Is the tool or the use case the right unit for responsibility?
The unit somebody carries responsibility for is the use case. A use case is a stable, purpose-bound use of AI inside a process. The same tool creates three use cases with three different risks across three departments. A list of installed tools therefore answers none of the questions an auditor asks: for what, at what risk, under whose responsibility. We built the five axis model at KIRegister together with Zoltan Alexander Gal, in April 2026, for a course aimed at consultants and lawyers. Looking back, the part that carries is the question about the right unit. That question is older than any regulation, and it helps in places where nobody is thinking about the law. A company uses an assistant in purchasing to compare supplier offers. HR writes to applicants with it. Marketing produces campaign copy with it. That is one piece of software, and it is three use cases. The first touches business relationships, the second people applying for a job, the third the public voice of the house. One line in a tool inventory captures none of that.
One tool, three use cases
A company uses an assistant in purchasing to compare supplier offers. HR writes to applicants with it. Marketing produces campaign copy with it. That is one piece of software, and it is three use cases. The first touches business relationships, the second people applying for a job, the third the public voice of the house. One line in a tool inventory captures none of that.
A use case describes a stable, purpose bound use of AI inside an organisational process.
The five axes
Each axis carries one question you can ask in an ordinary conversation. In most companies three or four of them are answered with silence. That is exactly where the work starts.
The policy says what should apply. The register shows what actually applies.
Check one of your own use cases in half an hour.
- The use case is the unit. Question: can you say, department by department, what AI is actually used for, and not just which tools are installed? Example: in purchasing the same software compares offers, in HR it writes to applicants.
- The minimum principle. Question: for your most important use cases, can you answer five questions on the spot, meaning where, for what purpose, at what risk, who carries responsibility, with which measures? Example: half an hour of documentation per case gets routed around, half a minute gets done.
- The tool is an attribute. Question: would you have to rebuild your structure if you switched providers tomorrow? Example: the newsletter stays the same use case even when the language model behind it is swapped out.
- The duty follows the effect. Question: by what criteria do you decide today which use has to be documented and which does not? Example: having a spreadsheet formula explained once does not count, writing to applicants every day does.
- Artefact first. Question: does each use case produce a checkable artefact you can hand on? Example: one sheet per case, readable by humans and machines, ready to go to auditors and to a partner purchasing department.
What the EU AI Act orders
The EU AI Act orders organisation and liability. It asks who is responsible, which measures were taken, and whether the house can prove it. A system is not a legal person and therefore cannot be liable. The organisation is liable, the operator is liable, and in many cases management is personally liable once it can be shown that an adequate structure was missing.
What I meet most often has a name: shadow AI. A tool approved long ago gets used for a new purpose because somebody on the team had a good idea. That is the normal state in most houses, and it happens without any bad intent. The duties attach to actual operation. So a one-off inventory is a good start and not a conclusion.
The use is there at once, the evidence is not. The effect is there at once, the documentation is not.
The moments it turns urgent
The topic stays abstract until a concrete moment arrives. Four of them come up again and again. A supplier asks in writing for AI documentation. An internal IT project with AI components is announced. An authority announces an audit. A merger is coming, and the review before it asks which AI systems are running. Anyone who knows what to listen for hears these sentences in ordinary talk.
A fifth signal has been in the garden for a while. Anyone advertising a role for AI responsibility has already put a number on the need and fixed the timing. How to read such an ad stands in What does an open job ad reveal?
The same unit inside an AI department
Inside an ki-department I work with the same unit. The approval platform is one use case: every draft sits in one place, a person looks at it and gives approval. The guardian of the brand is the second: it checks tone, claims and rules before a human sees the draft. For a newsletter that is up to 21 checks, for a blog post 48 on content and 26 on the platform. How that gate is built stands in the note on the guardian.
The third case is the agent on the mailbox, and draft before send applies to it. It researches, writes, fills in forms down to the last click, and never sends on its own. Each case carries a purpose, a risk and a name, which is exactly what a register asks for. The rule in detail has a note of its own.
If you want to sort one level further down, the foundation stands in model, tool or agent. How such a department is built stands on the AI implementation page.
From the course
KIRegister course for consultants and lawyers, recorded on 12 April 2026, on the channel since 14 April 2026. The check counts 21, 48 and 26 come from the running engagement and stand in the note on the guardian of the brand.
- A use case is a stable, purpose-bound use of AI inside an organisational process
- One piece of software across purchasing, HR and marketing produces three use cases with three risk profiles
- Five data points per use case are enough: where, for what purpose, at what risk, under whose responsibility, with which measures
- Half an hour of effort per use case gets routed around, half a minute gets done
- What gets documented is what runs stably and has effect, meaning relevance for decisions or a serious risk
- Each use case produces a checkable artefact, readable by humans and machines, shareable with auditors and partners
Use case sheet
Five axes with a scale and a reason, for one use case in half an hour. PDF · A4, 1 pages, , as of 3 September 2026.
Sources and links
This note keeps growing
2026-09-03: Planted from the KIRegister course for consultants and lawyers, April 2026.