How to keep a reliable record of where AI is running in your projects and hiring
AI arrives feature by feature, not as a project. Here is how to keep an operational record of where it runs, who owns it, and what it changed — before the December deadlines make it urgent.
Ask an operations leader how many AI systems their organisation runs and you will usually get a confident number. Ask which team turned each one on, who owns the output, and what a customer or candidate was told about it, and the confidence disappears.
That gap is not a governance failure in the usual sense. Nobody skipped a control. It is a record-keeping failure, and it has the same shape as every other one: the information exists, but it is distributed across tools, inboxes, vendor release notes, and people's memory, so it can only be assembled after somebody asks for it.
The reason to close the gap now is not philosophical. Reporting deadlines are landing, and the ones that matter most for project and people teams fall in December 2026 and December 2027. The work those deadlines require is not difficult, but it is slow to reconstruct and easy to accumulate.
AI did not arrive as a project
Almost no organisation adopted AI the way it adopts software. There was no procurement cycle, no implementation plan, no owner named in a project charter. It arrived in increments, inside tools bought for something else, often in an update nobody read.
In a typical delivery and people operation it is already running in:
- summaries and drafted status updates generated from project activity
- automation rules that classify, route, prioritise, or assign incoming work
- candidate screening, ranking, and shortlisting in the hiring pipeline
- drafted first responses in the service desk and customer communication
- generated content in documents, knowledge bases, and marketing
- assistants that answer questions over internal data
Each one was a small decision, usually a sensible one, made by somebody close to the work. The problem is only visible in aggregate: there is no single place where those decisions are written down, and the person who made each one may no longer be in the role.
The questions nobody can answer yet
The test is not whether you have an AI policy. It is whether you can answer six questions from your systems, today, without convening anybody:
- Which AI features are switched on, in which parts of the business?
- Who turned each one on, and when?
- Which of them touch customers, candidates, or employees?
- What were those people told, and from what date?
- When AI assisted a decision, which human owns it?
- When a feature changed behaviour, is the change dated and attributable?
Most organisations can answer the first question approximately and the rest not at all. That is worth noticing, because these are not exotic compliance questions. They are the same questions you would ask about any operational change: what changed, who decided, who owns it, what was communicated. The fact that they are hard to answer for AI says something about where AI adoption sits relative to the rest of the operating record.
A register in a spreadsheet will not survive
The instinctive response is to open a spreadsheet and build an AI register. It works for about a quarter. Then a vendor ships an update, a team enables a feature, somebody leaves, and the register becomes a document that describes the organisation as it was in the spring.
Registers decay for the same reason status reports arrive late: they are a copy of the operating record rather than the record itself. Anything maintained by remembering to maintain it will drift.
The alternative is to keep the information where the work already lives. That is less ambitious than it sounds, because the mechanisms are ones delivery teams already use:
- A field, not a document. A custom field on the work — a checkbox or dropdown marking AI-assisted output, with the responsible owner attached. In Orbyna, custom field values are searchable and can be used in automation conditions, so the marking is queryable rather than decorative.
- An execution log, not a memory. Where automations act, the automation log records which rules ran, on which issues, and whether they succeeded or failed. That is the difference between "we use automated routing" and being able to show what it did last Tuesday.
- History with before and after. Issue history captures every field change with its previous value, new value, and timestamp. When somebody asks what changed and when, that is the answer, and it was recorded without anybody deciding to record it.
- Permissions as a boundary. Project roles — Admin, Member, Viewer — determine who can enable and configure. Access control is the cheapest form of AI governance, because it limits how much there is to track.
- One control plane. Orbyna's Settings & Administration layer holds reference data, custom fields, execution logs, permissions, and traceable change history in one place, rather than nine tools each with a partial view.
The same applies on the people side. Hiring is where AI adoption and regulatory exposure overlap most directly, and where an ad-hoc record is least defensible. In Orbyna's HRMS, the recruitment pipeline moves candidates through defined stages — Applied, Screening, Interview, Offer, Hired, Rejected — on the same identity and permission model as the rest of the workspace. Whatever assists a screening decision, the stage change, its timing, and its owner are already on the record.
What the new rules actually ask for
The regulatory picture moved twice this year, and both moves matter for planning.
Since 2 August 2026, the EU AI Act's transparency obligations have been applicable, and the AI Office's supervision and enforcement powers have been exercisable. Those duties are deliberately broad: they are not limited to high-risk systems, and they cover telling people when they are interacting with an AI system and marking content that AI generated.
Then the Digital Omnibus — published in the Official Journal on 24 July 2026 and in force from 27 July — deferred several of the harder deadlines:
- December 2026 — machine-readable marking of AI-generated content, and the end of the grace period for systems already on the market before August.
- December 2027 — obligations for the high-risk category that includes recruitment and employment screening.
- August 2028 — high-risk AI embedded in safety components of regulated products.
This was reported as relief, and for engineering roadmaps it is. For operations it is better read as a scheduled deadline for work that takes longer than it looks. A candidate-ranking feature switched on quietly this year is a system you will have to describe in detail in 2027, and the description will be far easier if the record was accumulating the whole time rather than being reconstructed from memory.
Build the record while it is still small
The useful version of this work is unglamorous and finite. It is a list, an owner per line, and a decision about where the list lives.
Start where people outside the organisation are affected — service desk replies, published content, candidate screening, anything conversational. Confirm what each one discloses today, fix what is missing, and record the date you fixed it. Then work inward to internal automations, which carry lower exposure but are the easiest place to lose track of what is running.
- Inventory every AI feature that is switched on, including ones that arrived in a vendor update
- Name a human owner for each system that touches customers, candidates, or employees
- Mark AI-assisted work with a field on the work itself, not a line in a separate register
- Keep AI-assisted actions in the same dated history as everything else, not a parallel log
- Review screening and shortlisting features now, well ahead of the December 2027 date
The organisations that will struggle are not the ones using the most AI. They are the ones whose AI usage lives entirely outside their operating record, so that every question — from a regulator, a customer's procurement team, or their own board — starts with an investigation.
Fragmentation is what makes this expensive. Eleven tools mean eleven inventories, eleven administrators, and eleven partial answers to assemble every time somebody asks. The operational cost of that fragmentation was already high before anyone was asking about AI.
Talk to us about consolidating your operating record, see how the Project Management System keeps automations and history attributable, or read Governance works better when it lives inside the work.