AI Inventory: See and Govern Every AI System | Layer 1 | T3

Layer 01 · AI governance

AI Inventory: Know Every AI System in Your Estate

Every effective AI governance programme starts with a complete, continuously updated AI inventory.

An AI inventory gives organisations visibility into every AI system operating across the business. From employee-adopted copilots and third-party applications to internally developed models and autonomous agents, organisations often use more AI than they can formally account for.
A robust AI asset inventory identifies what exists, how it is being used, who owns it, what data it touches and what risks it creates. It provides the foundation for risk management, security, model assurance, compliance and ongoing AI governance.

AI inventory and model registry illustration

LIVE AI DISCOVERY

See the AI Your Organisation Is Actually Running

A modern AI system inventory goes beyond manually submitted spreadsheets. Discovery can analyse browsers, cloud applications, identity platforms, procurement records and network telemetry to identify models, copilots, agents and embedded AI services that may never have been formally registered.

0systems in scope
0AI tools surfaced*
0unregistered
0high-risk systems

Illustrative figures based on patterns observed across representative client engagements and real-world AI discovery exercises. Actual results vary by organisation.

Public guidance increasingly emphasises the importance of maintaining visibility over AI systems throughout their lifecycle. NIST and European Commission guidance provide important reference points for organisations establishing AI governance and risk-management processes.

Evidence: Evidence: NIST AI Risk Management Framework |  |  European Commission AI Act

In this example, 214 AI tools were identified across the estate and consolidated into 47 distinct AI systems after related services, integrations and deployments were grouped.
24 AI systems discovered

Scanning estate 0 discovered

01 · WHERE AI GOVERNANCE BEGINS

Five AI Inventory Questions Every Organisation Must Answer

A reliable AI model inventory starts by answering five basic questions: what AI exists, what it does, how risky it is, who is accountable and whether its lifecycle can be traced.
These questions form the core controls of an effective AI use case inventory.

02 · THE CONTROLS BEHIND A GOVERNABLE AI ESTATE

Five AI Inventory Controls That Turn Visibility Into Governance

An effective AI inventory is more than a list of tools. It is a structured governance capability that connects discovery with classification, risk, ownership and lifecycle management.
The five controls work together. If discovery is incomplete, classification is incomplete. If ownership is unclear, accountability is unclear. If the registry is stale, every downstream governance process becomes less reliable.

01

Shadow AI Discovery

Find the AI Your Organisation Doesn't Know It Has

Definition

Shadow AI discovery identifies AI applications being used without formal registration or approval.

How it works

This includes employee-installed tools, AI features hidden inside SaaS platforms, third-party APIs and agents operating behind business workflows.

What this control covers

• Employee-adopted AI tools
• Embedded AI features
• AI browser usage
• Autonomous agents
• Procurement reconciliation
• Unapproved AI applications
• Third-party AI services • Cloud AI services
• Unregistered APIs
• Identity and access telemetry

Without it

effective Shadow AI discovery, an organisation can build governance around only the AI it already knows about.

02

System classification

Turn an AI System Inventory Into a Risk-Aware Register

Definition

Once systems are discovered, each needs to be classified according to what it does and how it is used.

How it works

AI system inventory records should capture the system's purpose, users, data, deployment environment, model dependencies and regulatory context.

What this control covers

• Intended purpose
• Deployment environment
• Data categories
• Third-party dependencies
• Sector-specific requirements
• AI functionality
• User groups
• Regulatory scope • Business criticality • AI system classification

Classification

Classification creates the foundation for proportionate governance.

03

Risk tiering

Measure AI Risk Before It Becomes a Governance Problem

Definition

Not every AI system requires the same level of oversight.

How it works

AI inventory requirements should therefore include a consistent risk methodology that considers factors such as impact, autonomy, data sensitivity, affected individuals and business criticality.

What this control covers

• Risk classification
• Autonomy level
• User impact
• Business criticality
• Approval thresholds
• Impact assessment
• Data sensitivity
• Regulatory exposure
• Control requirements
• Review frequency

Risk

Risk should be assessed according to how an AI system is used, rather than simply the model or product name.

04

Ownership assignment

Put a Real Person Behind Every AI System

Definition

An AI system without a clear owner creates an accountability gap.

How it works

Every entry in an AI asset inventory should identify who is responsible for business use, technical operation, security, compliance, and ongoing review.

What this control covers

• Business owner
• Security owner
• Approval authority
• Incident ownership
• Escalation routes
• Technical owner
• Compliance responsibility
• Review responsibility
• Vendor responsibility
• Retirement authority

Without it

Clear ownership turns inventory data into accountable governance.

05

Model registry

Create the Living Source of Truth for Your AI Estate

Definition

An AI model registry provides a structured, version-controlled record of AI assets throughout their lifecycle.

How it works

It can connect models and systems to their owners, use cases, datasets, versions, approvals, tests and deployment environments.

What this control covers

• Model versions
• Training datasets
• Approval history
• Associated AI use cases
• Retirement status
• Model lineage
• Deployment status
• Model documentation
• Third-party models
• Change history

Without it

The result is a living AI model inventory that supports governance rather than a static spreadsheet that quickly becomes outdated.

THE AI ESTATE, VISUALISED

What an AI Inventory Reveals About Your Organisation

A complete AI inventory provides multiple views of the same estate, helping organisations understand where systems are concentrated, how much AI remains outside formal governance and how quickly discovery improves visibility.

AI Systems by EU AI Act Risk Tier

Registered vs Shadow AI

AI Systems Catalogued During the Discovery Sweep

03 · A PRACTICAL AI INVENTORY REFERENCE

AI Risk Tiers: What Each Category Requires

An effective AI use case inventory depends on correctly understanding the regulatory and operational risk associated with each AI system.

The EU AI Act establishes prohibited and risk-based requirements, while General-Purpose AI (GPAI) models are subject to additional obligations.
Risk CategoryTypical ExamplesGovernance Requirements
ProhibitedSocial scoring, manipulative AI, untargeted facial-image scraping, emotion recognition in the workplace and in education, and (since the Digital Omnibus) AI-generated non-consensual intimate imagery and CSAM, all under Article 5 These practices cannot be deployed, marketed or used in the EU at all; no risk-management or documentation regime makes them permissible
High–riskRecruitment, education, employment, biometric identification, creditworthiness and certain critical infrastructure applications under Annex III; healthcare AI is generally high-risk via Annex I as a medical device rather than through Annex III Risk management, data governance, documentation, logging, human oversight, accuracy and robustness
LimitedChatbots, emotion recognition, generated contentTransparency obligations apply. Users must be informed when interacting with AI systems, AI-generated content, emotion-recognition systems or deepfakes, where required under the EU AI Act.
MinimalSpam filters, AI in games and many productivity applicationsVoluntary good practice
General-Purpose AI (GPAI)Foundation models and general-purpose models integrated into downstream systemsDedicated requirements including technical documentation, copyright policies, training-data summaries and additional obligations for models presenting systemic risk
Transparency risk (Art. 50) *Chatbots and virtual assistants; AI-generated or manipulated audio, image, video and text; deepfakes; emotion recognition and biometric categorisation in permitted contexts Disclose to people that they are interacting with AI; mark synthetic output in a machine-readable format; label deepfakes and AI-generated text published on matters of public interest; notify individuals exposed to emotion recognition or biometric categorisation

*Transparency obligations under Article 50 apply in addition to, not instead of, any other classification. A high-risk system that interacts with users carries both sets of requirements.
GPAI models are governed through additional requirements rather than simply being placed into one of the four primary risk categories.

Remember: risk depends on how AI is used, not simply which model or product is deployed. The same technology can present very different risks depending on its purpose, users, data and deployment environment.

03b · MAPPING AI INVENTORY TO GOVERNANCE FRAMEWORKS

Where AI Inventory Controls Support Recognised Standards

Evidence generated through an AI asset inventory can support multiple governance requirements when the register is structured consistently.

AI inventory: control-to-standard mapping
ControlEU AI ActNIST AI RMFISO / other
Shadow AI discoveryArt. 26 (deployer obligations) & Art. 72 (post-market monitoring) Govern 1 · Map 1ISO/IEC 42001 §6.1
System classificationArt. 6-7 & Annex IIIMap 1-2ISO/IEC 42001 §8.4
Risk tieringArt. 5-7Govern 1 · Map 5ISO/IEC 23894
Ownership assignmentArt. 16-17 & Art. 26(2) Govern 2ISO/IEC 42001 §5.3
AI model registryArt. 11, Art. 49 (EU database registration) & Annex IVMap 4ISO/IEC 42001 §7.5

This mapping is illustrative. Regulatory requirements should always be assessed against the latest official legislation and guidance.

04 · WHAT A DEFENSIBLE AI INVENTORY CONTAINS

The AI Inventory Requirements Checklist

A credible AI inventory should provide more than system names and owners. It should create a reliable record that can support governance, assurance and regulatory review.

  • Discovery before documentation. Use technical and organisational signals to identify AI rather than relying exclusively on voluntary declarations.
  • Every AI asset type. Capture models, agents, prompts, datasets, third-party APIs, copilots and AI embedded within purchased software.
  • A named owner. Every system has clearly defined business, technical, security and compliance responsibility.
  • A current risk tier. Risk classification is reviewed whenever an AI system's purpose, data, users, autonomy or integrations change.
  • Version and lineage. Model versions, datasets, approvals, changes and deployment status remain traceable throughout the lifecycle.
  • Audit-ready export. The register can produce structured evidence for internal reviews, customer assurance and regulatory requirements.

FROM OUR EXPERIENCE

Shadow AI Is Not an Exception - It Is Something You Need to Discover.

AI can enter an organisation through employee tools, SaaS applications, APIs, productivity platforms and embedded vendor functionality.
That means a register containing only internally developed models is unlikely to represent the real AI esta

A comprehensive AI asset inventory must account for build, buy and embedded AI.

FAILURE MODES

How AI Inventory Programmes Quietly Fail

Four patterns we see before a register can be trusted.

The Stale Spreadsheet

The register was last updated months ago and no longer reflects new copilots, AI applications or

Fix · Reconcile the register against procurement, identity and technology telemetry on a defined cadence.

System-Level Risk Tiering

A tool is assigned one risk level even though its risk changes dramatically depending on the use case.

Fix Assess risk at the use-case level using impact, autonomy and materiality.

Everything Becomes “Medium”

Subjective assessments result in almost every system receiving the same risk rating.

Fix Use a deterministic risk methodology with defined thresholds, required controls and approval levels.

The Build-Only View

The organisation inventories models it developed but misses third-party and embedded AI.

Fix · Maintain one AI inventory across internally developed, purchased, embedded and externally hosted AI.

MATURITY MODEL

Five Stages of AI Inventory Maturity

Where does your organisation sit?

01

Ad hoc

AI is discovered incident by incident. No central register exists.

02

Listed

A spreadsheet records known models, but shadow AI, embedded AI and third-party services remain largely invisible.

03

Reconciled

The inventory is cross-checked against procurement and identity records, covering build, buy and embedded AI.

04

Tiered

Every system has a use-case risk tier and named accountable owner.

05

Live

A version-controlled AI model registry connects inventory data with governance workflows and continuously flags changes, emerging risks and common dependencies.

05 · AI INVENTORY IN PRACTICE

Real-World AI Inventory Scenarios

AI inventory becomes valuable when it exposes risks that conventional registers miss. The following scenarios are illustrative composites based on common patterns across regulated industries.

Financial Services
Tier-1 Bank · Supervisory Examination

Challenge

A Tier-1 bank could not demonstrate a complete AI model inventory across trading, credit and operations ahead of a supervisory review.

Controls applied

Shadow AI discoverySystem classificationOwnership AI model registry

Outcome

Discovery surfaced hundreds of previously unregistered AI tools. Several systems with access to customer financial data were escalated for immediate remediation. The resulting register established a single source of truth for governance and accountability.

Key learning

The bank's known AI estate represented only part of its actual AI activity. Discovery had to come before governance.

Healthcare
NHS Trust · Clinical AI Governance Review

Challenge

An NHS Trust needed to classify and risk-tier AI systems used across radiology, pathology and administration.

Controls applied

System classificationRisk tiering Ownership

Outcome

A unified classification framework identified systems requiring enhanced oversight, human review and more frequent governance assessments.

Key learning

Healthcare AI may need to be assessed against sector-specific requirements as well as broader AI regulation. A unified AI use case inventory provides the structure needed to manage both.

Professional services
Global Advisory Firm · Client Assurance

Challenge

A global advisory firm needed to demonstrate that AI used during client engagements was approved, version-controlled and appropriately separated between client environments.

Controls applied

AI model registryOwnership

Outcome

Per-engagement asset lineage provided the evidence required for client assurance reviews and contractual governance requirements.

Key learning

An AI asset inventory can become more than a compliance mechanism. It can provide evidence that supports customer trust and commercial commitments.

Technology / SaaS
AI-Native Scale-Up · ISO/IEC 42001

Challenge

An AI-native SaaS organisation needed to demonstrate ISO/IEC 42001 conformance within a commercial deadline without an established governance programme.

Controls applied

System classificationRisk tieringOwnership AI model registry

Outcome

An accountability structure covering AI products, internal tools and third-party APIs established the core inventory required for governance and assurance.

Key learning

For AI-native organisations, an AI system inventory can become the foundation for enterprise customer assurance and responsible AI governance.

Disclaimer: illustrative use cases based on anonymised real-world scenarios.

06 · QUESTIONS LEADERS ASK

AI Inventory Q&A

No. A policy explains how AI should be governed, while an AI inventory establishes what actually needs to be governed. Both are required for an effective AI governance programme.
A registry is valuable, but it depends on accurate inputs. Without Shadow AI discovery, the registry can simply become a structured record of the AI systems the organisation already knows about.
A spreadsheet typically records known models. A modern AI system inventory can include models, agents, applications, APIs, datasets, embedded AI, owners, use cases, risk tiers, versions and lifecycle status.
Yes. A complete AI asset inventory should account for AI functionality within third-party applications, SaaS platforms and external services.
The timeline depends on organisational size, technology complexity, discovery coverage and the maturity of existing governance. Discovery can begin with a focused estate assessment and expand into continuous inventory management.
The AI inventory provides the foundation. Data governance manages the information AI uses, security protects systems and access, model assurance tests behaviour, human oversight manages decisions, and compliance uses the resulting evidence.

CONTINUE THROUGH THE STACK

Related AI Governance Layers

NEXT STEP

How Much AI Is Your Organisation Actually Running?

A complete AI inventory starts with visibility.
A structured inventory assessment can examine your current discovery capabilities, governance processes, system classification, risk tiering, ownership and registry structure.

Book a complimentary assessment →
EMAILcontact@t-3.ai
WEBt-3.ai
UK+44 20 8087 0917
US+1 213 659 0224

WHY T3

Why T3 for AI Inventory?

T3 is an award-winning AI implementation partner for high-risk industries.
T3 supports trustworthy AI adoption across the entire lifecycle, from AI inventory and data foundations through security, model assurance, human oversight and compliance.

The team designs bespoke AI controls, conducts adversarial red teaming on models and AI systems, and implements end-to-end AI governance operating models aligned with standards including the EU AI Act, , ISO/IEC 42001, and NIST AI RMF.

Where off-the-shelf GRC platforms stop, T3 builds the custom controls, integrations and assurance required to fit your technology stack, AI models and regulatory environment.

Trusted by two-thirds of BigTech and Financial Services, this is where policy meets engineering.