, a feature feed. The acceptable-use rules here are the AI-specific companion to the general acceptable-use rules for information assets and can be issued as a section of them. Deployer seat (ADR-031). Where a deployer changes the intended purpose of a system someone else built, it may become that system provider, at which point the provider controls apply as well; the classifier carries that rule.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore

The provider is also a user of AI systems, including the models beneath its product. The use register covers both.

Enterprise AI Deployerstablerequiredrole duty

Use in accordance with the instructions (Art.26.1) and input data relevance (Art.26.3) are the deployer's central duties. The row binds every deployer through ISO 42001 A.9 and becomes a legal duty at high risk.

GPAI Model Providerstablerequiredcore

The provider is also a user of AI systems, including the models beneath its product. The use register covers both.

High-Risk Provider (EU)stablerequiredcore

The provider is also a user of AI systems, including the models beneath its product. The use register covers both.

Public Body Deployer (EU)stablerequiredrole duty

Art.26(1) and Art.26(4) bind both seats and are the central duties of this seat at high risk. Art.26(1) requires use in accordance with the instructions for use and the appropriate technical and organisational measures to secure that use, so every entry in the use register sits inside the intended purpose the provider stated or carries an exception record. Art.26(4) applies where the deployer controls the input data: relevance and representativeness against the intended purpose are checked before use. For a public body the input is commonly its own administrative record, which makes the check a data quality question it owns and the provider cannot answer.

The provider is also a user of AI systems, including the models beneath its product. The use register covers both.

DORA ICT Provider (EU)stablerequiredcore

The provider is also a user of AI systems, including the models beneath its product. The use register covers both.

The provider is also a user of AI systems, including the models beneath its product. The use register covers both.

NIS2 Cloud Provider (EU)stablerequiredcore

The provider is also a user of AI systems, including the models beneath its product. The use register covers both.

Framework Mappings (12)

GRC-09Acceptable Use of the AI Servicepartial
HRS-15AI Acceptable Usefull
EU-AI-Art.26.1Deployer Obligations — Use in Accordance with Instructionsfull
EU-AI-Art.26.3Deployer Obligations — Input Data Qualityfull
A.9.2Processes for responsible use of AI systemsfull
A.9.3Objectives for responsible use of AI systemfull
A.9.4Intended use of the AI systemfull
GV-1.4-002Transparent Risk Management Policies | GV-1.4-002partial
GV-3.2-003Human-AI Configuration Roles | GV-3.2-003partial
GV-6.1-007Third-Party AI Risk Policies | GV-6.1-007informative
GV-6.1-010Third-Party AI Risk Policies | GV-6.1-010partial
MS-4.2-003Trustworthiness Measurement with Expert Input | MS-4.2-003informative

Evidence (3)

recorddocumentmanual

The AI use register, listing for each system in use the purpose it is used for, the permitted and excluded uses drawn from the accompanying instructions, the objectives of the use and the accountable owner.

Example: AI use register, extract of 30 June 2026, covering nine systems including three obtained from third parties.

Test: Verify: (1) every AI system in the inventory that the organisation operates appears in the use register, (2) the permitted and excluded uses for each third-party system trace to a clause of that provider's instructions rather than to a summary, (3) each entry names an accountable owner who is a current employee, (4) any recorded use outside the stated intended purpose carries an exception with a justification, an owner and an unexpired date.

system_exporttechnicalautomated

Acknowledgement export from the policy or learning system showing which personnel have accepted the acceptable-use rules for AI systems and on what date.

Example: Policy platform export ai-acceptable-use-acknowledgements-2026-06.csv, generated 30 June 2026.

Test: Verify: (1) the population in the export matches the current personnel list from the human resources system, (2) every person with access to an AI system named in the use register appears as having acknowledged, (3) acknowledgement dates fall after the current version date of the rules, (4) joiners in the period acknowledged inside the window the process states.

recorddocumentmanual

Input data check records for the data the organisation supplies to an AI system, showing what was checked for relevance and representativeness against the stated purpose, the result and the date.

Example: Retrieval corpus review for the Policy Assistant, 11 May 2026, covering coverage by business line and document currency.

Test: Verify: (1) a check record exists for each data source the organisation supplies to a system in the use register, (2) the check is against the purpose recorded for that system rather than a generic quality statement, (3) the record states a result that could have been a fail, (4) where a check failed, the record shows what changed before the data was used.

Questions (3)

boolean

Is there a register recording what each AI system you operate is used for?

The AI system inventory (AIG-003) records that a system exists and who owns it. This question is about the use: the purpose it is put to and the uses its instructions permit and exclude. One register can serve both provided both sets of fields are present.

multi

Which of the following are recorded for the AI systems you operate?

The purpose each system is used forThe uses the accompanying instructions permit and excludeThe objectives the use is meant to meetAn accountable owner for staying inside the intended purposeExceptions for use outside the intended purpose, with a justification and an expiry dateAcceptable-use rules for AI systems, acknowledged by personnelChecks that input data you supply is relevant and representativeNone of the above

Options follow the order the items appear in a use register. Answer for what is recorded today, not for what the process says should be recorded.

select

How is use outside a system stated intended purpose handled?

It is prevented, with any need for it going through an exception carrying a justification, an owner and an expiry dateIt is recorded as an exception with a justification, an owner and an expiry dateIt is recorded, without an expiry dateIt is noticed informally and discussedIt is not tracked

Options run from the strongest handling to the weakest. Answer for what happened the last time a use fell outside the instructions, not for what the process states.