Layer 01 · AI governance
AI inventory
Every effective AI governance programme starts with an AI system inventory.
An AI system inventory is the foundation of Layer 1 AI governance. Most organisations use more AI than they can account for, from tools adopted by employees to AI embedded inside vendor software and autonomous agents operating in the background. This layer discovers every AI system, assigns ownership, classifies risk, and creates an audit-ready inventory that supports ongoing governance and regulatory compliance.
Live discovery
Most organisations run far more AI than they can see
A discovery sweep analyses browsers, cloud applications, identity platforms and network telemetry to identify every model, copilot, agent and embedded AI service in use, including systems that have never been formally registered.
*Illustrative figures based on patterns observed across representative client engagements and real-world AI discovery exercises. Actual results vary by organisation.
Recent public guidance also shows that organisations routinely underestimate the AI systems operating across their estates. Government agencies and international standards bodies increasingly recommend continuous AI discovery rather than relying solely on manually maintained inventories.
Evidence: NIST AI Risk Management Framework | European Commission AI Act
In this example, 214 AI tools were detected across the estate and consolidated into 47 distinct AI systems after grouping related services, integrations and deployments.
01 · Where it begins
Business challenges linked to AI inventory
An effective AI governance framework starts with knowing which AI systems exist, who owns them, how they are used and which regulatory obligations apply. These five questions represent the core controls required to establish and maintain a complete AI inventory.
02 · The controls, explained
The five controls that make AI governable
Each control is a distinct capability with a clear definition, a working mechanism, where the field is heading, and the consequence of skipping it. The five are sequential: miss one and every control after it is built on an incomplete picture.
Shadow AI detection
Finding the AI that exists outside formal approval.
Definition
The practice of discovering and cataloguing the AI tools, models, and agents in use across an organisation without formal IT or governance sign-off. This identifies the invisible AI operating in the shadows of the official estate.
How it works
Signals are gathered from browsers, cloud applications, network traffic, and identity systems, then analysed to identify AI tools, copilots, APIs, and agents and compare them against the approved inventory and policy.The emerging frontier is monitoring AI-to-AI interactions and autonomous-agent activity. Traditional application discovery often misses these machine-to-machine interactions, creating a growing governance gap.
How we help
We run AI-usage discovery across browsers, cloud apps, and networks; give you a single view of approved and unapproved tools; set automated alerts for policy breaches; and translate the findings into an acceptable-use policy your people can actually follow.
Without it
Staff keep feeding sensitive IP and customer data to unvetted AI providers. Audits fail on undocumented usage. Governance fragments, and every layer above is built on an estate you have only partially seen.
Latest advancement
2025–26AI discovery is expanding beyond employee GenAI usage. Enterprise AI governance increasingly includes autonomous agents, embedded AI services and AI-to-AI interactions that cannot be discovered through traditional software inventories alone. Continuous AI discovery is becoming an important capability for maintaining an accurate AI inventory. As autonomous agents call other agents and tools, discovery is extending beyond employee GenAI use to the machine-to-machine traffic that no one signed off on, which is the fastest-growing blind spot in the estate.
Reference:European Commission AI Act
System classification
Sorting every system by purpose, function, and regulatory scope.
Definition
The process of categorising each AI system by its intended purpose, business function, affected users, sector, and regulatory applicability, which then determines the governance and compliance requirements that apply to it.
How it works
Systems are analysed on metadata: use case, business process, data types, user impact, and deployment context. That maps each system to applicable regulations and required controls. Increasingly, language models are used to read a system’s documentation and propose a classification, re-checking it as the system evolves.
How we help
We give you a standardised classification framework, apply it consistently across models, GenAI applications, and agents, and align each system to its business function and regulatory obligations, producing governance reporting a board or auditor can read at a glance.
Without it
Regulatory obligations are overlooked, high-impact systems receive the same light-touch oversight as trivial ones, and audit readiness weakens because no one can say which rules apply to which system.
Latest advancement
2025
Classification becomes a legal prerequisite.
With the EU AI Act’s prohibited-practice rules in force and high-risk obligations approaching, a defensible classification framework has shifted from good practice to the first step of demonstrable compliance.
Reference:
European Commission AI Act
Risk tiering
Quantifying harm potential so governance is proportionate.
Definition
The process of assigning a risk level to each AI system based on how much harm it could do to individuals, organisations, and society, so that oversight is proportionate rather than uniform.
How it works
Tiering is a two-step judgement. First, classify what the system is (language, image, audio, video, or multimodal). Then tier the use case, because the use case is what actually exposes people to harm: a transcription tool is low-risk for meeting notes and high-risk in a clinical setting. Severity combines the scale of people or money affected, the depth of harm, its likelihood, and its frequency. Scores are re-checked continuously as integrations and data access change.
How we help
We assess systems against the EU AI Act tiers (unacceptable, high, limited, minimal), monitor for changes that alter a risk profile, single out the high-risk systems that need additional controls, and give you risk-based governance recommendations you can defend.
Without it
High-risk systems run without the controls they need while effort is spent policing trivial ones. Critical failures go unidentified until they cause harm, and legal, financial, and reputational exposure compounds quietly.
Latest advancement
2026
Agentic risk enters the model.
Risk tiering is being extended to score autonomous agents by their decision authority, the scope of tools they can reach, and the operational "potential impact" of a single action. These are dimensions that a use-case-only view does not capture.
Reference:
European Commission AI Act
Ownership assignment
Putting a named person behind every AI system.
Definition
The practice of assigning accountable owners to every AI system, model, and agent, establishing clear responsibility for performance, safety, security, human oversight, and compliance across the full lifecycle.
How it works
Distinct business, technical, security, and compliance owners are named for each system. Governance workflows use those ownership records to route approvals, reviews, incidents, and oversight duties, with automated reminders so periodic reviews and documentation updates actually happen.
How we help
We build an accountability framework with defined roles, wire it into approval and incident workflows, track ownership changes, and document the human-oversight responsibilities each owner carries, so accountability is a record, not an assumption.
Without it
No one owns AI decisions or outcomes. Reviews are missed, incidents drift unresolved, and autonomous agents operate with no one answerable for them: the finding regulators and auditors flag first.
Latest advancement
2026
Regulators want accountability demonstrated, not asserted.
Guidance is increasingly requiring named owners and traceable decision records. This provides evidence that a real person is accountable for a system, rather than relying on a policy statement that someone, somewhere, is.
Reference:
European Commission AI Act
Model registry
The living, version-controlled source of truth for every AI asset.
Definition
A centralised, version-controlled catalogue of every AI model, agent, prompt, dataset, and API, in development and in production, storing the metadata, lineage, and history needed to manage each asset across its life.
How it works
The registry records ownership, version history, approvals, deployment status, training-data references, benchmarks, and lineage for each asset. Automated lineage tracking captures how an asset was built, tested, approved, and deployed, and model cards provide a standard summary of purpose, performance, risks, and limitations.
How we help
We stand up a single repository for models, agents, prompts, datasets, and AI assets, with version tracking, lifecycle status, approvals, and links to training data, owners, and compliance requirements, that produces audit-ready reporting on demand.
Without it
No one can say which models, agents, or prompts are live. Duplicate, outdated, or unapproved assets linger in production, lineage cannot be traced, and audit reporting is impossible to produce in the time a regulator allows.
Latest advancement
2025–26The registry becomes the compliance backbone.
As documentation requirements for general-purpose AI and high-risk AI systems take effect, a registry structured around the required technical documentation turns compliance from a fire drill into a report you can export.
Reference:
European Commission AI Act
The estate, visualised
What the inventory actually reveals
Three views of the same estate: where risk concentrates, how much of it was shadow AI, and how quickly a discovery sweep builds the register.
AI systems by EU AI Act risk tier
Registered vs shadow AI
Systems catalogued over the sweep
03 · A practical reference
Risk tiers and what they demand
An accurate AI inventory depends on correctly classifying each AI system. The EU AI Act defines four primary risk categories, while General-Purpose AI (GPAI) models are governed under a separate set of obligations. The table below summarises the practical governance requirements.
| Tier | Typical examples | What is required |
|---|---|---|
| Prohibited | Social scoring, manipulative AI, exploitative AI, and other prohibited AI practices listed under Article 5. | prohibited |
| High–risk | Recruitment, education, employment, biometric identification, healthcare, creditworthiness assessment, law enforcement and critical infrastructure. | Risk management, data governance, documentation, logging, human oversight, accuracy & robustness |
| Limited | Chatbots, emotion recognition, generated content | Transparency obligations apply. Users must be informed when interacting with AI systems, AI-generated content, emotion-recognition systems or deepfakes, where required under the EU AI Act. |
| Minimal | Spam filters, AI in games, most productivity tools | voluntary good practice |
| General-Purpose AI (GPAI) | Foundation models and other general-purpose AI models that can be integrated into multiple downstream AI systems. | Subject to dedicated obligations including technical documentation, copyright policy compliance, training-data summaries and, for GPAI models presenting systemic risk, additional evaluation, reporting and cybersecurity requirements. |
General-Purpose AI (GPAI) models are regulated separately from the four primary EU AI Act risk categories. Organisations should first classify an AI system as Prohibited, High-risk, Limited-risk or Minimal-risk before determining whether additional GPAI obligations apply.
Remember: Risk is determined by how an AI system is used, not simply by the model or product name. The same AI application may fall into different regulatory categories depending on its intended purpose, deployment context and users.
03b · Mapping AI inventory controls to leading governance frameworks
Where each control satisfies a recognised obligation
Evidence produced once should satisfy many obligations. Each control maps to a specific reference across the frameworks your auditors already use.
| Control | EU AI Act | NIST AI RMF | ISO / other |
|---|---|---|---|
| Shadow AI detection | Supports Art. 4 & Art. 5 | Govern 1 · Map 1 | ISO/IEC 42001 §6.1 |
| System classification | Art. 6–7 & Annex III | Map 1–2 | ISO/IEC 42001 §8.4 |
| Risk tiering | Art. 5–7 | Govern 1 ·Map 5 | ISO/IEC 23894 |
| Ownership assignment | Art. 16–17 | Govern 2 | ISO/IEC 42001 §5.3 |
| Model registry | Art. 11 & Annex IV | Map 4 | ISO/IEC 42001 §7.5 |
This mapping is illustrative and is intended to help organisations align AI inventory controls with major governance frameworks. Regulatory obligations should always be interpreted using the latest official guidance.
04 · What a credible inventory includes
The inventory checklist
A register worth relying on covers the following, whether you build it in-house or with us.
- Discovery before documentation. The estate is found through telemetry, not a survey, because the riskiest systems are the ones no one would volunteer.
- Every asset type. Models, agents, prompts, datasets, and third-party AI APIs, not just the models the data-science team built.
- A named owner per system. Business, technical, security, and compliance responsibility is unambiguous.
- A live risk tier. Each system carries a current tier that updates when its use or integrations change.
- Version and lineage. Training data, version history, approvals, and deployment status are traceable end to end.
- Audit-ready export. The register produces the technical documentation a regulator asks for, in the time they allow.
From our engagements
Shadow AI isn’t an exception to manage. It’s the default state to discover.
In most estates, the AI you have registered is the minority of the AI actually in use: copilots switched on inside SaaS, models embedded in vendor products, agents running in the background. A register that only lists what you built is inventorying the wrong thing.
Pattern seen across T3 Responsible AI gap analyses
Failure modes
How an inventory quietly fails
Four patterns we see before a register can be trusted.
The stale spreadsheet
Last updated months ago; GenAI and copilots missing; no risk-tier field.
Fix · Reconcile against procurement and identity logs on a quarterly cadence.System-level tiering
The same tool tiered once, ignoring that risk lives at the use case. Otter AI is low-risk for meeting notes and high-risk in a clinician’s hands.
Fix · Tier at the use case: impact × autonomy × materiality.Everything lands “medium”
Subjective tiering where appetite is qualitative and never actually breached.
Fix · A deterministic rubric that sets both the required controls and the sign-off level.The build-only view
Captures the models you built, misses embedded and third-party GenAI.
Fix · One source of truth across build, buy and embedded.Maturity model
Five stages of inventory maturity
Most organisations sit at stage 2. Audit-readiness begins at stage 4.
Ad hoc
AI surfaces incident by incident; no register exists.
Listed
A spreadsheet of known models, updated occasionally; embedded and shadow AI missing.
Reconciled
Inventory cross-checked against procurement and identity logs; build, buy and embedded all covered.
Tiered
Every entry carries a use-case risk tier and a named, accountable owner.
Live
A version-controlled registry wired into governance workflows; a portfolio view flags common-mode risk when many use cases share one vendor model.
05 · In practice
Real-world scenarios
AI inventory is not abstract. Each scenario shows a genuine challenge, the controls that addressed it, and the outcome, anonymised across regulated industries.
Challenge
Facing a supervisory review, a Tier-1 bank could not demonstrate a complete inventory of AI across its trading, credit, and operations functions.
Controls applied
Shadow AIClassificationOwnershipRegistry
Outcome
Discovery surfaced hundreds of unregistered AI tools; several with access to customer financial data were escalated for immediate remediation. The resulting registry and accountability framework passed the review without findings.
Key learning
The bank’s “known” estate was a minority of its actual AI activity. Without discovery first, governance would have been built on a majority-incomplete picture.
Challenge
An NHS Trust needed to classify and risk-tier dozens of AI systems across radiology, pathology, and administration ahead of a joint governance review.
Controls applied
ClassificationRisk tieringOwnership
Outcome
A classification framework aligned to medical-device guidance elevated several systems to a high-risk tier requiring human-in-the-loop controls and quarterly review cycles.
Key learning
Regulated healthcare AI must be classified against sector-specific frameworks as well as the EU AI Act: a dual-alignment need met with a single unified matrix.
Challenge
A global advisory firm needed to assure large clients that AI used on their engagements was approved, version-controlled, and isolated between client environments.
Controls applied
RegistryOwnership
Outcome
A model registry with per-engagement asset lineage let the firm commit contractually to AI governance standards and evidence them with registry exports during client audits.
Key learning
A registry is not only a compliance tool. For professional services it is a commercial differentiator: the evidence base behind the promises made to clients.
Challenge
An enterprise customer required an AI-native SaaS company to demonstrate ISO/IEC 42001 conformance within 90 days, with no governance programme in place.
Controls applied
ClassificationRisk tieringOwnershipRegistry
Outcome
An accountability framework covering the firm’s AI products, internal tools, and third-party APIs was delivered in weeks, and the conformance assessment passed inside the commercial deadline.
Key learning
For AI-native companies, the inventory is not overhead; it is the foundation for every enterprise sales conversation that demands evidence of responsible AI.
Disclaimer: illustrative use cases based on anonymised real-world scenarios.
06 · Questions leaders ask
AI inventory Q&A
Continue through the stack
Related layers
Next step
How much AI are you actually running?
Book a complimentary AI inventory assessment. A working session that benchmarks your current visibility against the five controls in this layer and surfaces the highest-priority gaps, including the shadow AI you cannot yet see.
Book a complimentary assessment →Why T3
Why T3 for AI inventory?
T3 is an award-winning AI implementation partner for high-risk industries.
We support the adoption of trustworthy AI across the entire lifecycle. We design and engineer bespoke AI controls, conduct adversarial red teaming on models and AI systems, and implement end-to-end AI governance operating models, aligned to standards we helped write such as the EU AI Act, ISO/IEC 42001, and NIST AI RMF.
Where off-the-shelf GRC platforms stop, we build the custom controls, integrations, and assurance that fit your stack, your models, and your regulator.
Trusted by two-thirds of BigTech and Financial Services, this is where policy meets engineering.