A team leader looks for a solution to a recurring problem: too much text, too little time, a deadline that won't move. Somewhere he finds a tool that makes the work faster. The tool costs little, can be paid for with a credit card or a private account, and requires no approval from IT. Within a day the department is running on it. Nobody has done anything wrong — there was a problem, there was a solution, and the path between them ran outside any form.
This is not an exception. It is the standard pattern as soon as an AI tool is cheaper and more accessible than the procedure to request it. The heavier the request route, the greater the chance that someone skips it. The IT list of approved applications then no longer describes what happens, but what was once requested.
A subscription that works doesn't get cancelled. The department using the tool sees the problem that has been solved, not the governance gap that has arisen. Without a reason, nobody comes forward on their own to report that work is being done outside the view of IT or risk with a tool that processes text, customer data, or internal documents.
The pattern is comparable to a browser extension with access to your email: someone installs something small, it works, and the question of who else is reading along is never asked because there is never a moment at which that question presents itself. This is how a collection of applications arises that are each small and useful on their own, and that together form a blind spot larger than whoever is individually responsible for it.
The first reflex is often: track it down, point it out, make it stop. That backfires. Anyone who knows that having their own subscription will lead to a reprimand won't report it — they'll simply use the tool more quietly from then on, perhaps via a different account, perhaps outside office hours. The inventory then becomes not more complete but less complete, and the problem moves to a place that is even harder to see.
An inventory that works doesn't start with the question "who did this" but with "what is running here". Without repercussions, you get an answer to the question of which tools are being used, for which work, and with which data. With repercussions, you only get silence, and a department that hides the next tool even better.
The first step is not to correct but to make visible. That means asking questions of the people who do the work, not only of the systems that IT manages. How you build an AI inventory describes what that round of questions can look like: what is used, for which task, with which input.
Once an application is identified, the next question is not whether it may continue to exist, but what role it plays and which risk level fits that role. A tool that summarises internal memos requires something different from a tool that works with customer data. That classification determines what needs to be recorded per application — not as a paper exercise, but as a basis for being able to show later what was happening and why that was justified.
The risk of a stray subscription doesn't stand on its own. The same pattern of something arriving without a request also occurs with a pilot setup that was never switched off and with a supplier that built AI into its product without that having been separately discussed. Anyone mapping one department with its own subscription would do well to ask the same question more broadly — not as a hunt for offenders, but as a record of what is actually happening.
A one-off inventory records what is running now. Without repetition, that is a photograph that starts ageing from the day it was taken. New departments discover new tools, existing subscriptions get new features, and the next blind spot arises in the same way as the previous one. How you recognise that pattern before it repeats itself is described at employees using a tool that nobody has approved — as a follow-up to the inventory, not as a replacement for it.
A subscription that a department has taken out itself usually tells you something about the work itself: there was a task that took too much time, and someone looked for a way out. That way out is now identified, but the underlying question remains — which part of that work can structurally be handed over to AI, and under which conditions. The work scan from FTE TO AI calculates per task which part of the work can be taken over by AI, independent of whichever tool a department may already have found for that on its own initiative.
Vraag maar. Governance begint bij weten wat er draait — ook wat niemand heeft goedgekeurd.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.