🎉 Launch offer — 20% off workbooks & bundles, applied automatically at checkout. Security Program Pillars guides are at list price.
ciso.diy
Pillar 06 Companion — The 2026 AI Risk Register preview
Security Program Pillars AI risk registerpillar 06AI governanceEU AI Act

Pillar 06 Companion — The 2026 AI Risk Register

The register that inventories every AI system, model and agent in your business, classifies it against the 2026 regulatory map, scores it on autonomy and blast radius, and routes remediation to real suppliers. Full schema, five classification rule tables, 41 build prompts.

What this actually gives you

  • The Digital Omnibus on AI entered into force 27 July 2026 and pushed the high-risk regime for stand-alone Annex III systems out to 2 December 2027, with embedded Annex I systems following on 2 August 2028.
  • What survived every amendment: Article 50 transparency, the Article 4 AI-literacy duty, and the 2 December 2026 marking obligation for systems already on the market.
  • The line to use with your board: the high-risk regime moved by sixteen months, and a team that restarts this work in mid-2027 restarts it with fifteen months less evidence history than a team that never stopped.
  • Texas TRAIGA has been enforceable since 1 January 2026 with no revenue or compute threshold, and carries an enforcement safe harbor for substantial compliance with the NIST AI RMF.

The engineered companion to Pillar 06 — The Fractional CISO Operating System. Pillar 06 is the practice: operating model, pricing ladder, the first 90 days, the board deck. It tells you the register is the deliverable that outlives the engagement. This is how you build the thing so that claim is true. Sold on its own, and as a pair.

Every deadline moved. None of the work went away. The Digital Omnibus on AI entered into force on 27 July 2026 and pushed the high-risk regime for stand-alone Annex III systems out to 2 December 2027, with embedded Annex I systems following on 2 August 2028. Most teams read the headline and stopped. What survived every amendment: Article 50 transparency, the Article 4 AI-literacy duty, and the 2 December 2026 marking obligation for systems already on the market. And under all of it, the work no delay touches — inventory, classification, documentation, human oversight. Which is to say, the register. The line to use with your board: the high-risk regime moved by sixteen months, and a team that restarts this work in mid-2027 restarts it with fifteen months less evidence history than a team that never stopped. Evidence history is the one thing you cannot buy late.

One instrument, most of the US patchwork. Texas TRAIGA has been enforceable since 1 January 2026 with no revenue or compute threshold, and it carries an enforcement safe harbor for substantial compliance with the NIST AI RMF. Build the register against AI RMF, crosswalk it to ISO 42001 and the AI Act, and one register answers to several regimes rather than being rebuilt per statute.

This is a build system, not another workbook. It hands you the data model, the classification rule tables, the scoring method, and 41 sequenced prompts that take you from an empty repository to a working AI risk register you own outright. It does not hand you a finished application, and that is deliberate: a shipped app dates in nine months, buyers land on Workers, Postgres and isolated SQLite in roughly equal numbers, and a register you generated yourself is one you can extend when the first field you need turns out to be the one nobody modelled.

Five planes, built in order, each useful on its own — which matters more than it sounds, because a register that only ever reaches plane 1 is still the most valuable AI governance artifact most organizations have. Inventory across six discovery lanes, all landing in staging so a human promotes what enters the register. Classification through deterministic rule tables where the model proposes which rule applies and never the outcome. Risk, scored on an autonomy ladder times blast radius times reversibility. Evidence, append-only and hash-chained. Conduct, where board packs carry a query fingerprint per figure and remediation routes outward as a supplier-ready brief. The rule that makes the whole thing defensible: every write originating from a model sets ai_suggested = 1 and never human_decided = 1, so when an acquirer's diligence team asks who accepted a risk, the answer is a name and a timestamp rather than a workflow.

Why generic 5×5 scoring fails on AI systems. A likelihood-impact matrix cannot tell the difference between a chatbot that drafts marketing copy and an agent with write access to ticketing, a spend limit and the ability to email customers. Both score medium-medium. Only one can quietly destroy something over a long weekend. So the register applies three multiplicative modifiers — an autonomy ladder from A0 (suggests only) to A4 (acts on production autonomously), blast radius, and reversibility — and all three are derived rather than entered. Blast radius comes from the agent's granted tool scopes, not from anyone's description of what it does, which means an engineer adding a scope on a Tuesday moves the risk score without anyone touching the risk row. If you take one thing from this guide, take that.

From a scored risk to a real remediation. A register earns its keep the moment a risk turns into work someone actually does, and in a mid-market organization most of that work is a procurement problem rather than an engineering one — the gap is not that nobody knows the egress path is uncontrolled, it is that nobody has a shortlist, a budget, or a quote cycle they can stomach. So the register generates the brief: mark a treatment as needing a supplier and the system resolves a supplier category, then builds a requirements document out of register data, with an explicit redaction test keeping everything else out. Walk into procurement with that and a three-month evaluation compresses into a three-week one. It is the most immediately monetisable output of the whole build for anyone running a fractional practice, and the briefs can route straight to the advisor network.

Your risk register is the best thing an attacker could steal. A completed register is a manifest of every AI system you run, every credential scope your agents hold, every kill-switch address, every unremediated finding with its due date, and a written record of every risk you accepted and why. It holds your pentest results. Most GRC platforms put exactly that package in a multi-tenant cloud behind someone else's authentication and someone else's incident response. Tier 2 of the deployment guide covers the isolated Register Node: coreboot firmware with the management engine neutralised, hardware-held boot, admin and signing keys, signed export as the only egress, and a local model behind the AI provider interface. Hardware is sold separately and you do not need ours — any coreboot-capable mini-PC and any OpenPGP smartcard satisfies the design, and the key-role table is the part that matters. NovaCustom and Nitrokey are what we run and what we can answer questions about.

Eleven steps, forty-one prompts. Every prompt is written to be pasted verbatim into a Claude Code session, with acceptance criteria for each step and three recovery prompts for the places builds typically break. A focused practitioner reaches the end of step 4 in a day and has a register worth using.

Can it run fully offline? Yes, and step 10 is written for it. Signed export is the only egress, inbound bundles are verified data and never executed, and the AI layer sits behind a provider interface so a local model drops in. Classification never depended on a model in the first place, so the isolation costs you less than you would expect.

Includes the 27-page guide, the 41-prompt pack, the full SQL schema with indexes, the read-only query view and Cloudflare D1 notes, seed data with ten AI systems and three shadow candidates, five classification rule tables — EU AI Act, NIST AI RMF, ISO 42001, TRAIGA and state ADMT, every rule versioned, dated and carrying its citation — the tool-scope blast map, the treatment-to-supplier routing map across all fourteen risk categories, the Register Node build sheet, and a 20-item pre-flight checklist. Regulatory content current as of September 2026 and dated throughout, so the numbers hold up in a live conversation. Rule tables ship as diffable changelogs naming which rule ids moved and why, rather than wholesale replacements.

And where it federates. This is a domain register: AI systems, agents and models. The Enterprise Risk Register is the hub the whole estate feeds into, and the two share canonical entity names on purpose — so owning both gives you one register with two ingest lanes rather than two that disagree. The Register Family is both plus the practice that owns them.

The managed fractional CISO pillar is the done-for-you version: the register stood up on your estate, the classification work done, and the board cadence owned by a named human.

What's included

  • PDF — fully editable
  • Build System (.zip) — 41-prompt pack, schema, five rule tables, routing maps — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-01
Pages 27