AI answers
Do we need an AI inventory?
Most companies discover they need one at the worst possible moment, which is halfway through an audit or a security questionnaire they cannot answer.
Why this stops being optional
AI adoption inside a company is rarely centralised. A model appears inside a SaaS tool you already pay for, a team wires up an API for one workflow, a vendor adds a feature you did not ask for, someone builds a script that quietly becomes load-bearing. Individually each is reasonable. Collectively, nobody can say what is running.
Then a question arrives that requires the whole picture. A client security questionnaire asks which AI systems process their data. An insurer asks the same before renewing. Under the EU AI Act, obligations depend on the risk category of each system, which you cannot classify without knowing they exist. Every one of these becomes a scramble across teams if there is no register.
The minimum useful fields
The most common failure is an over-engineered template nobody keeps current. Keep it small enough to maintain:
- System name and what it does, in one plain sentence a non-technical person understands.
- Named owner, a person rather than a team. Unowned entries go stale first.
- Model and provider, including version, so you know your exposure when a provider deprecates something.
- Data it touches, specifically whether personal, special category or client-confidential data is involved.
- What it decides or produces, and crucially whether a human reviews the output before it has effect.
- Where it runs, and which region, which is what data residency questions turn on.
- Last reviewed date, because an inventory nobody dates is an inventory nobody trusts.
Seven columns in a spreadsheet is a perfectly respectable starting point. A governance platform bought before the first honest list exists is a way of avoiding the work.
The hard part is discovery, not the register
Writing down what you know takes an afternoon. Finding what you did not know takes longer. Three places to look that people skip: features switched on inside existing SaaS subscriptions, API keys issued to model providers under expense claims rather than procurement, and anything an individual built for personal productivity that colleagues now depend on. Expect the real list to be roughly double the one you start with.
What the register makes possible
Once it exists, three things get much cheaper. Security questionnaires are answered from a document instead of a fire drill. Risk classification under the EU AI Act becomes a filtering exercise instead of a discovery project. And when a provider announces a model deprecation or a price change, you know within minutes which systems are affected rather than finding out when one breaks.
Who should keep it
Someone with authority to ask questions across departments, typically in security, risk or operations. It should be reviewed on a fixed cadence, quarterly is usually enough, and updating it should be a condition of launching anything new. That last rule is what keeps it alive, because an inventory maintained only during audits is a document about the past.
Building the first honest list, including the systems nobody mentioned, is part of what an AI audit produces.
Frequently asked questions
Do we need an AI inventory?
If more than two or three AI systems are in use, yes. Client security questionnaires, insurers and the EU AI Act all require you to know what is running, who owns it, what data it touches and whether a human reviews its output. Without a register, each of those requests turns into a scramble across several teams.
What should an AI inventory contain?
Keep it small enough to stay current: system name and plain-language purpose, a named individual owner, model and provider with version, the data it touches and whether that is personal or confidential, what it decides and whether a human reviews it, where it runs and in which region, and the date it was last reviewed.
Is an AI inventory required by the EU AI Act?
The Act assigns obligations by risk category per system, so you cannot comply without knowing which systems exist and what they do. A register is the practical way to get there, and it is what auditors and insurers ask for in the same breath. A maintained spreadsheet is a legitimate starting point.
Related
Ready to put AI to work?
Book a discovery audit and we will map the highest-ROI AI agents and automations for your business.
Book a discovery audit →