AIPolicyTracker
ProcedureFree · sent to your work emailEU AI ActISO/IEC 42001NIST AI RMF

AI Use-Case Intake and Triage Form

Formats: XLSX and DOCX · Version v1 · Built from dataset c6967b988bb5 · CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

In brief

The AI Use-Case Intake and Triage Form is a free XLSX and DOCX procedure for EU AI Act, ISO/IEC 42001 and NIST AI RMF. Register and screen every proposed AI use before work starts: an intake register, a screen against every prohibited practice on record, and routing to standard, enhanced or transparency review.

Format
XLSX and DOCX · Procedure
Version
v1, built 5 Oct 2026
Duties cited
11 from 6 instruments
Rows from the records
17
Written for
Provider / developer, Deployer / user organisation, Public authority / government body
Price and licence
Free · CC BY 4.0

What's inside

  • Intake register with routing and a flag for a failed screen
  • Prohibited-use screen: every prohibited practice on record, one question each
  • Procedure document with the routing table
  • Risk and impact-assessment duties sheet

Preview

The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.

Sheet: Intake · 13 columns · blank, 150 rows ready to fill
First rows of the Intake sheet
Request IDDateRequested byUse caseBuild or buy ▾Makes or supports decisions about people ▾Uses personal data ▾Generates content ▾Where it will be usedProhibited-use screen ▾Route ▾Decision and dateInventory entry
Rows are yours to fill; the dropdowns, formulas and colour rules are already in place.

One row per proposed AI use, before any work starts. A failed prohibited-use screen ends the request; a possible high-risk use goes to enhanced review.

Sheet: Prohibited-use screen · 6 columns · 6 rows from the records
First rows of the Prohibited-use screen sheet
Practice on recordReferenceInstrumentCould this use involve it? ▾ReasoningRecord
Do not deploy or provide AI for prohibited practicesArticle 5EU AI Acthttps://aipolicytracker.org/obligations/eu-ai-act-prohibited-practices
Developers and deployers must not use AI to incite self-harm, harm to others or crimeBusiness and Commerce Code Section 551.052Texas Responsible AI Governance Act (TRAIGA)https://aipolicytracker.org/obligations/us-texas-responsible-ai-governance-act-traiga-manipulation-prohibition
Governmental entities must not use AI for social scoringBusiness and Commerce Code Section 551.053Texas Responsible AI Governance Act (TRAIGA)https://aipolicytracker.org/obligations/us-texas-responsible-ai-governance-act-traiga-government-social-scoring-prohibition
Governmental entities must not use AI for biometric identification from public data without consent where it infringes rightsBusiness and Commerce Code Section 551.054Texas Responsible AI Governance Act (TRAIGA)https://aipolicytracker.org/obligations/us-texas-responsible-ai-governance-act-traiga-government-biometric-identification-prohibition
Developers and deployers must not use AI with the intent to unlawfully discriminate against a protected classBusiness and Commerce Code Section 551.056Texas Responsible AI Governance Act (TRAIGA)https://aipolicytracker.org/obligations/us-texas-responsible-ai-governance-act-traiga-unlawful-discrimination-prohibition
Developers and distributors must not build AI intended to produce child sexual abuse material or unlawful sexual deepfakesBusiness and Commerce Code Section 551.057Texas Responsible AI Governance Act (TRAIGA)https://aipolicytracker.org/obligations/us-texas-responsible-ai-governance-act-traiga-sexual-content-and-csam-prohibition

Every prohibited practice on record. Answer each for the use case; any "Yes" stops the request until legal has reviewed it.

Sheet: Risk duties · 14 columns · 11 rows from the records
First rows of the Risk duties sheet
DutyCategoryInstrumentJurisdictionWho it bindsNatureSource referenceApplies fromWhat it requiresEvidence a reviewer expectsISO/IEC 42001NIST AI RMFVerificationRecord
Establish a risk management system for high-risk AIAI risk managementEU AI ActEuropean UnionProvider / developerLegal requirementArticle 92027-12-02Providers of high-risk AI systems must establish, implement, document and maintain a continuous, iterative risk-management system across the system's lifecycle:Risk register and treatment plan; Pre-market test reportsClauses 6.1.2, 6.1.3, 8.2, 8.3 and Annex A controls on AI riskMAP, MEASURE and MANAGE functionsSource-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-risk-management-system
Carry out a fundamental rights impact assessment before deploymentImpact assessmentEU AI ActEuropean UnionDeployer / user organisation, Public authority / government bodyLegal requirementArticle 272027-12-02Before deploying most Annex III high-risk systems, deployers that are bodies governed by public law or private entities providing public services, and deployersFundamental rights impact assessment reportClause 6.1.4 AI system impact assessment; Annex A control on impact assessmentMAP 5.1, MAP 5.2Source-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-fundamental-rights-impact-assessment
Significant Data Fiduciaries must appoint a DPO and run impact assessments and auditsImpact assessmentIndia DPDP ActIndiaProvider / developer, Deployer / user organisationLegal requirementSection 10Entities notified as Significant Data Fiduciaries, based on factors such as volume and sensitivity of data and risk to individuals, must appoint a Data ProtectiData protection impact assessmentClause 6.1.4 AI system impact assessmentSource-linkedhttps://aipolicytracker.org/obligations/india-dpdp-significant-data-fiduciary-duties
Operators of high-impact AI must establish and operate a risk management planAI risk managementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for TrustSouth KoreaProvider / developer, Deployer / user organisation, Public authority / government bodyLegal requirementArticle 34(1)2026-01-22An AI business operator that provides high-impact AI, or a product or service using it, must establish and operate a plan for managing the risks of that AI. HigHigh-impact AI risk management plan; High-impact classification recordClause 6.1.2, 6.1.3, 8.1MAP 1.5, MANAGE 1.3Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-34-high-impact-ai-risk-management-plan
Operators of high-impact AI should assess its impact on fundamental rights before useImpact assessmentFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for TrustSouth KoreaProvider / developer, Deployer / user organisation, Public authority / government bodyVoluntaryArticle 352026-01-22An AI business operator that provides high-impact AI, or a product or service using it, is to make efforts to assess in advance the impact the AI may have on peFundamental-rights impact assessment for high-impact AIClause 6.1.4; Annex A.5.2, A.5.4MAP 5.1, MAP 5.2Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-35-high-impact-ai-impact-assessment
Conduct a data protection impact assessment for high-risk processing using new technologiesImpact assessmentUAE PDPLUnited Arab EmiratesProvider / developer, Deployer / user organisationLegal requirementArticle on data protection impact assessment (reviewer to cite article number)Before processing that uses modern technologies and is likely to pose a high risk to privacy, controllers must assess the impact on personal data protection, coData protection impact assessmentClause 6.1.4 AI system impact assessmentSource-linkedhttps://aipolicytracker.org/obligations/uae-pdpl-impact-assessment-new-technologies

The recorded risk-management and impact-assessment duties an approved use case may trigger.

Document outline (DOCX)

  1. AI use-case intake and triage procedure
  2. 1. Register the request
  3. 2. Screen for prohibited practices
  4. 3. Classify and route
  5. 4. Record the decision
  6. Prohibited practices on record
  7. Do not deploy or provide AI for prohibited practices
  8. Developers and deployers must not use AI to incite self-harm, harm to others or crime
  9. Governmental entities must not use AI for social scoring
  10. Governmental entities must not use AI for biometric identification from public data without consent where it infringes rights
  11. Developers and deployers must not use AI with the intent to unlawfully discriminate against a protected class
  12. Developers and distributors must not build AI intended to produce child sexual abuse material or unlawful sexual deepfakes

How to use it

  1. 1Request the files. Enter your name, company and work email in the form on this page. The XLSX and DOCX download links arrive by email and work for 7 days.
  2. 2Read the README page. It states the version (v1), the dataset it was built from and the licence, so anyone reviewing your copy knows which records it reflects.
  3. 3Fill in your rows. Complete the "Intake" sheet for your own systems. Dropdowns, formulas and colour rules are already set.
  4. 4Check the duties against your situation. The "Prohibited-use screen" and "Risk duties" sheets list the recorded duties with their source references. Mark which apply to you and follow each link to the official text.
  5. 5Complete the document. Work through the DOCX sections (AI use-case intake and triage procedure, Prohibited practices on record) and replace each placeholder with your organisation's answer.
  6. 6Keep the evidence and watch for new versions. Link each completed row to the evidence that supports it. When the law on record changes, this template gets a new version and a changelog on this page.

Duties this template covers (11)

Each is cited in the file with its source reference and a link back to the record.

Legal basis

  • EU AI Act European Union · Partially applicable

Version history

Versions of AI Use-Case Intake and Triage Form
VersionBuiltDatasetWhat changed
v1c6967b988bb5First version, built from dataset c6967b988bb5.

Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.

Frequently asked questions

What is in the AI Use-Case Intake and Triage Form?

Intake register with routing and a flag for a failed screen. Prohibited-use screen: every prohibited practice on record, one question each. Procedure document with the routing table. Risk and impact-assessment duties sheet.

Which duties does it cite?

11 recorded duties from EU AI Act, Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, Texas Responsible AI Governance Act (TRAIGA) and UK AI regulation framework, including Article 5, Article 9, Article 34(1), Business and Commerce Code Section 551.052, Business and Commerce Code Section 551.053 and Business and Commerce Code Section 551.054. Each row links to the record, and the record to the official source.

Who is it for?

The duties it cites fall on provider / developer, deployer / user organisation and public authority / government body. Whoever owns AI governance for those roles usually completes it, with the system owner supplying the facts.

Is it free?

Yes. Request the XLSX and DOCX with your work email on this page; the download links arrive by email, valid for 7 days. No account and no charge. Licensed CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

How will I know when it changes?

Version v1 was built on 5 October 2026. The library is rebuilt daily; when a change to the records reaches this template it gets the next version, a changelog below and an entry in the templates feed.

Does completing it make us compliant?

No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.

Disclaimer: informational only, not legal advice. Verify every claim against the linked official sources and consult a qualified lawyer before acting.