GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

AIG-045 Deployer Registration in a Public AI Register

Tier 1+AIDeployerhigh-risk-annex-iii

Description

Where regulation requires the organisation operating an AI system to register itself and its use of that system in a public register, a registration record exists and pre-dates the first use of the system. The record names the register, the entry the organisation registered under, the system as the register identifies it, the date of the filing and the reference the register returned. That reference is held against the deployment record for the system, so the system, its use and its filing read together. A change to the registered use is filed before the changed use begins and the record carries the amended reference.

Rationale

The filing is the operator's own and is separate from any filing the provider makes about the same system, which AIG-003 records against the inventory entry. The register entry is public, so the test is mechanical: the reference resolves, it names this organisation and its date is earlier than the date of first use. That is why the control asks for the reference rather than for a copy of the submission. Deployer seat (ADR-031). Where the register asks for details of the system that only the provider holds, they are obtained under AIG-032 and filed with the registration rather than reconstructed.

Applicability (9 profiles)

SaaS AI Providerstablenot-applicableout of scope

Registration by the organisation using the system is a deployer duty under Art.49(3). The provider registration of Art.49(1) and (2) sits on AIG-003 and is required of this profile there.

Enterprise AI Deployerstableconditionalrisk class duty

Condition: ai_risk_class in high-risk-annex-iii and the deployer is a public authority, an agency or another body governed by public law, or acts on behalf of one

Art.49(3) binds a public authority, an EU institution or a person acting on their behalf, before the system is put into service or used. The Annex III point 2 carve-out applies. The provider-side arm of Art.49 sits on AIG-003 and stays with the provider, so a deployer holds two references against one system.

GPAI Model Providerstablenot-applicableout of scope

Deployer-seat duty (enterprise-ai-deployer).

High-Risk Provider (EU)stablenot-applicableout of scope

Registration by the organisation using the system is a deployer duty under Art.49(3). The provider registration of Art.49(1) and (2) sits on AIG-003 and is required of this profile there.

Public Body Deployer (EU)stablerequiredrole duty

The first of the two seats this profile is built on. Art.49(3) binds deployers that are public authorities, Union institutions, bodies, offices and agencies or persons acting on their behalf: before a high-risk Annex III system is put into service or used, the body registers itself, selects the system and registers its use in the EU database. Systems in the Annex III point 2 area are carved out and carry no filing, so the record states the carve-out rather than leaving the field empty. The provider's Art.49(1) registration of the system is a different filing on a different seat and sits on AIG-003, so one system carries two references. The filing is due from 2 December 2027 with the other Annex III duties: Art.49 sits in Chapter III Section 5 rather than Sections 1 to 3, but the registration duty attaches to a high-risk system when Chapter III applies to it (ADR-025; owner decision of 2026-09-15 on the S11 digest).

Data Act Cloud Provider (EU)stablenot-applicableout of scope

Registration by the organisation using the system is a deployer duty under Art.49(3). The provider registration of Art.49(1) and (2) sits on AIG-003 and is required of this profile there.

DORA ICT Provider (EU)stablenot-applicableout of scope

Registration by the organisation using the system is a deployer duty under Art.49(3). The provider registration of Art.49(1) and (2) sits on AIG-003 and is required of this profile there.

HIPAA Business Associate (US)stablenot-applicableout of scope

Registration by the organisation using the system is a deployer duty under Art.49(3). The provider registration of Art.49(1) and (2) sits on AIG-003 and is required of this profile there.

NIS2 Cloud Provider (EU)stablenot-applicableout of scope

Registration by the organisation using the system is a deployer duty under Art.49(3). The provider registration of Art.49(1) and (2) sits on AIG-003 and is required of this profile there.

Framework Mappings (2)

EU-AI-Art.49.2EU Database Registration — Deployer Registration for Public Authoritiesfull
EU-AI-Art.5.2Prohibited Practices — Conditions on the Law Enforcement Use of Real-Time Remote Biometric Identificationinformative

Evidence (2)

recorddocumentmanual

Registration confirmation for a named system, giving the register, the organisation entry it was filed under, the system as the register identifies it, the filing date and the reference returned.

Example: EU database registration confirmation for the benefits eligibility triage system, entry filed 11 March 2026, reference EU-AI-DB-2026-014732.

Test: Verify: (1) the filing date is earlier than the date the organisation first used the system, (2) the reference resolves in the public register and the entry it resolves to names this organisation, (3) the system named in the entry is the system the deployment record describes rather than a family or a product line, (4) where the recorded use has changed since the original filing, an amended entry exists dated before the changed use began.

system_exporttechnicalautomated

Export from the AI system inventory or the deployment register listing each system the organisation operates that carries a registration duty, with its register reference, filing date and first-use date.

Example: Inventory export registered-deployments-2026-06.csv, generated 30 June 2026, covering six systems.

Test: Verify: (1) every system flagged as carrying a registration duty holds a non-empty reference, (2) no filing date falls on or after its first-use date, (3) every reference is distinct, so no two deployments have been recorded against one filing, (4) a system whose registration duty was assessed as not applying carries the determination that says so rather than an empty field.

Questions (2)

boolean

Is each AI system that carries a registration duty registered before the organisation first uses it?

Answer yes only where a reference returned by the register exists for every such system and pre-dates first use. A registration made after the system went live, or a reference held by the supplier rather than by this organisation, is a no.

multi

Which of the following does the registration record hold?

The register the filing was made inThe organisation entry the filing was made underThe system as the register identifies itThe date of the filingThe reference the register returnedAn amended filing covering a later change of useNone of the above

The reference is the element an assessor checks first, because it is the one that can be resolved independently. Tick the amendment option only where the recorded use has actually changed and a later filing exists.