What is an AI agent registry?
An AI agent registry is an organization's system of record for every AI agent it runs. Each entry gives the agent a unique identity and records its purpose, accountable owner, vendor, version, the data and tools it may use, its current status, and its review history, so the organization always knows what AI is acting on its behalf.
Registry, inventory, and catalog
The terms overlap but are not identical. An AI inventory is a list of AI systems in use, often kept in a spreadsheet for compliance. A registry goes further: it issues each agent an identity that other systems can check at runtime, and it tracks status changes such as approved, restricted, paused, or retired. A public catalog, such as CHAI's registry of health AI products, describes products a vendor offers. It is not a hospital's record of what is deployed inside its own walls.
The NIST AI Risk Management Framework treats the inventory as a basic governance control. GOVERN 1.6 calls for "mechanisms in place to inventory AI systems," resourced according to organizational risk priorities. NIST SP 800-53 control CM-8 makes a similar demand for all system components, asking for an inventory that "accurately reflects the system" and "includes all components."
Why hospitals keep one
In US healthcare, several obligations assume the organization knows what AI it uses:
- Section 1557. 45 CFR 92.210(b) gives covered entities "an ongoing duty to make reasonable efforts to identify uses of patient care decision support tools" that use race, color, national origin, sex, age, or disability as inputs. Identification is hard without a registry.
- HTI-1 source attributes. Certified EHRs must let users access source attributes for predictive decision support interventions, which gives hospitals a ready set of fields to record.
- Joint Commission and CHAI guidance. The Responsible Use of AI in Healthcare guidance expects a governance structure that oversees selection, implementation, and lifecycle management of third-party and internally developed AI tools.
What a useful entry contains
A practical entry for an agent usually includes: a unique agent ID, name and version, vendor, accountable owner, intended use and out-of-scope uses, data sources, PHI exposure, the specific actions the agent may take, required human approvals, validation and monitoring results, status, and a link to its audit trail. Agents add fields that older model inventories lack, especially the tools an agent can call and whose authority it acts under.
The most common failure is a registry that is only documentation. If agents can act without being registered, the record drifts away from reality. Tying runtime permissions to the registry, so an unregistered or paused agent cannot act, keeps the record accurate. Review cadence matters too: entries should be revisited at each vendor update, at scheduled revalidation, and whenever an incident involves the agent.
How Skovos handles this
Skovos keeps the registry as the live source of truth. Every agent gets a registered identity, owner, and scopes, and its permission checks run against that entry, so recalling an agent in the registry means every later permission check denies it.
Frequently asked questions
Is an AI agent registry required by law?
No US law uses the phrase. But Section 1557's duty to identify decision support tools, HIPAA risk analysis, and accreditation-oriented guidance all assume a current inventory of AI in use.
Can a spreadsheet work as a registry?
For a handful of tools, briefly. It cannot issue identities, enforce status, or show what an agent actually did, so it tends to fall out of date once agents multiply.
What is the difference between a model registry and an agent registry?
A model registry, common in machine learning operations, tracks model versions and training artifacts. An agent registry tracks deployed agents as actors: who owns them, what they may do, and whether they are currently allowed to act.
Who should own the registry?
Usually the AI governance function, with entries owned by the business or clinical leaders accountable for each tool.
Related reading
- AI agent registry for hospitals: fields and template
- AI agent inventory for health systems
- Best healthcare AI governance platforms in 2026
Sources
- NIST, AI Risk Management Framework (AI RMF 1.0), GOVERN 1.6: https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
- NIST SP 800-53 Rev. 5, CM-8 System Component Inventory (OSCAL catalog): https://github.com/usnistgov/oscal-content/tree/main/nist.gov/SP800-53/rev5
- 45 CFR 92.210, Nondiscrimination in the use of patient care decision support tools: https://www.law.cornell.edu/cfr/text/45/92.210
- ONC/ASTP, HTI-1 Decision Support Interventions fact sheet: https://www.healthit.gov/sites/default/files/page/2023-12/HTI-1_DSI_fact%20sheet_508.pdf
- Joint Commission and CHAI, Guidance on the Responsible Use of AI in Healthcare: https://digitalassets.jointcommission.org/api/public/content/dcfcf4f1a0cc45cdb526b3cb034c68c2