AI Use-Case Intake and Triage Form
In brief
The AI Use-Case Intake and Triage Form is a free XLSX and DOCX procedure for EU AI Act, ISO/IEC 42001 and NIST AI RMF. Register and screen every proposed AI use before work starts: an intake register, a screen against every prohibited practice on record, and routing to standard, enhanced or transparency review.
- Format
- XLSX and DOCX · Procedure
- Version
- v1, built 5 Oct 2026
- Duties cited
- 11 from 6 instruments
- Rows from the records
- 17
- Frameworks
- EU AI Act, ISO/IEC 42001, NIST AI RMF
- Written for
- Provider / developer, Deployer / user organisation, Public authority / government body
- Price and licence
- Free · CC BY 4.0
What's inside
- Intake register with routing and a flag for a failed screen
- Prohibited-use screen: every prohibited practice on record, one question each
- Procedure document with the routing table
- Risk and impact-assessment duties sheet
Preview
The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.
Sheet: Intake
| Request ID | Date | Requested by | Use case | Build or buy ▾ | Makes or supports decisions about people ▾ | Uses personal data ▾ | Generates content ▾ | Where it will be used | Prohibited-use screen ▾ | Route ▾ | Decision and date | Inventory entry |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Rows are yours to fill; the dropdowns, formulas and colour rules are already in place. | ||||||||||||
One row per proposed AI use, before any work starts. A failed prohibited-use screen ends the request; a possible high-risk use goes to enhanced review.
Sheet: Prohibited-use screen
| Practice on record | Reference | Instrument | Could this use involve it? ▾ | Reasoning | Record |
|---|---|---|---|---|---|
| Do not deploy or provide AI for prohibited practices | Article 5 | EU AI Act | https://aipolicytracker.org/obligations/eu-ai-act-prohibited-practices | ||
| Developers and deployers must not use AI to incite self-harm, harm to others or crime | Business and Commerce Code Section 551.052 | Texas Responsible AI Governance Act (TRAIGA) | https://aipolicytracker.org/obligations/us-texas-responsible-ai-governance-act-traiga-manipulation-prohibition | ||
| Governmental entities must not use AI for social scoring | Business and Commerce Code Section 551.053 | Texas Responsible AI Governance Act (TRAIGA) | https://aipolicytracker.org/obligations/us-texas-responsible-ai-governance-act-traiga-government-social-scoring-prohibition | ||
| Governmental entities must not use AI for biometric identification from public data without consent where it infringes rights | Business and Commerce Code Section 551.054 | Texas Responsible AI Governance Act (TRAIGA) | https://aipolicytracker.org/obligations/us-texas-responsible-ai-governance-act-traiga-government-biometric-identification-prohibition | ||
| Developers and deployers must not use AI with the intent to unlawfully discriminate against a protected class | Business and Commerce Code Section 551.056 | Texas Responsible AI Governance Act (TRAIGA) | https://aipolicytracker.org/obligations/us-texas-responsible-ai-governance-act-traiga-unlawful-discrimination-prohibition | ||
| Developers and distributors must not build AI intended to produce child sexual abuse material or unlawful sexual deepfakes | Business and Commerce Code Section 551.057 | Texas Responsible AI Governance Act (TRAIGA) | https://aipolicytracker.org/obligations/us-texas-responsible-ai-governance-act-traiga-sexual-content-and-csam-prohibition |
Every prohibited practice on record. Answer each for the use case; any "Yes" stops the request until legal has reviewed it.
Sheet: Risk duties
| Duty | Category | Instrument | Jurisdiction | Who it binds | Nature | Source reference | Applies from | What it requires | Evidence a reviewer expects | ISO/IEC 42001 | NIST AI RMF | Verification | Record |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Establish a risk management system for high-risk AI | AI risk management | EU AI Act | European Union | Provider / developer | Legal requirement | Article 9 | 2027-12-02 | Providers of high-risk AI systems must establish, implement, document and maintain a continuous, iterative risk-management system across the system's lifecycle: | Risk register and treatment plan; Pre-market test reports | Clauses 6.1.2, 6.1.3, 8.2, 8.3 and Annex A controls on AI risk | MAP, MEASURE and MANAGE functions | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-risk-management-system |
| Carry out a fundamental rights impact assessment before deployment | Impact assessment | EU AI Act | European Union | Deployer / user organisation, Public authority / government body | Legal requirement | Article 27 | 2027-12-02 | Before deploying most Annex III high-risk systems, deployers that are bodies governed by public law or private entities providing public services, and deployers | Fundamental rights impact assessment report | Clause 6.1.4 AI system impact assessment; Annex A control on impact assessment | MAP 5.1, MAP 5.2 | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-fundamental-rights-impact-assessment |
| Significant Data Fiduciaries must appoint a DPO and run impact assessments and audits | Impact assessment | India DPDP Act | India | Provider / developer, Deployer / user organisation | Legal requirement | Section 10 | Entities notified as Significant Data Fiduciaries, based on factors such as volume and sensitivity of data and risk to individuals, must appoint a Data Protecti | Data protection impact assessment | Clause 6.1.4 AI system impact assessment | Source-linked | https://aipolicytracker.org/obligations/india-dpdp-significant-data-fiduciary-duties | ||
| Operators of high-impact AI must establish and operate a risk management plan | AI risk management | Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust | South Korea | Provider / developer, Deployer / user organisation, Public authority / government body | Legal requirement | Article 34(1) | 2026-01-22 | An AI business operator that provides high-impact AI, or a product or service using it, must establish and operate a plan for managing the risks of that AI. Hig | High-impact AI risk management plan; High-impact classification record | Clause 6.1.2, 6.1.3, 8.1 | MAP 1.5, MANAGE 1.3 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-34-high-impact-ai-risk-management-plan |
| Operators of high-impact AI should assess its impact on fundamental rights before use | Impact assessment | Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust | South Korea | Provider / developer, Deployer / user organisation, Public authority / government body | Voluntary | Article 35 | 2026-01-22 | An AI business operator that provides high-impact AI, or a product or service using it, is to make efforts to assess in advance the impact the AI may have on pe | Fundamental-rights impact assessment for high-impact AI | Clause 6.1.4; Annex A.5.2, A.5.4 | MAP 5.1, MAP 5.2 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-35-high-impact-ai-impact-assessment |
| Conduct a data protection impact assessment for high-risk processing using new technologies | Impact assessment | UAE PDPL | United Arab Emirates | Provider / developer, Deployer / user organisation | Legal requirement | Article on data protection impact assessment (reviewer to cite article number) | Before processing that uses modern technologies and is likely to pose a high risk to privacy, controllers must assess the impact on personal data protection, co | Data protection impact assessment | Clause 6.1.4 AI system impact assessment | Source-linked | https://aipolicytracker.org/obligations/uae-pdpl-impact-assessment-new-technologies |
The recorded risk-management and impact-assessment duties an approved use case may trigger.
Document outline (DOCX)
- AI use-case intake and triage procedure
- 1. Register the request
- 2. Screen for prohibited practices
- 3. Classify and route
- 4. Record the decision
- Prohibited practices on record
- Do not deploy or provide AI for prohibited practices
- Developers and deployers must not use AI to incite self-harm, harm to others or crime
- Governmental entities must not use AI for social scoring
- Governmental entities must not use AI for biometric identification from public data without consent where it infringes rights
- Developers and deployers must not use AI with the intent to unlawfully discriminate against a protected class
- Developers and distributors must not build AI intended to produce child sexual abuse material or unlawful sexual deepfakes
How to use it
- 1Request the files. Enter your name, company and work email in the form on this page. The XLSX and DOCX download links arrive by email and work for 7 days.
- 2Read the README page. It states the version (v1), the dataset it was built from and the licence, so anyone reviewing your copy knows which records it reflects.
- 3Fill in your rows. Complete the "Intake" sheet for your own systems. Dropdowns, formulas and colour rules are already set.
- 4Check the duties against your situation. The "Prohibited-use screen" and "Risk duties" sheets list the recorded duties with their source references. Mark which apply to you and follow each link to the official text.
- 5Complete the document. Work through the DOCX sections (AI use-case intake and triage procedure, Prohibited practices on record) and replace each placeholder with your organisation's answer.
- 6Keep the evidence and watch for new versions. Link each completed row to the evidence that supports it. When the law on record changes, this template gets a new version and a changelog on this page.
Duties this template covers (11)
Each is cited in the file with its source reference and a link back to the record.
- Do not deploy or provide AI for prohibited practices
- Establish a risk management system for high-risk AI
- Operators of high-impact AI must establish and operate a risk management plan
- Developers and deployers must not use AI to incite self-harm, harm to others or crime
- Governmental entities must not use AI for social scoring
- Governmental entities must not use AI for biometric identification from public data without consent where it infringes rights
- Developers and deployers must not use AI with the intent to unlawfully discriminate against a protected class
- Developers and distributors must not build AI intended to produce child sexual abuse material or unlawful sexual deepfakes
- Ensure AI systems are safe, secure and robust throughout their lifecycle
- Prioritise, respond to and monitor AI risks (Manage)
- Apply minimum risk-management practices to high-impact AI
Legal basis
Version history
| Version | Built | Dataset | What changed |
|---|---|---|---|
| v1 | c6967b988bb5 | First version, built from dataset c6967b988bb5. |
Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.
Frequently asked questions
What is in the AI Use-Case Intake and Triage Form?
Intake register with routing and a flag for a failed screen. Prohibited-use screen: every prohibited practice on record, one question each. Procedure document with the routing table. Risk and impact-assessment duties sheet.
Which duties does it cite?
11 recorded duties from EU AI Act, Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, Texas Responsible AI Governance Act (TRAIGA) and UK AI regulation framework, including Article 5, Article 9, Article 34(1), Business and Commerce Code Section 551.052, Business and Commerce Code Section 551.053 and Business and Commerce Code Section 551.054. Each row links to the record, and the record to the official source.
Who is it for?
The duties it cites fall on provider / developer, deployer / user organisation and public authority / government body. Whoever owns AI governance for those roles usually completes it, with the system owner supplying the facts.
Is it free?
Yes. Request the XLSX and DOCX with your work email on this page; the download links arrive by email, valid for 7 days. No account and no charge. Licensed CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
How will I know when it changes?
Version v1 was built on 5 October 2026. The library is rebuilt daily; when a change to the records reaches this template it gets the next version, a changelog below and an entry in the templates feed.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.
Disclaimer: informational only, not legal advice. Verify every claim against the linked official sources and consult a qualified lawyer before acting.