Why you need one now, not after the first incident
Proofpoint surveyed more than 1,400 security professionals in January 2026. In the UK, 94% of organisations had AI assistants deployed beyond pilot stage. 31% had already experienced a suspected or confirmed AI-related incident. Only 36% said they were fully prepared to investigate one. Read those three numbers together. Almost everyone is using AI. A third have already had a problem. Two thirds could not properly investigate it if it happened tomorrow.
A risk register does not stop incidents. It does two other things. It forces you to write down what you are actually running, and it gives you a place to put the answer to "what would we do if". When a director, an auditor, an insurer or the ICO asks how you manage AI risk, the register is the first document they will want to see. If you have one, the conversation is about its contents. If you do not, the conversation is about why not.
The UK government's own AI Management Essentials tool, finalised in February 2026, asks organisations whether they maintain a record of AI risks and how they are managed. It is voluntary today. Public sector buyers are already starting to ask suppliers the same questions in tenders. A register you built six months ago answers that question in one attachment.


