AI Use Case Register
Record every place your business uses AI: what data goes in, who checks the output, what it saves, what it costs and how risky it is. Scores each use case and shows which ones need attention. Runs entirely in your browser. Nothing is uploaded.
Version 1.0.0 · Updated Aug 20, 2026
Use AI Use Case Register now
Runs in your browser · nothing is uploaded
This in-page version cannot save your work between visits — browser storage is switched off inside the sandbox. The full version saves your work locally after download.
Overview
Frequently asked questions
How does the AI Use Case Register licence work?
It is a one-time purchase for a downloadable tool — no subscription. You buy it once and the file is yours to keep and use.
Can I try the AI Use Case Register before buying?
Yes. Use the Try online button for a fully interactive demo with sample data already loaded — nothing to install and nothing is saved.
Can I import my data from a spreadsheet?
Yes. Use the Spreadsheet template button to save a CSV with the right headings, fill it in Excel or any spreadsheet, then Import spreadsheet to load it back. The file is read in your browser — nothing is uploaded.
Does my data stay private?
Yes. The tool is a single HTML file that runs entirely on your computer and makes no network requests, so nothing you enter is ever uploaded or shared.
Do I need Excel or any other software?
No. It replaces the spreadsheet template entirely: open the file in your browser (Chrome, Edge, Firefox or Safari) on Windows, Mac, Linux or a tablet, and start working.
How to use AI Use Case Register
The complete in-tool guidance, reproduced here so you can read it before you download.
What this tool does
CM8-347 is a register of every place your business uses AI. For each one you record what it does, what data goes into it, who checks the output, what a wrong answer would cost, how often it runs and what it saves. The tool scores each use case for risk, works out what it is worth a year after a deliberate haircut on the claim, flags the ones with no owner or no human step, and prints a register you can take to a board or an auditor.
Everything runs inside this single file. There is no account, no upload and no network request of any kind. That matters here: a complete list of where a business uses AI, with the sensitive data each one touches, is a map of exactly where to attack it.
Why a register at all
AI use rarely arrives as a project. It arrives as a feature in software you already pay for, and as individuals quietly pasting work into an assistant because it saves them twenty minutes. By the time anybody asks the question, the honest answer to "where do we use AI?" is "we don't know".
That is the problem this solves. Not governance theatre — a list. Once the list exists, three questions become answerable: is any of this touching data it should not, is anything making a decision with no person in the loop, and is any of it actually saving money.
What one row is
One row is one job the AI is doing, not one tool. The same assistant used to draft support replies and to summarise contracts is two rows, because the data, the risk and the value are completely different in each case. A tool used for one job across six departments is one row if the job is the same, and six if it is not.
Record ideas and trials as well as live use. An idea nobody has started costs nothing and carries no risk, but writing it down stops it being started twice, and stops it being started badly.
How the risk score works
Three judgements multiply together:
Risk score = data weight × autonomy weight × impact weight data weight public 1 · internal 2 · confidential 3 · personal 4 · special category 5 autonomy weight drafts or always checked 1 · spot-checked 2 · automatic 3 impact weight low 1 · moderate 2 · high 3 · severe 4 Range: 1 to 60
Multiplication rather than addition is deliberate. A use case that is high on one dimension and low on the others is usually fine; one that is high on all three is not, and multiplying makes that gap wide. Special-category data used automatically in a severe-impact decision scores 60. Public data drafted and rewritten by a person scores 1.
Set the threshold in Settings to whatever level your organisation wants to see sign-off at. Anything at or above it is Elevated; anything at or above twice it is High. The default of 12 means, roughly, that confidential data used with anything less than a full human check on a high-impact job needs a decision.
The score ranks use cases against each other. It is not a probability, it does not mean anything on its own, and a score of 4 is not "safe" — it is "less pressing than the one scoring 36".
Judging the data going in
Judge by the worst case, not the usual case. The question is not "what do I normally paste in" but "what could end up in a prompt if somebody is in a hurry". If a support agent can paste a whole email thread, then the data going in is personal data, whatever the intended use was.
Include what the tool can reach as well as what you type. An assistant with access to a shared drive is handling everything on that drive, not only the file you asked about.
How the output is used
This is the single most useful field in the register, because it is the one that can be changed tomorrow. Four levels:
- Drafts only — a person rewrites before anything is used. The AI is a starting point and nothing it produces survives unedited.
- Checked every time — the output is used, but a person reads it first. Scored the same as drafts, because a real check is a real control.
- Spot-checked — some are checked, most are not. Be honest here: "a recruiter reviews the list" usually means the top twenty are read and the rest are not, which is spot-checking.
- Automatic — the output is used with no human step at all.
Most use cases that feel uncomfortable can be made comfortable by moving one level up this list. That is a cheaper fix than changing tools.
Decisions about people
Tick the box where the output feeds a decision about an individual: hiring, pay, promotion, discipline, credit, eligibility, or anything a person would reasonably want to appeal. Two positions are flagged regardless of score:
- Automatic decision about a person — no human step in a decision that affects somebody. This is the one to fix first, whatever the arithmetic says, and in several countries it is also the one most likely to be unlawful.
- Affects people, not disclosed — the decision involves AI and the people affected have not been told.
The register flags these; it does not tell you what the law requires of you, which differs by country and by sector and is changing quickly.
Working out what it is worth
Value comes from time, and only live use cases claim any:
Hours saved per year = runs per month × minutes saved each × 12 ÷ 60 Gross value = hours saved per year × cost of an hour of staff time Running cost = cost per month × 12 Net value = gross value × (1 − haircut %) − running cost
"Minutes saved each time" is the honest number: how long the job took before, less how long it takes now including reading and fixing the output. A draft that takes four minutes to write and six minutes to correct has saved nothing.
A trial or an idea shows its running cost as a negative net value. That is not a criticism — it is what a trial is — but it does mean the register never quietly counts a hoped-for saving as a real one.
Why savings get a haircut
Estimated time savings are consistently optimistic, for three reasons that show up everywhere: the saved minutes are estimated by the person who wanted the tool, the time saved is rarely converted into anything else, and the checking effort is under-counted. The haircut in Settings, 30% by default, is applied to every claim before it reaches a total.
Set it to zero if you have measured the saving properly, with a before and after. Nobody should be presenting an unmeasured AI saving to a board without saying which it is.
Reviews
Live and trial use cases fall due for review after the interval you set, counted from the last review or, if there has not been one, from the date the use case was recorded:
Review due = last reviewed (or date recorded) + review interval in months
A review is not a form. It is three questions: is it still being used, has what goes into it changed, and has the vendor changed anything about how the data is handled. The third question is the one that catches people out — terms change, features get switched on by default, and a use case that was fine in March may not be in September.
What this is not
- It is not a data protection impact assessment. Where one is required, this register tells you which use cases need one; it does not replace it.
- It is not legal advice and it does not know which rules apply to you.
- It does not monitor anything. If a use case changes, somebody has to change the row.
- It does not find shadow use. It records what people tell you about. The most useful thing you can do with this tool is ask everybody, once, without blame, what they are already using.
- A low score is not approval. It means this one is less urgent than the others in your own list.
Printing and sharing
The Report tab prints the tiles, charts and both tables with a title block you fill in. Filter first if you want a register for one area or one status — the report follows the filter, so a board paper on personal-data use cases is a filter and a print.
Saving your work
The register is held in this browser, on this computer, and stays there between visits. Use the backup button to write a JSON file you control — that file is the only copy that survives clearing browsing data or moving to a new machine. The spreadsheet download gives you the same rows in a form you can share.
Accuracy & disclaimer
Every figure here comes from your own judgement and your own estimates. The scoring weights are stated in full above so you can disagree with them; if your organisation weighs these things differently, the ranking is what matters, not the number. Nothing in this tool has been reviewed by a lawyer, and a register that says "Routine" has told you about your own inputs, not about your obligations.
Where this fits
Part of AI & Data Privacy in IT, Data & Cyber.
Related tools
Paste text and see what a chat assistant would receive: names, emails, phone numbers, addresses, employee and customer identifiers, bank and card details, national IDs, credentials and special-category data, each scored for sensitivity into one risk verdict, with a redacted version you can copy. Run
Anonymise text before sending it to a chat assistant: every name, email, phone number, address, identifier and term of your own is replaced by a consistent stand-in, a reversible key is kept on your machine, and the assistant's reply can be turned back into the real thing in one step. Runs entirely
Keep an IT change and release register: what changed, the risk, who approved it, whether it worked, and the rollback evidence — with success rate and emergency-change share worked out for you. Nothing is uploaded.
Log every backup job and every restore test, so you can prove the data actually comes back. Shows which systems have never been restore-tested, which tests are overdue, and which restores miss their recovery time objective. Nothing is uploaded.
Keep one register of every device, licence and subscription: who has it, what it cost, when the warranty runs out and when it renews. Keeps one-off purchases and recurring cost apart instead of adding them together. Nothing is uploaded.
Identify which roles the business actually cannot do without, measure how long you would be exposed if one emptied, and see where the single points of failure really are. Runs entirely in your browser. Nothing is uploaded.