The IT department keeps track of what has been purchased, installed or authorised. That is useful information, but it answers a different question than the one a board member, CIO or General Counsel is actually asking. The IT list shows what has been approved. The question that matters is what is being used.
Between those two lies a gap. An employee who uses a free AI tool in the browser is registered nowhere. A team that consults a language model via a browser extension does not appear in a licence overview. A department that has built a chatbot into a spreadsheet macro does not show up in an asset register. None of this is against the rules by definition. It is simply invisible to the list on which management and oversight rely.
The gap between the list and practice does not arise because someone is negligent. It arises because AI applications have become easily accessible, often without a purchasing process, without an invoice, without IT involvement. An employee who wants to complete a task faster looks for a solution and often finds one within a few minutes, outside any formal channel. That behaviour is predictable and it creates a real problem: no one with an overview of the organisation still knows which AI is actually working with which data.
The IT list is not worthless. It is the starting point of an inventory, not the end point. What procurement and licence data reveal shows that invoices and contracts often reveal more than the asset register itself: a trial subscription that was never cancelled, a licence taken out by a department without consulting IT, an API connection billed monthly without any formal approval underlying it. In addition, there are IT signals that are useful for detecting shadow AI: network traffic to known AI domains, new browser extensions, unusual spikes in data traffic to external services. None of these sources is complete on its own. Together they give a picture that the official list does not provide.
Technical signals show that something is being used, but rarely why or for exactly what purpose. You only get that context by asking the people who use it. That only works if the question is not posed as an investigation. Anyone afraid of a sanction will not give an honest answer, or will not answer at all. How to ask employees without repercussions describes how that question can be asked in a way that gets people to actually tell you what they use, and why, without feeling like they are betraying themselves.
An inventory is more than a list of applications. For each application, you document: who uses it, for what task, with what data, and whether the outcome plays a role in a decision that affects someone outside the organisation. That last question determines the risk level and, with it, which governance requirements apply. What you must document per application describes that format in detail. For organisations with multiple departments, locations or subsidiaries, an additional layer is added: the same application may have low impact in one department and affect a decision about customers in another. How to build an AI inventory at an organisation with multiple units addresses that scale, and why the IT list falls even further behind reality there than at a single department.
An inventory built from multiple sources — the IT list, procurement data, technical signals and conversations with employees — gives a board member something with which he can account for what is actually going on, instead of relying on a register he knows to be incomplete. That is no guarantee that everything is captured; invisible use can never be fully ruled out. It is, however, a foundation that has demonstrably been built, with a clear method, rather than a list that just happens to exist.
An inventory shows which AI applications exist and who uses them. It does not show how much of the underlying work those applications actually take over, or how much room remains to hand over tasks. That is a different question, requiring a different instrument: the work scan from FTE TO AI calculates, per task, what portion of the work can be taken over by AI, based on what that task actually involves rather than on the job title.
Vraag maar. Governance begint bij weten wat er draait — ook wat niemand heeft goedgekeurd.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.