AI inventory

BusinessSafety and governancePublished By Simon Budziak

An AI inventory is a maintained record of the AI systems, models, agents, vendors, data connections, and owners a company uses. It gives leaders and operators a factual view of what exists, what each system does, what data it handles, and which controls or reviews apply to it.

It is more useful than a list of licenses. One entry should make it possible to answer who owns the system, which workflow it supports, which data and tools it reaches, what risk review it passed, and when it should be checked again. That information is essential during an incident or a vendor change.

Why does an AI inventory matter?

AI governance cannot work from assumptions. Without an inventory, a company cannot find systems affected by a model change, revoke an agent’s access, or show what controls apply to a customer-facing workflow. The inventory makes ownership and review visible before a failure demands them.

It also exposes shadow AI. The goal is not to punish teams for useful experimentation. It is to discover real use, assign an owner, and decide whether the system should be approved, changed, or removed.

What keeps an inventory from going stale?

Attach updates to normal delivery and review work. Creating a system, adding a data connection, approving a vendor, changing permissions, or retiring a workflow should update the same record. An inventory is only trustworthy when change events update it. AI vendor assessment and the AI operating model provide the points where that update belongs.

Frequently asked questions

What belongs in an AI inventory?

At minimum, record the system or vendor, owner, purpose, users, data sources, permissions, risk level, approval status, review date, and retirement plan.

Is a spreadsheet enough for an AI inventory?

For a small portfolio, yes if someone owns updates and the record supports review, incident response, and decisions. The process matters more than the software.

Summarize this page with

See this working in a system we built