In transport and logistics, AI is often not housed in a separate system with a name and an owner, but woven into the operation itself: route planning, load optimization, predictive maintenance systems, demand forecasting, and the algorithms that determine which driver gets which trip. Part of this arrives via software from carriers, forwarders or platforms, and therefore works with decision rules that the organization itself has not set and sometimes cannot fully see. The ratio between what the planning department has purchased itself and what comes in via chain partners or built-in functionality keeps shifting. This makes taking inventory in this sector no easier than elsewhere, but different: the question is not only who has installed an AI tool, but also which automated decisions were already present in existing systems before anyone labeled them as AI.
An overview of approved software rarely tells the whole story. Planners who use an AI tool to optimize routes, customer service staff who deploy a chatbot for track-and-trace, or a warehouse employee who uses an application to make inventory forecasts: this kind of application often arises locally, driven by time pressure or a concrete task, without anyone having submitted a request. Anyone who wants to map this out must ask the people doing the work, and that only succeeds if asking questions does not immediately lead to a correction. An organization that wants to find shadow AI must first make clear that reporting it carries no risk.
An inventory that goes beyond the IT list maps out which AI applications are actually in use, where in the process they sit, and who attaches decisions to them. In transport and logistics, that often means a distinction between systems that only advise, systems that plan automatically without intervention, and systems that have an effect on people outside the organization, such as drivers or customers who are shown a delivery time based on a prediction. That distinction is relevant because it changes the risk level: a tool that only gives a planner a suggestion requires a different form of oversight than a system that independently sets schedules or routes.
After the inventory comes the question of what each application actually does and for whom. A system that predicts when maintenance is needed has a different impact than a system that determines which driver is assigned a trip based on performance data. Classification here does not mean applying a fixed template, but ordering what has been found: which application affects decisions about people, which affects only logistical optimization, and which functions purely in a supporting role. The current regulation that determines which obligations apply to which risk level is addressed elsewhere; here it is about the structure needed to be able to apply those rules later, whatever the text precisely prescribes.
Transport companies generally already work with risk management around safety, planning and compliance. AI governance does not have to be a new apparatus alongside that existing system; it works better if the classification of AI applications connects to categories that already exist, so that a director or risk manager does not have to maintain two separate overviews. That requires a governance set that records who manages an application, who is responsible for it, and what control exists over it, in a form that fits what is already present in terms of reporting and accountability structure.
A director or General Counsel who is asked to declare which AI systems are active within the organization must be able to substantiate this with more than a list from the procurement system. Demonstrability means there is an up-to-date overview of applications, their classification and the status of oversight over them, and that this overview also holds up when someone probes further. Other sectors face comparable issues, as can be seen in AI governance in retail, AI governance in the agricultural sector and AI governance in the ICT sector, each with its own ratio between what was purchased centrally and what arose locally.
The Responsible AI Scan that brings together this inventory, classification and governance structure is under construction. Anyone who wants to get started with this can sign up for the waiting list; there is currently no ready-made product to order, and that is not suggested otherwise here.
Once it is clear which AI applications are running in the transport chain and which risk level applies to them, a follow-up question arises that is not answered by taking inventory: how much of the work that planners, drivers or customer service staff currently do can actually be taken over with these applications. That question lies close to governance, but is not identical to it, and is answered by the work scan from FTE TO AI, which calculates per task what portion of the work can be taken over by AI.
Vraag maar. Governance begint bij weten wat er draait — ook wat niemand heeft goedgekeurd.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.