Key facts

  • Start with a spreadsheet — dedicated software is not required to create a useful inventory.
  • Cover shadow AI and AI features embedded in third-party products, not only formally procured tools.
  • Record business purpose, accountable ownership, supplier dependencies, affected people, data, geography, role, risk, oversight and review triggers.
  • Use the free AI system inventory template to start immediately.
  • Treat the inventory as a living evidence record, with a named owner and change-triggered review.

What to include

Include every material AI system or use case: customer-facing chatbots, internal productivity tools, AI used in HR or recruitment decisions, models or APIs embedded in products, and AI features inside third-party software. If a tool influences a decision, produces an output used by the business or processes organisational data, include it until a documented assessment says otherwise.

Finding shadow AI

Survey teams directly, review expense claims and software subscriptions, ask suppliers which AI features are enabled, and include tools employees use informally. Shadow AI — use without formal procurement, security or governance sign-off — is often the largest gap in a first inventory.

What buyers expect each record to show

For every AI system or use case, record:

  • A clear name, business purpose, intended output and boundary of use.
  • The operational owner, accountable decision-maker and evidence owner.
  • The supplier, model and material third-party dependencies.
  • Intended users and the people whose decisions, access or interests may be affected.
  • Important data sources, data categories and any personal or sensitive data involved.
  • Deployment geography, customer exposure and relevant sector context.
  • The organisation's EU AI Act role and the facts supporting that conclusion.
  • The risk or classification rationale, including unresolved legal questions.
  • The human-oversight decision, intervention trigger, authority and escalation route.
  • The version, approval date, next review date and events that trigger reassessment.

These fields turn a software register into evidence that procurement, security, legal, auditors and boards can interrogate.

Keeping it current

Review the inventory at least quarterly, but do not rely on a calendar alone. Reassess a record when the purpose, model, supplier, data, users, geography, oversight design or regulatory classification changes, or after a material incident. Make the update part of procurement, change management and release approval.

Frequently asked questions

What is the first step in building an AI inventory?

Identify every AI system and use case actually in use, including shadow AI, then assign an owner to each record.

Do I need special software to build an AI inventory?

No. A spreadsheet is sufficient to start if it records the evidence buyers need and has a clear owner and review process.

What is shadow AI?

Shadow AI means AI tools or features adopted without formal procurement, security or governance sign-off.

What fields should a buyer-ready AI inventory contain?

Record the business purpose, owner, supplier and model dependencies, intended users and affected people, data categories, geography, EU AI Act role, risk rationale, oversight, approval date and review trigger.

How often should an AI inventory be updated?

Review it at least quarterly and whenever the model, supplier, purpose, data, users, geography or regulatory classification materially changes.

Turn the inventory into procurement evidence

An inventory becomes commercially useful when each answer links to a current owner, rationale and supporting evidence. If buyer questionnaires are exposing gaps, the AI Procurement Readiness Scan identifies the records and controls to improve first.

Related pages

Sources

Last updated 14 August 2026.