Layer 01 · AI governance
AI Inventory: Know Every AI System in Your Estate
Every effective AI governance programme starts with a complete, continuously updated AI inventory.
An AI inventory gives organisations visibility into every AI system operating across the business. From employee-adopted copilots and third-party applications to internally developed models and autonomous agents, organisations often use more AI than they can formally account for.
A robust AI asset inventory identifies what exists, how it is being used, who owns it, what data it touches and what risks it creates. It provides the foundation for risk management, security, model assurance, compliance and ongoing AI governance.
LIVE AI DISCOVERY
See the AI Your Organisation Is Actually Running
A modern AI system inventory goes beyond manually submitted spreadsheets. Discovery can analyse browsers, cloud applications, identity platforms, procurement records and network telemetry to identify models, copilots, agents and embedded AI services that may never have been formally registered.
Illustrative figures based on patterns observed across representative client engagements and real-world AI discovery exercises. Actual results vary by organisation.
Public guidance increasingly emphasises the importance of maintaining visibility over AI systems throughout their lifecycle. NIST and European Commission guidance provide important reference points for organisations establishing AI governance and risk-management processes.
Evidence: Evidence: NIST AI Risk Management Framework | | European Commission AI Act
In this example, 214 AI tools were identified across the estate and consolidated into 47 distinct AI systems after related services, integrations and deployments were grouped.
24 AI systems discovered
01 · WHERE AI GOVERNANCE BEGINS
Five AI Inventory Questions Every Organisation Must Answer
A reliable AI model inventory starts by answering five basic questions: what AI exists, what it does, how risky it is, who is accountable and whether its lifecycle can be traced.
These questions form the core controls of an effective AI use case inventory.
02 · THE CONTROLS BEHIND A GOVERNABLE AI ESTATE
Five AI Inventory Controls That Turn Visibility Into Governance
An effective AI inventory is more than a list of tools. It is a structured governance capability that connects discovery with classification, risk, ownership and lifecycle management.
The five controls work together. If discovery is incomplete, classification is incomplete. If ownership is unclear, accountability is unclear. If the registry is stale, every downstream governance process becomes less reliable.
Shadow AI Discovery
Find the AI Your Organisation Doesn't Know It Has
Definition
Shadow AI discovery identifies AI applications being used without formal registration or approval.
How it works
This includes employee-installed tools, AI features hidden inside SaaS platforms, third-party APIs and agents operating behind business workflows.
What this control covers
• Employee-adopted AI tools
• Embedded AI features
• AI browser usage
• Autonomous agents
• Procurement reconciliation
• Unapproved AI applications
• Third-party AI services • Cloud AI services
• Unregistered APIs
• Identity and access telemetry
Without it
effective Shadow AI discovery, an organisation can build governance around only the AI it already knows about.
System classification
Turn an AI System Inventory Into a Risk-Aware Register
Definition
Once systems are discovered, each needs to be classified according to what it does and how it is used.
How it works
AI system inventory records should capture the system's purpose, users, data, deployment environment, model dependencies and regulatory context.
What this control covers
• Intended purpose
• Deployment environment
• Data categories
• Third-party dependencies
• Sector-specific requirements
• AI functionality
• User groups
• Regulatory scope • Business criticality • AI system classification
Classification
Classification creates the foundation for proportionate governance.
Risk tiering
Measure AI Risk Before It Becomes a Governance Problem
Definition
Not every AI system requires the same level of oversight.
How it works
AI inventory requirements should therefore include a consistent risk methodology that considers factors such as impact, autonomy, data sensitivity, affected individuals and business criticality.
What this control covers
• Risk classification
• Autonomy level
• User impact
• Business criticality
• Approval thresholds
• Impact assessment
• Data sensitivity
• Regulatory exposure
• Control requirements
• Review frequency
Risk
Risk should be assessed according to how an AI system is used, rather than simply the model or product name.
Ownership assignment
Put a Real Person Behind Every AI System
Definition
An AI system without a clear owner creates an accountability gap.
How it works
Every entry in an AI asset inventory should identify who is responsible for business use, technical operation, security, compliance, and ongoing review.
What this control covers
• Business owner
• Security owner
• Approval authority
• Incident ownership
• Escalation routes
• Technical owner
• Compliance responsibility
• Review responsibility
• Vendor responsibility
• Retirement authority
Without it
Clear ownership turns inventory data into accountable governance.
Model registry
Create the Living Source of Truth for Your AI Estate
Definition
An AI model registry provides a structured, version-controlled record of AI assets throughout their lifecycle.
How it works
It can connect models and systems to their owners, use cases, datasets, versions, approvals, tests and deployment environments.
What this control covers
• Model versions
• Training datasets
• Approval history
• Associated AI use cases
• Retirement status
• Model lineage
• Deployment status
• Model documentation
• Third-party models
• Change history
Without it
The result is a living AI model inventory that supports governance rather than a static spreadsheet that quickly becomes outdated.
THE AI ESTATE, VISUALISED
What an AI Inventory Reveals About Your Organisation
A complete AI inventory provides multiple views of the same estate, helping organisations understand where systems are concentrated, how much AI remains outside formal governance and how quickly discovery improves visibility.
AI Systems by EU AI Act Risk Tier
Registered vs Shadow AI
AI Systems Catalogued During the Discovery Sweep
03 · A PRACTICAL AI INVENTORY REFERENCE
AI Risk Tiers: What Each Category Requires
An effective AI use case inventory depends on correctly understanding the regulatory and operational risk associated with each AI system.
| Risk Category | Typical Examples | Governance Requirements |
|---|---|---|
| Prohibited | Social scoring, manipulative AI, untargeted facial-image scraping, emotion recognition in the workplace and in education, and (since the Digital Omnibus) AI-generated non-consensual intimate imagery and CSAM, all under Article 5 | These practices cannot be deployed, marketed or used in the EU at all; no risk-management or documentation regime makes them permissible |
| High–risk | Recruitment, education, employment, biometric identification, creditworthiness and certain critical infrastructure applications under Annex III; healthcare AI is generally high-risk via Annex I as a medical device rather than through Annex III | Risk management, data governance, documentation, logging, human oversight, accuracy and robustness |
| Limited | Chatbots, emotion recognition, generated content | Transparency obligations apply. Users must be informed when interacting with AI systems, AI-generated content, emotion-recognition systems or deepfakes, where required under the EU AI Act. |
| Minimal | Spam filters, AI in games and many productivity applications | Voluntary good practice |
| General-Purpose AI (GPAI) | Foundation models and general-purpose models integrated into downstream systems | Dedicated requirements including technical documentation, copyright policies, training-data summaries and additional obligations for models presenting systemic risk |
| Transparency risk (Art. 50) * | Chatbots and virtual assistants; AI-generated or manipulated audio, image, video and text; deepfakes; emotion recognition and biometric categorisation in permitted contexts | Disclose to people that they are interacting with AI; mark synthetic output in a machine-readable format; label deepfakes and AI-generated text published on matters of public interest; notify individuals exposed to emotion recognition or biometric categorisation |
*Transparency obligations under Article 50 apply in addition to, not instead of, any other classification. A high-risk system that interacts with users carries both sets of requirements.
GPAI models are governed through additional requirements rather than simply being placed into one of the four primary risk categories.
Remember: risk depends on how AI is used, not simply which model or product is deployed. The same technology can present very different risks depending on its purpose, users, data and deployment environment.
03b · MAPPING AI INVENTORY TO GOVERNANCE FRAMEWORKS
Where AI Inventory Controls Support Recognised Standards
Evidence generated through an AI asset inventory can support multiple governance requirements when the register is structured consistently.
| Control | EU AI Act | NIST AI RMF | ISO / other |
|---|---|---|---|
| Shadow AI discovery | Art. 26 (deployer obligations) & Art. 72 (post-market monitoring) | Govern 1 · Map 1 | ISO/IEC 42001 §6.1 |
| System classification | Art. 6-7 & Annex III | Map 1-2 | ISO/IEC 42001 §8.4 |
| Risk tiering | Art. 5-7 | Govern 1 · Map 5 | ISO/IEC 23894 |
| Ownership assignment | Art. 16-17 & Art. 26(2) | Govern 2 | ISO/IEC 42001 §5.3 |
| AI model registry | Art. 11, Art. 49 (EU database registration) & Annex IV | Map 4 | ISO/IEC 42001 §7.5 |
This mapping is illustrative. Regulatory requirements should always be assessed against the latest official legislation and guidance.
04 · WHAT A DEFENSIBLE AI INVENTORY CONTAINS
The AI Inventory Requirements Checklist
A credible AI inventory should provide more than system names and owners. It should create a reliable record that can support governance, assurance and regulatory review.
- Discovery before documentation. Use technical and organisational signals to identify AI rather than relying exclusively on voluntary declarations.
- Every AI asset type. Capture models, agents, prompts, datasets, third-party APIs, copilots and AI embedded within purchased software.
- A named owner. Every system has clearly defined business, technical, security and compliance responsibility.
- A current risk tier. Risk classification is reviewed whenever an AI system's purpose, data, users, autonomy or integrations change.
- Version and lineage. Model versions, datasets, approvals, changes and deployment status remain traceable throughout the lifecycle.
- Audit-ready export. The register can produce structured evidence for internal reviews, customer assurance and regulatory requirements.
FROM OUR EXPERIENCE
Shadow AI Is Not an Exception - It Is Something You Need to Discover.
AI can enter an organisation through employee tools, SaaS applications, APIs, productivity platforms and embedded vendor functionality.
That means a register containing only internally developed models is unlikely to represent the real AI esta
A comprehensive AI asset inventory must account for build, buy and embedded AI.
FAILURE MODES
How AI Inventory Programmes Quietly Fail
Four patterns we see before a register can be trusted.
The Stale Spreadsheet
The register was last updated months ago and no longer reflects new copilots, AI applications or
Fix · Reconcile the register against procurement, identity and technology telemetry on a defined cadence.System-Level Risk Tiering
A tool is assigned one risk level even though its risk changes dramatically depending on the use case.
Fix Assess risk at the use-case level using impact, autonomy and materiality.Everything Becomes “Medium”
Subjective assessments result in almost every system receiving the same risk rating.
Fix Use a deterministic risk methodology with defined thresholds, required controls and approval levels.The Build-Only View
The organisation inventories models it developed but misses third-party and embedded AI.
Fix · Maintain one AI inventory across internally developed, purchased, embedded and externally hosted AI.MATURITY MODEL
Five Stages of AI Inventory Maturity
Where does your organisation sit?
Ad hoc
AI is discovered incident by incident. No central register exists.
Listed
A spreadsheet records known models, but shadow AI, embedded AI and third-party services remain largely invisible.
Reconciled
The inventory is cross-checked against procurement and identity records, covering build, buy and embedded AI.
Tiered
Every system has a use-case risk tier and named accountable owner.
Live
A version-controlled AI model registry connects inventory data with governance workflows and continuously flags changes, emerging risks and common dependencies.
05 · AI INVENTORY IN PRACTICE
Real-World AI Inventory Scenarios
AI inventory becomes valuable when it exposes risks that conventional registers miss. The following scenarios are illustrative composites based on common patterns across regulated industries.
Challenge
A Tier-1 bank could not demonstrate a complete AI model inventory across trading, credit and operations ahead of a supervisory review.
Controls applied
Shadow AI discoverySystem classificationOwnership AI model registry
Outcome
Discovery surfaced hundreds of previously unregistered AI tools. Several systems with access to customer financial data were escalated for immediate remediation. The resulting register established a single source of truth for governance and accountability.
Key learning
The bank's known AI estate represented only part of its actual AI activity. Discovery had to come before governance.
Challenge
An NHS Trust needed to classify and risk-tier AI systems used across radiology, pathology and administration.
Controls applied
System classificationRisk tiering Ownership
Outcome
A unified classification framework identified systems requiring enhanced oversight, human review and more frequent governance assessments.
Key learning
Healthcare AI may need to be assessed against sector-specific requirements as well as broader AI regulation. A unified AI use case inventory provides the structure needed to manage both.
Challenge
A global advisory firm needed to demonstrate that AI used during client engagements was approved, version-controlled and appropriately separated between client environments.
Controls applied
AI model registryOwnership
Outcome
Per-engagement asset lineage provided the evidence required for client assurance reviews and contractual governance requirements.
Key learning
An AI asset inventory can become more than a compliance mechanism. It can provide evidence that supports customer trust and commercial commitments.
Challenge
An AI-native SaaS organisation needed to demonstrate ISO/IEC 42001 conformance within a commercial deadline without an established governance programme.
Controls applied
System classificationRisk tieringOwnership AI model registry
Outcome
An accountability structure covering AI products, internal tools and third-party APIs established the core inventory required for governance and assurance.
Key learning
For AI-native organisations, an AI system inventory can become the foundation for enterprise customer assurance and responsible AI governance.
Disclaimer: illustrative use cases based on anonymised real-world scenarios.
06 · QUESTIONS LEADERS ASK
AI Inventory Q&A
CONTINUE THROUGH THE STACK
Related AI Governance Layers
Once you know what AI you have, the next step is making the data feeding those systems traceable, trustworthy and fit for purpose.
L06 · where the evidence landsCompliance & Audit →The AI inventory provides the system records, risk classifications and ownership information needed to demonstrate compliance and maintain audit-ready evidence.
NEXT STEP
How Much AI Is Your Organisation Actually Running?
A complete AI inventory starts with visibility.
A structured inventory assessment can examine your current discovery capabilities, governance processes, system classification, risk tiering, ownership and registry structure.
WHY T3
Why T3 for AI Inventory?
T3 is an award-winning AI implementation partner for high-risk industries.
T3 supports trustworthy AI adoption across the entire lifecycle, from AI inventory and data foundations through security, model assurance, human oversight and compliance.
The team designs bespoke AI controls, conducts adversarial red teaming on models and AI systems, and implements end-to-end AI governance operating models aligned with standards including the EU AI Act, , ISO/IEC 42001, and NIST AI RMF.
Where off-the-shelf GRC platforms stop, T3 builds the custom controls, integrations and assurance required to fit your technology stack, AI models and regulatory environment.
Trusted by two-thirds of BigTech and Financial Services, this is where policy meets engineering.