Skip to content

Version 1.4, October 2026

The method for the AI register

Published under a Creative Commons Attribution 4.0 license: you may reuse it, quote it and apply it, citing the source. These are the definitions Ojja applies in every readout, every snapshot and every feed. Each Ojja feature described here carries the version in which it arrives.

CC BY 4.0

Free reuse, source cited. Each readout and each snapshot cites the version it applies.

Why a public method

AI arrives in business software through updates, often enabled by default, sometimes paid for without being used. Nobody can say how much AI a company pays for, what lies dormant, what is duplicated, what was enabled without a decision, because nobody has defined the terms. This page defines them. A method that is not public is not a method.

The scope: the AI in place

A company's AI in place is the set of artificial intelligence features, agents and applications that it pays for, that it has deployed or that its employees have connected to its data: the features included in its licenses, the agents built or enabled on its platforms, the assistants and subscriptions taken out by its teams, the applications authorized by an employee. A feature is a unit named by the vendor, attached to a product and an edition. The scope is read in the company's tools (licenses, settings, inventories, aggregated usage reports, vendor announcements), never in its content. The dated inventory of this AI in place is the company's AI register.

  • AI register#cadastre

    The dated inventory of this AI in place is the company's AI register.

The origin of an activation

Each line of the register carries its origin: the vendor (enabled by an update or by default), the administrator (enabled by a setting), or the employee (authorized by an employee on their data).

  • origin of an activation#origine

    Each line of the register carries its origin: the vendor (enabled by an update or by default), the administrator (enabled by a setting), or the employee (authorized by an employee on their data).

The three statuses of a feature

  • Paid#payee

    at least one seat or subscription that includes it is billed to the company.

  • Enabled#activee

    the feature is available to at least one user, through an administrator setting or a vendor default.

  • Used#utilisee

    at least one user has used it over the last twenty-eight days, according to the vendor's aggregated usage reports.

The three statuses are independent and are never merged. A feature can be paid for without being enabled, enabled without being used, used without having been decided.

The three counts of the free readout (v0.9)

The free readout counts, without detail, three things read in your tools:

  • three counts of the free readout#trois-comptes

    The free readout counts, without detail, three things read in your tools: AI connected by your employees to your data: the applications an employee has authorized, with the data they reach. AI enabled by your vendors without a decision: the features put into service by a vendor update, with no decision recorded by the company. AI that trains its models on your data or sends data outside the EU: according to the catalog, edition by edition; “not yet verified” when the fact is not verified yet.

  1. AI connected by your employees to your data: the applications an employee has authorized, with the data they reach.
  2. AI enabled by your vendors without a decision: the features put into service by a vendor update, with no decision recorded by the company.
  3. AI that trains its models on your data or sends data outside the EU: according to the catalog, edition by edition; “not yet verified” when the fact is not verified yet.

Facts only: no rating, no conclusion about your situation.

The four measures

  • Spend#paye

    the yearly sum of licensed seats multiplied by the price per seat, feature by feature, plus the consumption billed by usage or in credits over the period, read or declared, always kept apart from licenses. The price is the negotiated price when the company provides it, otherwise the vendor's list price on the date of the snapshot; the provenance is shown.

  • Dormant#dormant

    the yearly sum of licensed seats not used over twenty-eight days multiplied by the price per seat, with the date on which they can be reclaimed: the contract anniversary, or its end for a multi-year commitment. When the vendor exposes usage only at license level, the measure says so.

  • Duplicate#doublon

    two paid features that cover the same use for the same population. The amount counted is the cost of the least used feature in the group. A suspected but unconfirmed duplicate does not enter the figure.

  • Enabled without a decision#active-sans-decision

    the number and cost of the features enabled by the vendor or authorized by an employee without any company decision having been recorded, with the subtotal of those that touch employee, candidate or customer data. This measure is derived from the facts; it is not declared.

The adoption rate

The adoption rate of a feature is the number of active users over twenty-eight days divided by the number of users who have access to it. Dormancy is its translation into euros. We use the vendor's definition when it publishes one. Usage is read per tool, never per person, and is never reported for a group of fewer than ten people.

  • adoption rate#taux-adoption

    The adoption rate of a feature is the number of active users over twenty-eight days divided by the number of users who have access to it.

Worth its price: the time it could save (v1.0)

The question is: “Is it worth what it costs?” The measure is the time it could save.

  • time it could save#temps-a-gagner

    For a licensed tool: the time each person who uses it must save per month for the tool to cover its price (cost read, divided by the number of people who use it, divided by a reference or declared hourly cost).

  • worth its price#vaut-son-prix

    Four answers: worth its price (even in the cautious case); worth its price if usage follows (only in the favorable case); not worth its price (even in the favorable case); too early to tell (usage not read or time not entered).

  • For a licensed tool: the time each person who uses it must save per month for the tool to cover its price (cost read, divided by the number of people who use it, divided by a reference or declared hourly cost).
  • For an agent: the minutes it must save per successful task, next to the time this task takes in the company today, entered and dated before deployment.
  • Four answers: worth its price (even in the cautious case); worth its price if usage follows (only in the favorable case); not worth its price (even in the favorable case); too early to tell (usage not read or time not entered).
  • Benchmarks are always marked as such: “measured elsewhere” (a published range, sourced, dated) and “announced by the vendor”. They are never mixed with what is read in the company.
  • The counter gives the number of tools and agents per answer. Never a total, never a percentage of return.

Exposure

The exposure of a feature is the facts recorded on its line (employee, candidate or customer data touched, transfers outside the European Union, training on your data, enabled without a decision, action without human validation, population concerned) and the frameworks that the public catalog links to this type of feature (data protection, the Artificial Intelligence Act, cybersecurity (NIS 2), information and consultation of employee representatives), each with its date of application, or “upcoming”. The method never concludes: no risk level, no role, no assessment of whether a text is being followed. It names the points to review with your counsel.

  • exposure#exposition

    The exposure of a feature is the facts recorded on its line and the frameworks that the public catalog links to this type of feature, each with its date of application, or “upcoming”.

The five verbs

Each line calls for a decision, and only one at a time:

  • adopt#adopter

    Adopt: it is used, and decided.

  • regularize#regulariser

    Regularize: it is used, without a decision.

  • reclaim#reprendre

    Reclaim: it is paid, and not used.

  • turn off#eteindre

    Turn off: it has neither usage nor decision.

  • consolidate#consolider

    Consolidate: it overlaps with another one.

The verb is proposed by the method and decided by the company, with an author, a date and a reason. Ojja executes nothing: the administrator applies the decision in the tool, and the next snapshot records that it is done.

The activation circuit (v1.0)

Nothing new arrives without going through a decision. A new feature announced by a vendor appears in the feed; it goes on hold in the register; the company can defer it as long as the vendor allows; it decides; the portal announces it to employees with its rule (v1.1); the next snapshot records that it is done.

The roadmap and the log (v1.0)

  • roadmap#feuille-de-route

    The roadmap: the vendors' dated announcements about your tools, the deadlines for deferral, the activations scheduled by the company, the next version of its rules.

  • log#journal

    The log: what has changed over the period, the decisions taken, the new versions of the rules.

Complete for the person who owns AI; filtered for employees, who see only what is announced to them.

The cadence (v1.0)

Your tools are read every day or every week, depending on the tool; an alert on five events as soon as they are read; a dated snapshot every week to decide. The five events: new AI application connected, usage-based billing enabled, a vendor's terms changed, new model behind a feature, new data access. An event that a vendor only lets us read once a week is shown as such, tool by tool.

  • cadence#cadence

    Your tools are read every day or every week, depending on the tool; an alert on five events as soon as they are read; a dated snapshot every week to decide.

Reading: the directory for breadth, the vendor for depth

  • Through the directory (v0.9 for Microsoft Entra, v1.2 for Google Workspace): each single sign-on tool, and the applications authorized by employees with the data they reach. Sign-in logs, where the company's plan provides them.
  • Vendor by vendor, through the administration access it opens: licenses, settings, enabled features, aggregated usage reports, inventory of agents.
  • What Ojja does not read yet is declared, and each line then carries the mention “declared”.

Two reading regimes

  • “We never have access to it”#jamais-acces

    when the vendor offers a right limited to metadata, Ojja asks only for that one.

  • “We never touch it”#jamais-touche

    when the only key available also opens content, Ojja accepts it on four conditions: a closed list of endpoints without content, published in the manifest; each call logged and visible to the company; the key stored in France, with minimal rights, rotation and one-click revocation; a switch to a limited key as soon as the vendor offers one.

The regime is shown tool by tool, before authorization and on the trust page. In both cases: we read registers and configurations, never your content.

The four tags of a vendor feature

For each feature announced by a vendor, four facts are enough to know whether it deserves a decision: is it enabled by default; does it touch employee, candidate or customer data; which framework the catalog links to it; how it is billed (included in the license, by usage, in credits). This is what the feed publishes, vendor by vendor.

  • tags#etiquettes

    For each feature announced by a vendor, four facts are enough to know whether it deserves a decision: is it enabled by default; does it touch employee, candidate or customer data; which framework the catalog links to it; how it is billed (included in the license, by usage, in credits).

Provenance

Each fact carries its provenance: extracted (read in a tool, with the source and the date), declared (provided by the company, with the author and the date), inferred (calculated by a named rule from other facts).

A fact that the catalog has not verified yet is shown “Not yet verified”. A fact that the vendor does not document is shown “Not documented by the vendor”, with the source consulted and its date. No field is hidden.

  • extracted#extrait

    read in a tool, with the source and the date

  • declared#declare

    provided by the company, with the author and the date

  • inferred#deduit

    calculated by a named rule from other facts

How a fact enters an AI fact sheet

An AI agent records the fact from a public page of the vendor and copies the sentence that establishes it. A second AI agent, which has not seen this record, reads the page again. The fact is published only if both readings agree and if the quoted sentence is found in the dated copy of the page; otherwise, it is shown “Not yet verified” until a documented arbitration. When two pages of the vendor say opposite things, the fact sheet publishes both, under “Two vendor statements”, without choosing. Every week, the source pages are read again; a modified page reopens the record. The types of feature, and the frameworks linked to them, are qualified by a doctor of law. The version of the verification chain appears on each fact sheet.

What the method does not do

  • It produces no rating and no level: counts, euros and times, never a weighting.
  • It never says whether a company follows a text.
  • It never reads an email, a document, a meeting or any content.
  • It does not recommend any purchase.

It measures; how the law applies to the company's situation is for its counsel to determine.

Versions

  • 1.4, October 2026: the verification of AI fact sheets, by two AI agents, with the vendor's quotation and a dated copy; “Two vendor statements”.
  • 1.3, October 2026 (in French): the cadence, every day or every week depending on the tool; the mentions “Not yet verified” and “Not documented by the vendor”.
  • 1.2, September 2026 (in French): the three counts of the free readout; the origin of an activation; “worth its price” and the time it could save, which replace value and its letters; the five verbs redefined by the facts; the activation circuit; the roadmap and the log; the cadence; reading through the directory; the two reading regimes; each feature with its version.
  • 1.1, September 2026 (in French): exposure in documentary mode.
  • 1.0, September 2026 (in French): first publication.

Versions are dated and kept; each readout and each snapshot cites the version it applies.

Cite the method

Ojja, The method for the AI register, version 1.4, October 2026, CC BY 4.0 license, https://ojja.ai/en/method/

Last updated October 9, 2026

Get the feed

Every week, vendor announcements and legal news, with four tags and the dated primary source. Public and free.

One email a week. One-click unsubscribe in every email. Your address is used only to send the feed.

Sent in French for now.

Privacy (in French)