If you asked five people in your organization to name every AI tool currently in use, you'd get five different answers — and all five would be wrong.
That's not a knock on your team. It's the natural result of how AI adoption actually happens inside most companies. It doesn't arrive through a single procurement process with a tidy approval chain. It arrives piecemeal: a marketing team signs up for an AI writing tool with a company card, a developer wires a model into a customer-facing feature, a sales rep starts using an AI note-taker on every call. None of it goes through IT. None of it shows up in a central system. And six months later, nobody — not IT, not legal, not the executive team — can say with confidence what AI is actually running in the business.
This is the starting point for any serious AI governance program: you cannot govern what you cannot see. An AI systems inventory is the foundational artifact that makes governance possible. Here's how to build one that actually reflects reality.
What an AI Systems Inventory Actually Is
An AI systems inventory is a structured, continuously updated record of every AI system, tool, or model in use across your organization — who owns it, what data it touches, what decisions it influences, and what risk it carries.
It is not a one-time audit. A static list compiled in a single week is out of date within a month, because new AI tools enter the organization constantly, often without anyone in a governance role knowing it happened.
A real inventory answers, for every AI system in use:
- What is it? The tool or model name, vendor, and version.
- Who owns it? The business unit or individual accountable for its use.
- What does it do? The function it performs and the decisions it informs or automates.
- What data does it touch? Especially personal, financial, or otherwise sensitive data.
- Who's affected? Employees, customers, or third parties impacted by its outputs.
- How was it approved? Whether it went through any review at all, or was adopted informally.
- What's the risk tier? A rough classification of how much oversight it warrants.
Why This Is Harder Than It Sounds
Most attempts to build an AI inventory stall for the same reasons:
Shadow AI is invisible by definition. Tools adopted outside formal procurement don't appear in your software asset management system, your SSO logs, or your finance team's vendor list. Employees using free-tier AI tools with a personal login are effectively undetectable through conventional IT discovery. Ownership is unclear. Even when a tool is known, it's often unclear who "owns" it in a governance sense. The person who signed up isn't necessarily accountable for how it's used six months later, especially after a team reorganization. Spreadsheets can't keep pace. A spreadsheet-based inventory requires someone to manually update it every time a new tool is adopted, a use case changes, or a team stops using something. In practice, this almost never happens consistently, and the spreadsheet becomes stale within weeks — creating a false sense of visibility that's arguably worse than having no inventory at all. There's no single source of truth for "AI." Unlike traditional software, AI capability is now embedded inside tools that don't look like "AI products" — CRM platforms, productivity suites, and internal applications all quietly ship AI features that get enabled by default.A Practical Process for Building Your Inventory
1. Start with what you can see
Begin with known AI tools: anything procured through IT, anything on a vendor contract, anything your finance team has approved spend for. This won't be complete, but it's your foundation.
2. Survey department heads directly
Ask every function leader — marketing, sales, product, finance, HR, legal — what AI tools their team uses, including free or individually-expensed tools. Frame this as a discovery exercise, not an audit, or you'll get incomplete answers driven by fear of consequences.
3. Check expense reports and SSO logs
Finance and IT data can surface tools that never went through a formal approval process. Recurring charges to AI vendors on corporate cards are a common way shadow AI first becomes visible.
4. Classify by risk, not just by presence
Not every AI tool warrants the same level of scrutiny. A grammar-checking tool and a model that influences credit decisions are not the same risk category, and treating them identically will exhaust your governance capacity on low-risk items while high-risk ones get insufficient attention.
5. Assign clear ownership
Every system in the inventory needs a named owner accountable for its appropriate use, not just a department label. Ownership without a name attached tends to mean no one is actually accountable.
6. Build in continuous updates
This is where most inventories fail. The inventory needs a mechanism for staying current — new tool intake requests, periodic re-surveys, and integration with procurement — rather than depending on someone remembering to update a document.
Why the Spreadsheet Approach Breaks Down at Scale
For a five-person startup, a spreadsheet might genuinely work. For any organization beyond that size, it runs into structural problems: no automatic risk scoring, no workflow for intake and review, no way to track changes over time, and no visibility for anyone who isn't the one person maintaining the file. It also can't connect the inventory to anything else you need to do with it — for example, mapping systems to relevant regulatory obligations like the EU AI Act, or rolling data up into board-level reporting.
This is exactly the gap platforms like Evum are built to close. Rather than maintaining a static list manually, Evum gives you a live, structured system of record for every AI tool in your organization — with ownership, risk classification, and update tracking built in from the start, so the inventory reflects what's actually happening rather than what was true when someone last remembered to check.
What This Looks Like in Practice
Consider a 200-person mid-market company with no formal AI governance program. On paper, IT might report three approved AI tools: a coding assistant for engineering, an AI meeting summarizer, and a chatbot vendor for customer support.
In reality, a proper survey turns up considerably more. Marketing has been running an AI copywriting tool on a personal login for eight months. A product manager wired an AI model directly into a customer-facing feature without looping in security review. Two different sales reps use two different AI note-takers, neither vetted by legal, both recording and storing calls with customers who never consented to AI processing of their conversations. HR has been experimenting with an AI resume screener that nobody has checked for bias.
None of this is unusual — it's the default state for most companies today. The gap between the three tools IT knows about and the seven or eight actually in use is exactly what an inventory is designed to close. And it's also why the inventory has to be treated as an ongoing discipline rather than a project with an end date: six months after this exercise, the list will already be incomplete again unless there's a standing process to keep it current.

How Detailed Should Your Inventory Be?
A common mistake is either too much detail or too little. Tracking every field imaginable for every tool creates a maintenance burden nobody keeps up with. Tracking only tool names creates an inventory that looks complete but tells you nothing useful when a regulator, auditor, or board member asks a real question.
A workable middle ground captures enough to answer three questions for any system, at any time: What could go wrong if this tool behaves unexpectedly? Who would need to be looped in if it did? And what's our exposure if a regulator asked us to justify how it's used? If your inventory can answer those three questions for every entry, it's doing its job. If it can't, more fields won't fix that — better structure will.
Getting Started
You don't need a perfect inventory before you start — you need a real one, built and maintained continuously, that gets more accurate over time as visibility improves. The organizations that get ahead of AI governance in 2026 aren't the ones with the most sophisticated frameworks; they're the ones that can actually answer the basic question of what AI they're running.
If you're ready to move past a spreadsheet that's already out of date, you can build your live AI systems inventory directly inside Evum — no manual maintenance required.
