An AI system inventory is a maintained record of every AI system your organization uses: who owns each one, what data it touches, and which decisions about people it influences. It is the first thing a regulator, a plaintiff’s attorney, or your own board will ask to see. It cannot be assembled retroactively.
Most organizations realize they need an inventory only when someone asks a question they cannot answer. The request is typically simple: a line in a customer’s security questionnaire, a due diligence checklist during a financing round, or a director asking in a routine meeting which AI tools the company is using.
The real problem is not that the answer is bad, but rather that there is no answer at all. Creating an AI inventory doesn’t happen overnight. It can often take at least six weeks and outside help.
Why this has become urgent
Two things changed at the same time. AI shifted from being a project to becoming a feature, and people started using it without asking for approval.
Verizon’s 2026 Data Breach Investigations Report, which analyzed more than 31,000 security incidents and over 22,000 confirmed breaches across 145 countries, found that 45 percent of employees now regularly use AI on their corporate devices, whether authorized or not, up from 15 percent the previous year. Sixty-seven percent of those accessing AI on corporate devices were doing so through non-corporate accounts. Shadow AI became the third most common non-malicious insider action in the report’s data-loss-prevention dataset, a fourfold increase in a single year.
The second shift is less obvious and matters more for governance. AI now arrives embedded in software purchased for a different purpose, which means an organization can be using it without anyone having decided on the other embedded features. The Mobley v. Workday litigation made this concrete: the platform at issue serves more than 11,000 organizations, and many of those employers would not have described themselves as using AI in hiring at all, because the screening capability sat within a system they had bought for workforce administration.
An inventory is the only tool that finds both types. Policy, training, and even asking IT will not uncover them, because IT is often unaware and overburdened with firefighting other tasks.
Why your board wants one, specifically
Directors do not request an inventory solely because it is good practice. They have three reasons, and it helps to know which one you are addressing.
Because oversight must be demonstrable
A board that cannot explain what AI the organization uses cannot show it provided oversight. McKinsey’s State of AI research, published in March 2025, found that 28 percent of respondents said their CEO was responsible for AI governance and 17 percent said their board was, with two leaders in charge on average. The same research found that CEO oversight of AI governance was closely linked to higher self-reported bottom-line impact from generative AI, and, at larger companies, it had the greatest impact on EBIT. Oversight is not just a duty—it leads to results.
Because evidence is what survives
Regulatory obligations have shifted considerably over the past year, and several deadlines have been deferred. What was not deferred is the requirement to hold records. Colorado’s replacement AI statute requires developers and deployers to retain the records necessary to demonstrate compliance for at least three years. The EU AI Act’s transparency obligations under Article 50 have been applied since August 2, 2026. A deadline can be extended by a legislature. A record that does not exist cannot be created after the fact.
Because it is the only honest basis for a budget
Every governance decision depends on knowing the scope, and scope depends on the inventory. Choosing between NIST AI RMF and ISO 42001, planning a policy program, or deciding whether to hire a governance lead or advisor; all of these are unknown until you identify the number of systems in use and which of those affect decisions about people. Organizations that pick a framework before making an inventory almost always end up having to change course later, and mid-implementation changes only result in budgets swelling.
What belongs in an entry
Eleven fields. Fewer than most templates propose, because an inventory nobody maintains is worse than none: it creates a record that is confidently wrong.
| Field | What it records and why a board asks for it |
|---|---|
| System name | What the thing is called internally, so two people describing it use the same words. |
| What it does | One sentence in plain language. If nobody can write the sentence, that is the finding. |
| Named owner | One person, not a department. The single most contested field, and the one that makes the rest maintainable. |
| How it arrived | Purchased, built internally, or embedded as a feature in software bought for another purpose. The third category is where most surprises live. |
| Vendor and contract terms | Who supplies it, and what the contract permits them to do with your data. This is the exposure the FTC pursued in the Rite Aid matter. |
| Data it touches | Categories, not a full schema. Personal data, employee data, customer records, financial data, source code. |
| Decisions it influences | Whether it touches a decision about a person: hiring, credit, pricing, access, discipline, service. This field determines your regulatory exposure more than any other. |
| Human review point | Who reviews the output, at what stage, and what they can change. Meaningful human review is a live obligation, not a description. |
| Records kept, and where | What the system logs, where those logs live, and how long they are retained. Colorado’s replacement statute requires records sufficient to demonstrate compliance to be kept for at least three years. |
| EU exposure | Whether the system is used in the EU or its output is visible there. This determines whether the AI Act applies to you at all. |
| Date last reviewed | The field that separates a living inventory from a document somebody made once. |
The field people want to skip is the named owner. A department is not an owner. A department cannot be asked a question, cannot certify that a record is complete, and cannot be held to a review date. If a system genuinely has no owner, that is not a gap in the spreadsheet. It is the most important finding the exercise will produce.
How to build an AI inventory in four weeks, without a data science team
You do not need special tools to start, and you should not begin by buying new software. A spreadsheet is enough for the first version and, for many mid-sized organizations, will continue to be enough.
Week one, follow the money. Get twelve months of software spending from finance and all active vendor contracts from legal. Most AI in a mid-sized organization is paid for, so it leaves a record even if no one has documented it. Flag anything whose product page mentions AI, machine learning, automation, scoring, ranking, or a copilot.
Week two, ask the people who use the tools. Send one question to every department head: What tools does your team use that make a recommendation, prediction, score, or draft? Do not use the phrase “artificial intelligence,” because people may say no even if they use such tools. Ask about what the tool does, not its category.
Week three, review the software you already have. Go through your main platforms and list the AI features that are turned on. This is where you find embedded capabilities, and it is the most often missed step. Your HR system, CRM, service desk, security tools, and productivity suite are the usual places to check.
Week four, sort systems by their impact, then fill in the details. Rank each system by asking: Does it influence a decision about a person? Complete all eleven fields for those systems first. For the rest, just record the name and owner for now. A full record of the important systems is better than a partial record of everything.
You won’t have a perfect inventory in four weeks, but you will have something much more useful: a defensible inventory with a date and a clear view of where the gaps are.
Keeping it alive
Most inventories fail after the first version for a simple reason. They are created as a one-time project and then forgotten. Within two quarters, they describe an organization that has already changed.
Attach the inventory to a recurring meeting, such as a quarterly review with the risk committee. The goal is not just to have a meeting, but to make sure someone updates the review date field and is accountable for it.
Include the inventory in your procurement process. Add one question to your approval steps: Does this tool make a recommendation, prediction, score, or draft? If yes, add it to the inventory before issuing a purchase order.
Review the inventory whenever a vendor updates their product. AI features are often added to existing software and are usually announced in release notes. A system that was not relevant last year may become important this year, even if no one in your organization made any changes.
Report the changes, not the whole document. Boards do not want the spreadsheet itself. They want to know what has changed since last quarter, what is new, what has been retired, and what still lacks an owner.
What good looks like
You’ll know the inventory is working when a director asks which AI systems affect hiring decisions, and someone during a meeting provides the answer from memory or pulls up the record within minutes. It doesn’t become another project plan or a promise to check, but rather a record with a date and a name.
This is a basic standard, but very few organizations meet it right now. That is exactly why achieving it matters.
What to do this month
- Pull twelve months of software spend and flag anything AI-adjacent.
- Ask department heads the behavior question, not the category question.
- List AI features switched on inside platforms you already own.
- Name one owner for each system that touches a decision about a person.
- Put a review date on the document and a recurring item on a committee agenda.
- Take the record to your next board or leadership meeting, gaps included. The gaps are the agenda.
Frequently asked questions
What is an AI system inventory?
A maintained record of every AI system an organization uses, capturing at minimum what each system does, who owns it, how it arrived, what data it touches, which decisions it influences, and when the entry was last reviewed. It is the foundational artifact of AI governance, and all other governance activities depend on it.
Is an AI inventory legally required?
It depends on where you operate and what your systems do. No general law requires a private US company to publish an inventory. However, several obligations are impossible to satisfy without one. Colorado’s replacement AI statute requires records sufficient to demonstrate compliance to be retained for at least three years. The EU AI Act imposes transparency and documentation duties on deployers, with Article 50 obligations applying from August 2, 2026. US federal agencies are required to maintain AI use case inventories under OMB Memorandum M-25-21, and those expectations reach private companies through procurement. Verify your own position against primary sources or counsel.
Who should own the AI inventory?
One named person should own the inventory itself, and each system within it should have its own named owner. In mid-sized organizations, the inventory usually sits with whoever holds risk, compliance, or operations. What matters less is which function holds it, and more that a specific individual can be asked whether it is current.
How is this different from an IT asset register?
An asset register records what you own. An AI inventory records what your systems decide. The fields that matter most, which decisions a system influences and where human review occurs, do not appear in asset management, and the systems that pose the greatest governance exposure are frequently features inside assets already on the register.
How long does it take to build?
A first usable version takes about four weeks in a mid-sized organization, using existing staff and a spreadsheet. Completeness takes longer, and full completeness is not the goal. A dated, honest record of the systems that touch decisions about people is more valuable than an exhaustive list of every tool in use.
Do we need software for this?
Not initially, and often not at all. Begin in a spreadsheet. Purchasing a governance platform before you know how many systems you have is the same error as choosing a framework before you inventory: you are sizing a solution to a problem you have not measured.
Where Raido AI® fits
Raido AI® is an independent AI governance advisory practice serving mid-sized organizations. Independence is the point of it: the practice sells no software, accepts no vendor commissions, and holds no stake in what your inventory finds.
If you are not yet certain which AI your organization is running, the Raido AI Health Check™ is a free, self-serve diagnostic across seven governance domains, including Inventory and Visibility, that takes a few minutes. The Raido AI Review™ is a fixed-scope, independent engagement that produces a confidential findings report and a prioritized action plan.
Start with the Health Check at raidoai.com.
Raido AI provides advisory services, not legal advice. Regulatory positions described here are current as of August 2026 and should be verified against primary sources before any compliance decision is taken. Nothing in this article constitutes a determination of compliance with any law, regulation, or standard.
© 2026 Raido AI®. Please share. Attribution appreciated.