How do you find all the AI your company uses?
An AI inventory is a simple list of the AI tools and AI features your company uses, what each is used for and who owns each use. Without one, it is hard to manage risks, approve new tools or answer a customer who asks how you use AI.
Why AI is easy to miss
Much of the AI in a company never appears in the IT budget. Staff sign up for free tools with a work email, familiar software gains AI features through an update, and developers connect to AI services with a few lines of code. AI tools used without the company knowing or approving are called shadow AI. It is rarely malicious: people adopt a tool because it helps them do their job. The risk is that nobody has checked what data goes into it or how its output is used.
Where to look
- Subscriptions and purchases. Go through card statements, expense claims and invoices for AI products and for software plans that include AI.
- Software with built-in AI features. Review the SaaS (software as a service) tools you already use: email, office suites, customer relationship management, support desks, design tools. Many now include AI assistants, sometimes switched on by default. Note which features are active.
- Browser extensions. Writing assistants, meeting note-takers and translation extensions can often read the pages people open. Check the extensions on work browsers, or ask IT for a list if browsers are centrally managed.
- API keys. API keys are the credentials software uses to connect to an external service. Ask developers which AI services your products and internal scripts call, and where those keys are stored and billed.
- A short team survey. Ask every team three questions: which AI tools do you use, what for, and what data do you put into them? Keep it to a few minutes.
A common mistake: hunting for rule-breakers
If the inventory feels like an investigation, people hide the tools they use and the list ends up incomplete. Present it instead as a way to find out what helps teams and to make those tools safe to use.
Hypothetical example: a design studio asks staff to list their AI tools and states that nothing reported during the inventory will lead to disciplinary action. Tools that raise concerns are then reviewed together with the people who use them, and a safer alternative is found where needed. Staff report more tools, and the studio learns which needs a business-grade tool should cover.
Keeping the AI inventory useful
Record one entry per use case, not per tool. If marketing uses a writing assistant for social media posts and HR uses the same tool for job adverts, that is two entries, because the data, the people affected and the risks differ. Alternatively, keep two linked levels: a tool record with the vendor and contract, and a use-case record for each use of it.
The classification fields in the template below are independent questions, not one risk label: prohibited-practice screening, high-risk classification with its rationale, transparency duties and the company’s role. One system can be high-risk and carry transparency duties at the same time (AI Act Art. 50(6)). Each field allows “Not yet determined”, and a named classification owner makes the final call. The articles on whether you are a provider or a deployer and what the EU AI Act requires explain the questions.
Give the inventory as a whole one owner. After the first round, add new use cases through your approval process for AI use cases rather than through occasional clean-ups, and mark entries as retired instead of deleting them, so the history stays visible.
Voluntary standards and frameworks. ISO and NIST start from the same point. The NIST AI Risk Management Framework expects organisations to have mechanisms for keeping an inventory of their AI systems. An AI management system under ISO/IEC 42001, a standard that can be certified, has to define which AI activities it covers, which is difficult without an inventory. Neither document, and no inventory, makes a company compliant on its own.
Next step: add the first five tools you already know about to the inventory, with one entry per use case.
Template
One row per field, one entry per use case. All examples are hypothetical.
| Field | What to record | Example |
|---|---|---|
| ID | A unique reference for the entry | AI-007 |
| Tool | The tool or AI feature, with the plan or version if relevant | Writing assistant, business plan |
| Vendor | The company selling the tool | Vendor name |
| Use case and purpose | What this team uses the tool for, in one sentence | Marketing drafts social media posts |
| Owner | The person responsible for this use case, by name and role | Maria Silva, Head of Marketing |
| Data used | Types of data that go in: public, internal, confidential, personal | Internal product information; no personal data |
| Markets | Countries where the use case operates or its output reaches people | Portugal, Spain |
| Company role | Provider, deployer or another AI Act role, or “Not yet determined” | Deployer |
| Prohibited-practice screening | Whether the use could fall under an Art. 5 prohibition: “No indication”, “Needs review” or “Not yet determined” | No indication |
| High-risk classification and rationale | High-risk, not high-risk or “Not yet determined”, with the reason | Not high-risk: marketing content, not an Annex I or Annex III use |
| Transparency duties (Art. 50) | Which Art. 50 duties apply, if any, or “Not yet determined” | Not yet determined |
| Classification owner | The person who makes the final call on the classification fields | João Costa, Legal Counsel |
| Approval record and conditions | Who approved the use, when, and on what conditions | Approved by the COO; no personal data in prompts |
| Human reviewer | Who checks the output before it is used | Marketing editor |
| Incident contact | Who to tell if something goes wrong | Maria Silva |
| Assessment and contract | Links to the assessment and to the vendor contract | Links to both documents |
| Last review | Date of the last review | September 2026 |
| Next review | Date of the next review | March 2027 |
| Status | Requested, pilot, in use, paused or retired | In use |
If you use two linked levels, keep Tool, Vendor and the contract link in the tool record, and reference its ID from each use-case entry.
Sources and further reading
AI Horizon Conference
The AI Horizon Conference returns to Lisbon, once again bringing together entrepreneurs, investors and industry leaders to discuss the future of AI.