Multiply the number of AI systems you think you have, by at least 10.

Many companies will be surprised about how much AI they are already using. Just about every traditional application will have an AI module. Your IT Manager never chose that, the vendor did it anyway. Think about the latest cars. Twenty years ago GPS, cruise control, reversing cameras, lane assist and so on were optional extras. Now they come as standard.
So how many AI systems do you have?
I ask this question a lot. And the answer is always wrong by at least 10x. Often three, becomes 30, very quickly.
AI systems and by default, AI risk management, has been forced upon us, but we didn't exactly ask for it.
Companies don't adopt AI one system at a time anymore. AI is being delivered continuously through software updates, license upgrades and cloud services.
AI is literally everywhere. It works something like this:
AI capabilities pop-up without a formal procurement process in software upgrades.
IT may not even realise AI has been activated.
Staff begin using AI features without training.
Sensitive information may be unexpectedly processed by AI enabled functions.
An AI systems inventory is now essential
An AI systems inventory allows companies to understand what AI they are using, why they are using it, who is responsible, what risks it creates, and what governance controls are in place. With this essential information, companies can rely on evidence rather than assumptions when managing AI risk.
As AI becomes embedded in more business processes, maintaining an accurate and current inventory is becoming as fundamental as maintaining registers for assets, information systems or corporate risks.
Where to start
I've been doing IT strategy consulting since 2012. The first question I ask is: What does your current tech stack look like? Rarely did I get a written list of software applications in use. I am not suggesting IT had no idea of the systems under their care, rather the detailed knowledge thereof was living inside someone's head. The kind of knowledge that goes home at night and comes back at 9am the next day.
I love the gentle reminder about the lack of documentation from The MythBusters. The well-known science oriented TV series ran for 14 seasons championing: "the difference between science and screwing-around is writing it down". Fast forward to present day, most IT departments will have a solid list of applications (IT asset register) they are supporting, typically as part of their cyber security protocols.
A simple list of systems is not enough
IT will be able to give you a good starting point for developing an AI system inventory. But a simple list of software is now not sufficient for AI risk management. Here's why:
Think of your weekly shopping list. You'll have a list of items you need to purchase from the supermarket. Next, imagine that one of your family members has developed a peanut allergy, which in some serious situations, can be fatal. So now, when you go shopping, you'll have to be vigilant. The way you see a product changes. You'll start by scanning labels for traces of peanuts before it's dropped into the trolley. You're now segmenting food items between safe and unsafe products. If in doubt, leave it out. Your intuition tells you to be cautious, the stakes are high, so if unsure, leave it on the shelf and maybe later contact the manufacturer for more information. Anaphylaxis is a process in risk management, in real time.
You need to read the labels on your AI systems too
Just like anaphylaxis, you can't manage what you can't see. And, just like anaphylaxis, if you aren't vigilant, the result of poor oversight could be fatal.
An AI systems inventory is no different to supporting someone with anaphylaxis.
For each system, you'll need to properly scrutinise the label with a new set of eyes. Then, segment high-risk ones from low-risk ones systems because to be effective you can't behave like Chicken Little. The sky isn't falling in but conscious risk choices will need to be made because your time is valuable. Excessive monitoring of low-risk systems means you have less time to keep an eye on the high-risk ones.
Assessing the AI risk means gathering data from the vendor's contractual terms and conditions for liability, the system user manual for its purpose, decision logic, where it has introduced AI and how it should be managed. You need to understand how it's actually being used by employees, how many employees use it, what data is used and where that data is processed. Some of this information might already sit in Procurement, Compliance or IT but I'll bet London to a brick it won't be centralised into one place. No single source of truth exists, until a good governance person gets a hold of it.
What I've found is that a useful AI inventory will capture maybe 30-40 data points for each AI system so that the risks can be properly assessed and then continually monitored.
Not every system will be high risk but every system isn't risk free either. A low-risk AI system might accidentally leave the front door open for a cyber-attack. A high-risk solution might have excellent controls mitigating potential AI data breaches.
The change has been forced on us
An AI system inventory is needed because companies cannot govern, secure or comply with regulations for AI systems they do not know they are using. AI is not like fixed, traditional systems (I wrote about this here). AI needs a lot more TLC (tender, love and care).
With every week that an organisation rolls out AI without proper governance, the cost of going back to fix things later keeps climbing. All the little things add up, like choosing training data without an audit trail, letting an AI make decisions without clear accountability, or signing a vendor contract without sorting out who’s liable.
Putting this off isn't a neutral choice. It’s actively deciding to deal with a much bigger problem down the road. Australian boards and ministers are beginning to ask directly about AI governance readiness. The question is no longer "do we have an AI policy?".
The game has changed. The Board question to be answered by management is:
"What is our comprehensive inventory of active AI systems and use cases, and what are the specific financial, operational, and regulatory risks associated with each?"Your AI inventory therefore provides the visibility required to move from reactive management to proactive governance.
The key reasons you need an AI inventory
1. You can't govern what you can't see
You will have far more AI in use than you realise. Employees may be using public generative AI tools, business units may have implemented AI-enabled software, and vendors may have introduced AI capabilities through routine software updates. Without an inventory, you cannot answer these fundamental questions:
How many AI systems are we using?
Where are they being used?
What decisions do they influence?
Who is accountable for them?
The AI inventory creates a single source of truth about your risk exposure. The more AI systems you are using the greater the risk exposure.
2. You need to manage AI risk
Different AI use cases create very different risks. For example:
Asking AI to summarise meeting notes presents relatively low risk (maybe not if these are confidential Board meetings).
Using AI to screen job applicants creates legal, ethical and discrimination risks.
Using AI to assist clinical decision-making in healthcare introduces patient safety risks.
Using AI to detect fraud in financial transactions may have significant financial and customer impacts.
The AI inventory helps identify which use cases require additional controls, testing or human oversight.
3. You need to comply
AI-specific regulation and standards increasingly require organisations to know what AI they are using. An AI inventory helps demonstrate compliance with requirements such as:
Australia's Digital Transformation Agency (DTA) AI Technical Standard expects Federal Federal agencies to identify and manage AI systems throughout their lifecycle.
Emerging Australian privacy obligations for automated decision-making requires organisations to understand where AI is processing personal information.
APRA has sent a letter to industry expecting financial organisations to establish an AI inventory
ISO/IEC 42001 requires organisations to establish and maintain information about AI systems within their AI management system.
Rather than scrambling during an audit or respond to questions from the Board, if you can produce a current inventory showing what AI exists, who owns it and how risks are managed, you'll be in a good place.
4. The process must uncover Shadow AI use
"Shadow AI" is AI that is adopted without IT approval or oversight. Employees often use AI this way to improve productivity, but they may inadvertently:
upload confidential information,
expose personal data,
create inaccurate outputs, or
bypass established business processes.
A structured process helps helps uncover these informal use cases. You can read about my Four step Shadow AI framework here.
5. Accountability with a capital A
Every AI use case should have a named business owner. Without ownership:
nobody reviews performance,
nobody monitors emerging risks,
nobody updates documentation, and
nobody is responsible when something goes wrong.
An inventory assigns clear accountability, ensuring AI governance is embedded within the business. As mentioned earlier this should never be treated solely as an IT responsibility.
6. Board oversight
Australian boards and government ministers are beginning to ask directly about AI governance readiness. The question is no longer "does your company have an Ai policy?". The real question is "can you demonstrate, under examination, that you have discharged your duty of care if something goes wrong?". Increasingly, astute Boards asking management questions such as:
What AI are we using?
What are our highest-risk AI applications?
Are we complying with regulatory expectations?
How are AI risks being monitored?
Without an AI inventory, these questions cannot be answered with any confidence. The inventory provides reliable management information for governance committees, executive teams and boards.
7. Saves money
Many CIOs discover they are paying for multiple AI tools that do the same thing. Sometimes different teams have independently developed similar AI solutions. An inventory helps companies:
eliminate duplication,
identify opportunities for standardisation,
negotiate better vendor arrangements, and
focus investment on AI initiatives that deliver the greatest business value.
8. AI lifecycle management
Your AI inventory sits at the core of your AI governance throughout a system's lifecycle by triggering or tracking activities such as:
privacy impact assessments,
security reviews,
bias and fairness testing,
human oversight arrangements,
approval workflows,
model monitoring,
periodic reviews,
incident reporting,
and retirement or decommissioning.
By linking governance activities to each AI use case, you can ensure that oversight happens and continues. An AI inventory should be treated as a living governance asset rather than a one-off compliance exercise.
What does a good AI system inventory look like?
An AI inventory is the foundation of every AI governance activity. One of the biggest mistakes is simply thinking the AI inventory is a list of software products. In reality, it should be a register of AI use cases supported by information about the underlying AI systems.
Some other governance gaps you'll need to watch out for are:
Not including "shadow AI" used directly by staff without formal approval.
Treating the inventory as an IT asset register instead of a governance tool (... respectfully keep IT out of this).
Collecting too much information, making the process difficult to sustain.
Business leaders failing to accept ownership.
Never reviewing or updating it after the initial setup.
For example, Microsoft Copilot (an AI system) might be used for these AI use cases:
drafting reports
analysing spreadsheets
writing software code
preparing board papers
summarising clinical notes
responding to customers
AI systems recorded in the inventory might include these types:
Generative AI (ChatGPT, Copilot, Gemini, Claude)
AI embedded within enterprise applications such as Finance ERP systems
Machine learning models
Predictive analytics used for decision-making
Facial or speech recognition systems
AI agents and autonomous workflows
AI risk management is not an IT problem. Managing AI risk is a business problem. So the AI inventory, the primary tool to manage that risk, should never be established or maintained by IT.
Good ongoing practices include:
quarterly reviews by business owners
annual independent audits
automated reminders to confirm information
continuous discovery of new AI tools
monitoring software vendors that add AI functionality
reviewing incidents and updating risk ratings
Many enterprise applications now introduce AI features through routine updates, so an inventory can become outdated even when no new software has been purchased.
Tools to solve this problem
National AI Centre: AI systems register template
So where should your AI systems inventory data be stored and managed?
Personally, I'm not a fan of big spreadsheets as part of a governance tool-kit. They aren't auditable, you can end up with different versions and on and on. BUT. Sometimes you need to start somewhere (see Mythbusters comment above).
Australia's National AI Centre has developed an AI register template as a Word document or an Excel spreadsheet. You can download it here. The template comes with instructions and includes example data. There are about a dozen or so data points captured for each AI system. It's a good starting point for writing things down and getting your arms around things.
AI Governance software
Recently, I wrote about the 4S of AI Adoption, and highlighted the third 'S' which stands for Sophistication. Companies need to get more sophisticated about how they manage their AI risk at an operational level. Here's a short video of one software tool (of many) I've come across that has been purpose-built for AI Governance, and especially, AI system inventory management.
In wrapping up
If you think you know how many AI systems are already in your company, multiply the answer by 10.
An AI systems and use case inventory is the foundation of effective AI governance because it provides visibility, accountability and control.
It allows companies to understand what AI they are using, why they are using it, who is responsible, what risks it creates, and what governance controls are in place. With this essential information, companies can rely on evidence rather than assumptions when managing AI risk.
As AI becomes embedded in more business processes, maintaining an accurate and current inventory is becoming as fundamental as maintaining registers for assets, information systems or corporate risks.
It is the starting point from which every other element of AI governance can operate effectively.
Stay safe,
Bruce
AI. Use responsibly.
ABOUT ME
I partner with mid-size companies to confidently adopt AI, prevent high-profile failures and avoid the expensive mistake.
I write all my own content, you can tell by the odd typo and occasional missing word. I use AI for my research.
To learn about my upcoming public AI Governance workshops visit: Public workshops
To learn more about AI Governance, check out my Hitchhikers Guide to AI Governance Podcast.
To listen visit: Hitchhikers Guide to AI Governance Podcast





Comments