It is more useful than a list of licenses. One entry should make it possible to answer who owns the system, which workflow it supports, which data and tools it reaches, what risk review it passed, and when it should be checked again. That information is essential during an incident or a vendor change.
Why does an AI inventory matter?
AI governance cannot work from assumptions. Without an inventory, a company cannot find systems affected by a model change, revoke an agent’s access, or show what controls apply to a customer-facing workflow. The inventory makes ownership and review visible before a failure demands them.
It also exposes shadow AI. The goal is not to punish teams for useful experimentation. It is to discover real use, assign an owner, and decide whether the system should be approved, changed, or removed.
What keeps an inventory from going stale?
Attach updates to normal delivery and review work. Creating a system, adding a data connection, approving a vendor, changing permissions, or retiring a workflow should update the same record. An inventory is only trustworthy when change events update it. AI vendor assessment and the AI operating model provide the points where that update belongs.