AI governance
What is an AI vendor register?
An AI vendor register lists every AI tool and LLM provider with access to company or customer data — what it processes, where, and whether it may train on inputs. Here is how to build one.
Published 2026-08-23 · Updated 2026-08-24
An AI vendor register is a maintained list of every artificial intelligence tool, model, and LLM provider that can access your company’s or customers’ data — recording what data each one touches, where it is processed, who owns the relationship, and which contractual terms apply.
It is the AI-era equivalent of a sub-processor list. Where a classic vendor register answers “who holds our data?”, an AI register answers “which models see our data, and could they learn from it?”.
Why companies need one now
- Shadow AI: employees adopt chatbots, copilots, and transcribers before procurement hears.
- Customer questionnaires now ask which AI services process customer data and whether they train on it.
- GDPR still treats these providers as processors; training and retention terms affect your documentation.
- LLM vendors change policies frequently. A dated register shows when a review is overdue.
What each entry should record
- Vendor name and product (API vs consumer app tier matters).
- Data categories submitted (content, customer records, employee data).
- Processing region and transfer mechanism (SCCs, adequacy).
- Whether the provider may train on submitted data.
- DPA status and retention / no-train settings in the contract.
- Internal owner and last/next review date (90 days works well for AI).
How to maintain it without spreadsheets
PrivyLedger keeps an AI vendor register alongside your broader sub-processor roster: automatic exposure scoring per tool, DPA chase letters, 90-day re-review reminders, and paste-ready answers for the AI sections of security questionnaires.
This guide describes general practice. It is not legal advice.
Questions
Is an AI vendor register required by the EU AI Act?
The Act does not prescribe a named “register” for every SMB, but you still need to know which AI systems you use, what data they process, and on what terms. Customer questionnaires and GDPR processor duties already require that inventory.
Does a ChatGPT personal account belong on the list?
If employees paste company or customer data into it, yes — that is shadow AI. Record it, then either ban it or move the work onto a contracted no-train tier.
How often should AI vendors be re-reviewed?
Ninety days is a practical cadence. Model providers change retention and training policies faster than ordinary SaaS.