Note 01

An AI inventory: the practical foundation for a workable policy

An AI policy can be drafted while the inventory is being built. The problem begins when it is treated as complete before the company knows which uses, data, and decisions it needs to govern.

Computing modules and documents organized into groups on a table.

Tailored Coding

NIST’s AI Risk Management Framework 1.0, currently under revision, includes mechanisms for inventorying AI systems among its governance outcomes. The framework’s Playbook recommends defining who maintains the inventory and which systems and attributes should be recorded.

The operational recommendation is to use this inventory to inform the policy. The two efforts can proceed in parallel, but the policy should not be treated as complete without evidence of the uses it intends to govern.

What needs to go into the inventory

The assessment is not limited to formal projects. Beyond approved systems and company-led initiatives, three routes deserve attention.

The first is use through personal accounts. Writing, transcription, translation, or analysis assistants may receive company information without the conditions of retention, reuse, and access being under corporate control.

The second is AI features built into tools already under contract. They may be activated by the supplier, included in an update, or enabled by an administrator without an explicit decision about purpose, data, and responsible parties.

The third is purchases outside the usual technology and procurement process. A low-cost subscription may seem like a simple operating expense, even though the service begins to process data and influence significant activities.

These categories do not, on their own, determine whether a use is acceptable, nor do they form an exhaustive list. They show where purpose, responsibility, contracts, and data processing may fall outside existing controls.

Five questions for prioritizing risk

For each item, the initial assessment needs to answer:

  1. What problem is the use intended to solve, who is responsible for it, and which decision or activity receives its output?
  2. Which data enters the system, including personal data, confidential information, and intellectual property?
  3. Under which account, license, and contract does the use take place, and which rules apply to data retention, reuse, training, location, and deletion?
  4. Who reviews the output before it has an internal effect or reaches a customer?
  5. What happens if the tool makes an error, changes its terms, or stops working tomorrow?

The answers make it possible to set priorities. A use that combines sensitive data, an account outside corporate control, unreviewed output, and operational dependency requires attention before a tool restricted to public information, with a designated owner and a reversible result.

The inventory does not replace the policy, risk assessment, legal and security analysis, or monitoring. It indicates where each of these areas needs further work.

The inventory and policy need to stay connected

With the list in hand, each rule can address an identified situation. Priority uses receive treatment and a remediation deadline. Built-in features are retained or disabled through recorded decisions. New purchases begin to follow common criteria for data, responsibility, human review, continuity, and exit.

The relationship also works in reverse. The policy defines which uses must be recorded, who updates the inventory, and when a change requires a new assessment. Without this cycle, the list becomes outdated and the policy returns to describing an environment that no longer exists.

What the first work cycle should deliver

An initial cycle may combine interviews, analysis of available contracts and invoices, and authorized technical observation of the tools in operation. The expected output is an initial inventory, risk prioritization with explicit criteria, rules adapted to the environment identified, and a remediation plan with responsible parties, sequencing, and estimated effort.

The duration and delivery model depend on the scope, access to evidence, and complexity of the environment. The work may continue with external support or be taken over by the team the company selects.

If your company is about to approve an AI policy, run a test: can it list the uses it intends to govern, the responsible parties, and the data involved? If the answer is no, the next step is to produce that evidence.

Explore the methodology of our threat and risk assessment.