Glossary · W

What kinds of AI should be registered?

Commonly this includes AI tools and platforms, internally built models and applications, third-party AI embedded in vendor products, and AI agents — recorded at the level of the specific [use case](/glossary/ai-use-case) where that distinction changes the risk.

Related terms

What's the difference between an AI registry and an AI inventory?

The terms are often used interchangeably, but where they're distinguished, an [AI Inventory](/glossary/ai-inventory) emphasizes discovery — listing every AI tool actually in use, including unapproved ones — while a registry emphasizes registration and control, recording systems that have gone through intake, review, and approval. An inventory typically feeds a registry.

What's the most common mistake organizations make with AI privacy?

Treating it as a one-time data classification exercise performed at adoption, rather than an ongoing practice — this misses exposure that continues to occur through everyday use, including live prompts, retained logs, and conversation memory that persist well after the initial review.

Why do agents need governance that single-response AI systems don't?

Because an agent chains multiple steps together, often without a human reviewing each one, a gap in oversight at any single step can propagate forward through the rest of the chain before anyone notices — unlike a single AI interaction, where there's one clear moment someone could review before acting on the output.

Why isn't reviewing an AI model's training data enough to address AI privacy?

Because AI systems can expose sensitive information well after training — through live prompts users type in, retained conversation memory, inference-time context, and logs — meaning most ongoing exposure happens during everyday use, not only during the training process.

Workflow Automation

The automation your team reviewed and approved three years ago probably didn't have an AI model reading customer emails. It might now — and nobody re-ran the review.

See What kinds of AI should be registered? in practice

Questa AI anonymizes sensitive data before it reaches any AI model — across documents and live prompts, with governance and data-residency control.

Contact

Contact Us

Have questions or ready to explore how Questa AI can transform your business?