AI Inventory: See and Govern Every AI System | Layer 1 | T3

Layer 01 · AI governance

AI inventory

Every effective AI governance programme starts with an AI system inventory.

An AI system inventory is the foundation of Layer 1 AI governance. Most organisations use more AI than they can account for, from tools adopted by employees to AI embedded inside vendor software and autonomous agents operating in the background. This layer discovers every AI system, assigns ownership, classifies risk, and creates an audit-ready inventory that supports ongoing governance and regulatory compliance.

AI inventory and model registry illustration

Live discovery

Most organisations run far more AI than they can see

A discovery sweep analyses browsers, cloud applications, identity platforms and network telemetry to identify every model, copilot, agent and embedded AI service in use, including systems that have never been formally registered.

0systems in scope
0tools surfaced*
0were unregistered
0high-risk

*Illustrative figures based on patterns observed across representative client engagements and real-world AI discovery exercises. Actual results vary by organisation.

Recent public guidance also shows that organisations routinely underestimate the AI systems operating across their estates. Government agencies and international standards bodies increasingly recommend continuous AI discovery rather than relying solely on manually maintained inventories.

Evidence: NIST AI Risk Management Framework  |  European Commission AI Act

In this example, 214 AI tools were detected across the estate and consolidated into 47 distinct AI systems after grouping related services, integrations and deployments.

Scanning estate 0 discovered

01 · Where it begins

Business challenges linked to AI inventory

An effective AI governance framework starts with knowing which AI systems exist, who owns them, how they are used and which regulatory obligations apply. These five questions represent the core controls required to establish and maintain a complete AI inventory.

02 · The controls, explained

The five controls that make AI governable

Each control is a distinct capability with a clear definition, a working mechanism, where the field is heading, and the consequence of skipping it. The five are sequential: miss one and every control after it is built on an incomplete picture.

01

Shadow AI detection

Finding the AI that exists outside formal approval.

Definition

The practice of discovering and cataloguing the AI tools, models, and agents in use across an organisation without formal IT or governance sign-off. This identifies the invisible AI operating in the shadows of the official estate.

How it works

Signals are gathered from browsers, cloud applications, network traffic, and identity systems, then analysed to identify AI tools, copilots, APIs, and agents and compare them against the approved inventory and policy.The emerging frontier is monitoring AI-to-AI interactions and autonomous-agent activity. Traditional application discovery often misses these machine-to-machine interactions, creating a growing governance gap.

How we help

We run AI-usage discovery across browsers, cloud apps, and networks; give you a single view of approved and unapproved tools; set automated alerts for policy breaches; and translate the findings into an acceptable-use policy your people can actually follow.

Without it

Staff keep feeding sensitive IP and customer data to unvetted AI providers. Audits fail on undocumented usage. Governance fragments, and every layer above is built on an estate you have only partially seen.

Latest advancement

2025–26AI discovery is expanding beyond employee GenAI usage. Enterprise AI governance increasingly includes autonomous agents, embedded AI services and AI-to-AI interactions that cannot be discovered through traditional software inventories alone. Continuous AI discovery is becoming an important capability for maintaining an accurate AI inventory. As autonomous agents call other agents and tools, discovery is extending beyond employee GenAI use to the machine-to-machine traffic that no one signed off on, which is the fastest-growing blind spot in the estate.

Reference:European Commission AI Act

02

System classification

Sorting every system by purpose, function, and regulatory scope.

Definition

The process of categorising each AI system by its intended purpose, business function, affected users, sector, and regulatory applicability, which then determines the governance and compliance requirements that apply to it.

How it works

Systems are analysed on metadata: use case, business process, data types, user impact, and deployment context. That maps each system to applicable regulations and required controls. Increasingly, language models are used to read a system’s documentation and propose a classification, re-checking it as the system evolves.

How we help

We give you a standardised classification framework, apply it consistently across models, GenAI applications, and agents, and align each system to its business function and regulatory obligations, producing governance reporting a board or auditor can read at a glance.

Without it

Regulatory obligations are overlooked, high-impact systems receive the same light-touch oversight as trivial ones, and audit readiness weakens because no one can say which rules apply to which system.

Latest advancement

2025 Classification becomes a legal prerequisite. With the EU AI Act’s prohibited-practice rules in force and high-risk obligations approaching, a defensible classification framework has shifted from good practice to the first step of demonstrable compliance.

Reference: European Commission AI Act

03

Risk tiering

Quantifying harm potential so governance is proportionate.

Definition

The process of assigning a risk level to each AI system based on how much harm it could do to individuals, organisations, and society, so that oversight is proportionate rather than uniform.

How it works

Tiering is a two-step judgement. First, classify what the system is (language, image, audio, video, or multimodal). Then tier the use case, because the use case is what actually exposes people to harm: a transcription tool is low-risk for meeting notes and high-risk in a clinical setting. Severity combines the scale of people or money affected, the depth of harm, its likelihood, and its frequency. Scores are re-checked continuously as integrations and data access change.

How we help

We assess systems against the EU AI Act tiers (unacceptable, high, limited, minimal), monitor for changes that alter a risk profile, single out the high-risk systems that need additional controls, and give you risk-based governance recommendations you can defend.

Without it

High-risk systems run without the controls they need while effort is spent policing trivial ones. Critical failures go unidentified until they cause harm, and legal, financial, and reputational exposure compounds quietly.

Latest advancement

2026 Agentic risk enters the model. Risk tiering is being extended to score autonomous agents by their decision authority, the scope of tools they can reach, and the operational "potential impact" of a single action. These are dimensions that a use-case-only view does not capture.

Reference: European Commission AI Act

04

Ownership assignment

Putting a named person behind every AI system.

Definition

The practice of assigning accountable owners to every AI system, model, and agent, establishing clear responsibility for performance, safety, security, human oversight, and compliance across the full lifecycle.

How it works

Distinct business, technical, security, and compliance owners are named for each system. Governance workflows use those ownership records to route approvals, reviews, incidents, and oversight duties, with automated reminders so periodic reviews and documentation updates actually happen.

How we help

We build an accountability framework with defined roles, wire it into approval and incident workflows, track ownership changes, and document the human-oversight responsibilities each owner carries, so accountability is a record, not an assumption.

Without it

No one owns AI decisions or outcomes. Reviews are missed, incidents drift unresolved, and autonomous agents operate with no one answerable for them: the finding regulators and auditors flag first.

Latest advancement

2026 Regulators want accountability demonstrated, not asserted. Guidance is increasingly requiring named owners and traceable decision records. This provides evidence that a real person is accountable for a system, rather than relying on a policy statement that someone, somewhere, is.

Reference: European Commission AI Act

05

Model registry

The living, version-controlled source of truth for every AI asset.

Definition

A centralised, version-controlled catalogue of every AI model, agent, prompt, dataset, and API, in development and in production, storing the metadata, lineage, and history needed to manage each asset across its life.

How it works

The registry records ownership, version history, approvals, deployment status, training-data references, benchmarks, and lineage for each asset. Automated lineage tracking captures how an asset was built, tested, approved, and deployed, and model cards provide a standard summary of purpose, performance, risks, and limitations.

How we help

We stand up a single repository for models, agents, prompts, datasets, and AI assets, with version tracking, lifecycle status, approvals, and links to training data, owners, and compliance requirements, that produces audit-ready reporting on demand.

Without it

No one can say which models, agents, or prompts are live. Duplicate, outdated, or unapproved assets linger in production, lineage cannot be traced, and audit reporting is impossible to produce in the time a regulator allows.

Latest advancement

2025–26The registry becomes the compliance backbone. As documentation requirements for general-purpose AI and high-risk AI systems take effect, a registry structured around the required technical documentation turns compliance from a fire drill into a report you can export.

Reference: European Commission AI Act

The estate, visualised

What the inventory actually reveals

Three views of the same estate: where risk concentrates, how much of it was shadow AI, and how quickly a discovery sweep builds the register.

AI systems by EU AI Act risk tier

Registered vs shadow AI

Systems catalogued over the sweep

03 · A practical reference

Risk tiers and what they demand

An accurate AI inventory depends on correctly classifying each AI system. The EU AI Act defines four primary risk categories, while General-Purpose AI (GPAI) models are governed under a separate set of obligations. The table below summarises the practical governance requirements.

EU AI Act risk categories, GPAI obligations and governance requirements
TierTypical examplesWhat is required
ProhibitedSocial scoring, manipulative AI, exploitative AI, and other prohibited AI practices listed under Article 5.prohibited
High–riskRecruitment, education, employment, biometric identification, healthcare, creditworthiness assessment, law enforcement and critical infrastructure.Risk management, data governance, documentation, logging, human oversight, accuracy & robustness
LimitedChatbots, emotion recognition, generated contentTransparency obligations apply. Users must be informed when interacting with AI systems, AI-generated content, emotion-recognition systems or deepfakes, where required under the EU AI Act.
MinimalSpam filters, AI in games, most productivity toolsvoluntary good practice
General-Purpose AI (GPAI)Foundation models and other general-purpose AI models that can be integrated into multiple downstream AI systems.Subject to dedicated obligations including technical documentation, copyright policy compliance, training-data summaries and, for GPAI models presenting systemic risk, additional evaluation, reporting and cybersecurity requirements.

General-Purpose AI (GPAI) models are regulated separately from the four primary EU AI Act risk categories. Organisations should first classify an AI system as Prohibited, High-risk, Limited-risk or Minimal-risk before determining whether additional GPAI obligations apply.

Remember: Risk is determined by how an AI system is used, not simply by the model or product name. The same AI application may fall into different regulatory categories depending on its intended purpose, deployment context and users.

03b · Mapping AI inventory controls to leading governance frameworks

Where each control satisfies a recognised obligation

Evidence produced once should satisfy many obligations. Each control maps to a specific reference across the frameworks your auditors already use.

AI inventory: control-to-standard mapping
ControlEU AI ActNIST AI RMFISO / other
Shadow AI detectionSupports Art. 4 & Art. 5Govern 1 · Map 1ISO/IEC 42001 §6.1
System classificationArt. 6–7 & Annex IIIMap 1–2ISO/IEC 42001 §8.4
Risk tieringArt. 5–7Govern 1 ·Map 5ISO/IEC 23894
Ownership assignmentArt. 16–17Govern 2ISO/IEC 42001 §5.3
Model registryArt. 11 & Annex IVMap 4ISO/IEC 42001 §7.5

This mapping is illustrative and is intended to help organisations align AI inventory controls with major governance frameworks. Regulatory obligations should always be interpreted using the latest official guidance.

04 · What a credible inventory includes

The inventory checklist

A register worth relying on covers the following, whether you build it in-house or with us.

  • Discovery before documentation. The estate is found through telemetry, not a survey, because the riskiest systems are the ones no one would volunteer.
  • Every asset type. Models, agents, prompts, datasets, and third-party AI APIs, not just the models the data-science team built.
  • A named owner per system. Business, technical, security, and compliance responsibility is unambiguous.
  • A live risk tier. Each system carries a current tier that updates when its use or integrations change.
  • Version and lineage. Training data, version history, approvals, and deployment status are traceable end to end.
  • Audit-ready export. The register produces the technical documentation a regulator asks for, in the time they allow.

From our engagements

Shadow AI isn’t an exception to manage. It’s the default state to discover.

In most estates, the AI you have registered is the minority of the AI actually in use: copilots switched on inside SaaS, models embedded in vendor products, agents running in the background. A register that only lists what you built is inventorying the wrong thing.

Pattern seen across T3 Responsible AI gap analyses

Failure modes

How an inventory quietly fails

Four patterns we see before a register can be trusted.

The stale spreadsheet

Last updated months ago; GenAI and copilots missing; no risk-tier field.

Fix · Reconcile against procurement and identity logs on a quarterly cadence.

System-level tiering

The same tool tiered once, ignoring that risk lives at the use case. Otter AI is low-risk for meeting notes and high-risk in a clinician’s hands.

Fix · Tier at the use case: impact × autonomy × materiality.

Everything lands “medium”

Subjective tiering where appetite is qualitative and never actually breached.

Fix · A deterministic rubric that sets both the required controls and the sign-off level.

The build-only view

Captures the models you built, misses embedded and third-party GenAI.

Fix · One source of truth across build, buy and embedded.

Maturity model

Five stages of inventory maturity

Most organisations sit at stage 2. Audit-readiness begins at stage 4.

01

Ad hoc

AI surfaces incident by incident; no register exists.

02

Listed

A spreadsheet of known models, updated occasionally; embedded and shadow AI missing.

03

Reconciled

Inventory cross-checked against procurement and identity logs; build, buy and embedded all covered.

04

Tiered

Every entry carries a use-case risk tier and a named, accountable owner.

05

Live

A version-controlled registry wired into governance workflows; a portfolio view flags common-mode risk when many use cases share one vendor model.

05 · In practice

Real-world scenarios

AI inventory is not abstract. Each scenario shows a genuine challenge, the controls that addressed it, and the outcome, anonymised across regulated industries.

Financial services
Tier-1 bank · supervisory examination

Challenge

Facing a supervisory review, a Tier-1 bank could not demonstrate a complete inventory of AI across its trading, credit, and operations functions.

Controls applied

Shadow AIClassificationOwnershipRegistry

Outcome

Discovery surfaced hundreds of unregistered AI tools; several with access to customer financial data were escalated for immediate remediation. The resulting registry and accountability framework passed the review without findings.

Key learning

The bank’s “known” estate was a minority of its actual AI activity. Without discovery first, governance would have been built on a majority-incomplete picture.

Healthcare
NHS Trust · clinical AI governance review

Challenge

An NHS Trust needed to classify and risk-tier dozens of AI systems across radiology, pathology, and administration ahead of a joint governance review.

Controls applied

ClassificationRisk tieringOwnership

Outcome

A classification framework aligned to medical-device guidance elevated several systems to a high-risk tier requiring human-in-the-loop controls and quarterly review cycles.

Key learning

Regulated healthcare AI must be classified against sector-specific frameworks as well as the EU AI Act: a dual-alignment need met with a single unified matrix.

Professional services
Global advisory firm · client assurance

Challenge

A global advisory firm needed to assure large clients that AI used on their engagements was approved, version-controlled, and isolated between client environments.

Controls applied

RegistryOwnership

Outcome

A model registry with per-engagement asset lineage let the firm commit contractually to AI governance standards and evidence them with registry exports during client audits.

Key learning

A registry is not only a compliance tool. For professional services it is a commercial differentiator: the evidence base behind the promises made to clients.

Technology / SaaS
AI-native scale-up · ISO/IEC 42001

Challenge

An enterprise customer required an AI-native SaaS company to demonstrate ISO/IEC 42001 conformance within 90 days, with no governance programme in place.

Controls applied

ClassificationRisk tieringOwnershipRegistry

Outcome

An accountability framework covering the firm’s AI products, internal tools, and third-party APIs was delivered in weeks, and the conformance assessment passed inside the commercial deadline.

Key learning

For AI-native companies, the inventory is not overhead; it is the foundation for every enterprise sales conversation that demands evidence of responsible AI.

Disclaimer: illustrative use cases based on anonymised real-world scenarios.

06 · Questions leaders ask

AI inventory Q&A

A policy only governs the AI you know about. Shadow AI is structurally endemic in large organisations; in practice the known estate is often a minority of actual AI activity. Discovery has to come before a policy can bite; otherwise you are governing a fraction of the real risk and calling it complete.
No: the five controls are sequential. Detection feeds classification, which feeds risk tiering, which feeds ownership, which feeds the registry. A registry built on incomplete discovery catalogues only part of the estate and inherits every gap beneath it. Start at the top of the layer.
A spreadsheet updated annually will not survive scrutiny. A registry is operational infrastructure: version-controlled, updated as systems change, wired into governance workflows, and generating the audit trail regulators expect: recording training data, owners, risk tier, live version, approvals, and performance for every asset.
It must. A large share of AI risk now arrives inside third-party products and APIs your teams never think of as “AI projects.” A credible inventory captures embedded and third-party AI alongside the models you build, and records who owns the relationship and what data flows to it.
It scales with the size of the estate. Discovery and an initial classification can run in weeks; a full accountability framework and audit-ready registry follow shortly after. In practice, an AI-native firm can reach a conformance-ready state inside a 90-day commercial deadline when the work is sequenced properly.
It is the foundation the whole stack stands on. The registry defines what needs a trustworthy data foundation (Layer 2) and security (Layer 3), what must be tested and assured (Layer 4) and given human oversight (Layer 5), and what evidence flows into compliance and audit (Layer 6). Nothing downstream can be complete if the inventory is not.

Continue through the stack

Related layers

Next step

How much AI are you actually running?

Book a complimentary AI inventory assessment. A working session that benchmarks your current visibility against the five controls in this layer and surfaces the highest-priority gaps, including the shadow AI you cannot yet see.

Book a complimentary assessment →
EMAILcontact@t-3.ai
WEBt-3.ai
UK+44 20 8087 0917
US+1 213 659 0224

Why T3

Why T3 for AI inventory?

T3 is an award-winning AI implementation partner for high-risk industries.

We support the adoption of trustworthy AI across the entire lifecycle. We design and engineer bespoke AI controls, conduct adversarial red teaming on models and AI systems, and implement end-to-end AI governance operating models, aligned to standards we helped write such as the EU AI Act, ISO/IEC 42001, and NIST AI RMF.

Where off-the-shelf GRC platforms stop, we build the custom controls, integrations, and assurance that fit your stack, your models, and your regulator.

Trusted by two-thirds of BigTech and Financial Services, this is where policy meets engineering.