Algorithm register vs AI register vs the EU database

"Register" is doing three different jobs in AI governance right now — public transparency, regulatory filing, and internal operations. Confusing them leads teams to publish what they should not or skip what they must. Here is the map.

Updated July 24, 2026 · Informational guidance, not legal advice

Three registers, three jobs

  • Public algorithm registers: transparency websites where governments publish the algorithms they use to make decisions about citizens. Amsterdam and Helsinki pioneered municipal registers in 2020; the Netherlands runs a national Algoritmeregister where government bodies publish impactful algorithms; the UK's Algorithmic Transparency Recording Standard plays a similar role for its public sector.
  • The EU AI Act database: the EU-level registration system under Article 49. Providers register high-risk Annex III systems before placing them on the market, and deployers that are public bodies register their use of such systems. Most of it is publicly viewable.
  • Your internal AI register: the operating record of every AI system you provide or deploy — classifications, roles, owners, evidence. Nobody sees it unless you show them; nothing in your program works without it.

The three share a word and almost nothing else: different audiences (the public, the regulator, your own organization), different scopes (government algorithms including non-AI rule-based systems, high-risk Annex III systems only, your entire AI portfolio), and different legal footings (national transparency policy, a binding EU-level duty, and operational necessity).

Which ones actually apply to you

For a private product company, the answer is usually: the internal register always, the EU database sometimes, the public algorithm registers almost never — but each deserves the check.

  • Internal AI register: applies to everyone. Every per-system duty in the AI Act — Article 5 screening, Article 6 classification, Article 26 deployer obligations, Article 50 transparency — presupposes it.
  • EU database (Article 49): applies when you are the provider of a high-risk Annex III system — registration happens before market placement, alongside conformity assessment. Providers who concluded a system is not high-risk via the Article 6(3) derogation also register that assessment. As a deployer, the duty to register use applies to public authorities and bodies acting on their behalf — a private SaaS deployer does not file its use there.
  • Public algorithm registers: apply to government bodies in the jurisdictions that run them. Relevant to you if you sell to those bodies — your public-sector customers may need inputs from you to publish their entry, and being easy to publish about is a quiet procurement advantage.

The direction of travel

Public registers started as municipal experiments and became national infrastructure within a few years, and the EU database makes high-risk registration a standing legal duty from December 2, 2027, when the Annex III regime applies. Transparency expectations flow downstream: enterprise buyers increasingly ask vendors for register-shaped answers even where no law compels publication. An internal register kept audit-ready is what makes every downstream disclosure cheap.

Why the Dutch keep asking about this

If you searched "AI register opzetten" — setting up an AI register — you are in the jurisdiction where this distinction is most alive. The Netherlands runs the most developed national algorithm register, Dutch supervisory authorities have been vocal about algorithmic transparency, and Dutch organizations consequently treat an internal AI register as standard governance hygiene rather than an exotic compliance artifact. The practical setup advice is the same everywhere: inventory your systems, classify each one, name owners, attach evidence, and review on a rhythm — the register is the record that rhythm produces.

One record, three outputs

The efficient architecture is not three parallel documents. It is one maintained internal register, from which the other two are projections: when a system becomes a high-risk provider situation, the Article 49 filing is an export of fields you already keep; when a public-sector customer needs material for their algorithm register entry, that is an export too. Organizations that maintain the internal record produce the public-facing ones in an afternoon; organizations that do not, reconstruct history under deadline.

Set up your internal register today

The free Attevera template gives you the 14 fields per system with a realistic filled-in example — the internal record the other registers project from.

Get the free template

Frequently asked questions

Is the EU AI Act database public?

Largely yes — high-risk system registrations are publicly accessible, with a restricted section for sensitive areas such as law enforcement and migration, where access is limited to supervisory authorities. Assume anything you register will be read by customers and competitors as well as regulators.

We're a private company deploying high-risk AI. Do we register in the EU database?

The deployer-side registration duty under Article 49 attaches to public authorities and bodies acting on their behalf. A private deployer does not file its use — but the provider of the system must have registered it, and your internal register should record that check. This is informational guidance, not legal advice.

Do public algorithm registers include non-AI systems?

Often, yes. The Dutch national register and similar initiatives cover impactful algorithms broadly, including rule-based systems that would not meet the AI Act's definition of an AI system. That is one more reason not to treat a public register's scope as a template for your AI Act obligations — the scoping rules differ.

Which register should we build first?

The internal one, always — it is the only one of the three that is both universally applicable and entirely under your control, and the other two are exports from it when they apply. A spreadsheet with one row per system, classifications, and owners is a legitimate day-one version.

Keep reading