A customer security questionnaire arrives with a new question: “List all AI systems that process our data.” Or an auditor asks the same thing in different words. What follows at most mid-size organizations is a scramble. Someone emails the department heads. The answers come back inconsistent and incomplete. And the AI features built into the software you already use, the CRM’s assistant, the meeting tool’s automatic notes, the help desk’s suggested replies, get missed entirely.
An AI inventory register fixes that. It’s one list of every AI tool and AI feature in use, with an owner, the data it touches, and its approval status. It takes about two weeks to build properly, and once it exists, questionnaires take minutes instead of days.
Why the inventory comes before most other governance
You can’t govern what you can’t see. Vendor reviews, the acceptable use policy, regulatory mapping, and incident response all depend on knowing what AI is actually in use. The inventory is the foundation they share. It’s also increasingly what outside parties ask for first, because it tells them quickly whether an organization has a handle on its AI use.
The hard part: AI you didn’t buy as AI
Standalone AI tools are relatively easy to find; someone bought them. The harder category is AI that arrived inside something else:
- AI features in SaaS you already pay for. Vendors add them, sometimes switched on by default, often without a contract change.
- Meeting assistants and note-takers that users connect to their own calendars.
- Browser extensions that read the pages people visit.
- Personal subscriptions expensed as “software.”
- Integrations an employee connected to a business system with their own credentials.
A useful inventory covers all of these, not just the tools IT approved.
Here’s how the assessment asks the question, and the 0 to 4 ladder I score it against:
G4. Do you keep an inventory of AI in use, including AI features inside your SaaS apps?
- No inventory
- We could list the major tools if asked
- Partial inventory, maintained by hand
- Complete inventory with an owner and data types for each tool
- Complete inventory with risk ratings, reviewed regularly, and AI covered in incident response
Level 1 is the honest answer for most organizations: you could name the big ones. The two-week plan below gets you to level 3, with the risk rating that starts you on level 4.
The asset: a two-week plan and the register fields
Days 1 to 3: pull from your systems
- SSO application list: which apps people sign into, and which of them have AI features.
- App consent grants: third-party apps, including AI tools, that users or admins have authorized to access your tenant.
- Expense and procurement records: search for the names of well-known AI vendors and for terms like “AI” and “GPT.”
- Web proxy or DNS logs: which AI sites are being used, and how much. Auditing your own logs for shadow AI walks through this.
- Browser extensions reported by your endpoint management tool.
Days 4 to 6: check your major SaaS vendors
For your top twenty SaaS applications, check the vendor’s documentation or trust center for AI features, then check the admin console to see which are enabled in your tenant. This is where most of the surprises are.
Days 7 to 9: ask the departments
Send department heads a five-question survey: which AI tools or features does your team use, for what, with what kind of data, who uses them, and who pays. Make it clear this is an inventory, not an investigation. People are much more candid when they know they won’t be punished for using an unapproved tool.
Days 10 to 12: consolidate and assign owners
Merge everything into one register and assign a business owner to each row. Where nobody will own a tool, that’s a finding in itself.
Days 13 and 14: review and rate
Review the register with security and your AI council if you have one. Assign risk ratings, decide what happens to anything unapproved, and set the review schedule.
The register fields
- Tool or feature name, and vendor.
- Type: standalone assistant, AI feature in SaaS, custom build or agent, API service, or browser extension.
- Business owner.
- Departments and approximate number of users.
- Data types involved, using the tiers from your acceptable use policy.
- Status: approved, approved with conditions, under review, or not approved.
- Integrations and access to company systems.
- Vendor review status, using the AI questions from your vendor security review.
- Does the vendor train on your data? Yes, no, or unknown.
- Risk rating: low, medium, or high.
- Last reviewed.
- Incident contact: who to call if something goes wrong.
A risk rating rule
- High: confidential or regulated data, write access to company systems, decisions about people, or customer-facing use.
- Medium: internal data, or read-only integrations.
- Low: public information only, with no integrations.
High-risk rows are also where your regulatory mapping should start; see mapping obligations before the pilot.
Keeping it current
An inventory decays quickly. Three habits keep it alive: every approved request through the council’s intake adds a row automatically; every quarter, re-run the day 1 to 3 system pulls to catch anything new; and any vendor announcement of new AI features triggers a check of that row. A quarterly re-scan takes a few hours once the process exists.
Level 4: AI in incident response
Level 4 adds regular review and connects the inventory to incident response. When something goes wrong with an AI tool, such as an exposure, a wrong action by an agent, or a vendor breach, the inventory row should tell you immediately who owns it, what data it touches, and who to call. Pair it with the AI incident runbooks described in observability for AI.
What moving up one level looks like
From 0 or 1 to 2: write down the tools you already know about, with a rough owner for each, even if it’s incomplete. From 2 to 3: run the two-week plan so the list is complete, and add the data types and owners for every row. From 3 to 4: add risk ratings, a quarterly review, and the incident contact for each tool. The first step takes an afternoon. The whole climb to level 4 can happen within a single quarter, because it’s mostly organizing information you can already get from your own systems.
Mistakes I see at this stage
Listing only standalone tools. The AI features inside your existing SaaS are often the larger exposure, and the easiest to miss.
Treating discoveries as violations. If the first inventory leads to discipline, the second will be empty. Offer amnesty for the initial pass, then enforce the policy going forward.
No owners. A row without an owner can’t be reviewed, rated, or retired.
Keeping it in someone’s personal drive. Put it somewhere shared, with change history, that survives staff turnover.
Building it once. An inventory that’s a year old gives false confidence. Schedule the quarterly re-scan.
Where does your team actually stand?
The AI inventory is one of 24 questions in the AI Readiness assessment, which covers six dimensions: data, security, infrastructure, skills, use cases, and governance. The free version is 10 questions and gives you a score in a few minutes.
Get your free AI Readiness Score →
Want to see what the full assessment covers first? Flip through a complete 38-page sample report.
Related guides
- Shadow AI Statistics Are Scary. Your Own Logs Are Scarier
- The 30-Minute AI Council: Lightweight Governance That Sticks
- Two Questions to Add to Every Vendor Security Review This Year
- SOX, State Privacy Laws, and AI: Map Obligations Before the Pilot
- Observability for AI: Logging What Your Assistants Do
Frequently asked questions
What should an AI inventory include?
Every AI tool and AI feature in use, with the vendor, type, business owner, users, data types, approval status, integrations and access, vendor review status, whether the vendor trains on your data, a risk rating, the last review date, and an incident contact.
How do we find AI tools we don't know about?
Pull from your systems: SSO application lists, third-party app consent grants, expense and procurement records, web proxy or DNS logs, and browser extensions reported by endpoint management. Then check your top SaaS vendors for AI features and ask departments directly.
Do AI features inside SaaS apps belong in the inventory?
Yes. They're often the larger exposure and the easiest to miss, because vendors add them to products you already pay for, sometimes switched on by default. Check each major vendor's documentation and your admin consoles.
How do we keep an AI inventory current?
Add a row automatically whenever the AI council approves a request, re-run the system pulls every quarter, and treat any vendor announcement of new AI features as a trigger to review that row. The quarterly re-scan takes a few hours once the process exists.




