Procurement lists twelve approved software products. Employees’ browsers simultaneously run translators, writing assistants, meeting bots, image generators and extensions containing AI features. Some retain prompts, some use them for further model training, and others can read files or take action on a user’s behalf. A policy without an inventory sees only a fraction of this landscape

Shadow AI is now often a feature

New tools used to be recognisable as separate services. Today, AI appears as a button in licensed office software, a browser extension or a model behind a familiar API. An inventory cannot record product names alone. It needs the function, provider, model, version, integration route and affected data

Agentic functions deserve particular attention. A chat that suggests text has a different risk profile from an agent that changes CRM records, sends email or executes code. Permissions and possible consequences belong in the same record as the business purpose

A record that supports decisions

  • business purpose and accountable owner
  • affected user groups and countries
  • provider, product, model family and relevant version
  • input, output and possible personal information
  • storage location, retention and use for provider training
  • integrations, access rights and executable actions
  • human review and consequences of an incorrect output
  • contract status, cost, next review and shutdown route

A field saying “GDPR compliant: yes” is too broad. The answer depends on configuration, contract, data and purpose. The register records the reviewed conditions, not a permanent seal of quality

The regulatory calendar is already running

AI literacy obligations under the EU AI Act have applied since February 2025. Obligations for providers of general purpose AI models have applied since August 2025. Since 2 August 2026, further transparency requirements apply depending on the system, including certain direct interactions with AI and synthetic content. A company’s role may be provider, deployer, importer or distributor and needs case specific assessment

An inventory does not replace that assessment. It supplies the facts: where AI runs, for what purpose, using which data and under whose responsibility. Without this basis, every legal review becomes another search exercise

Risk review without theatre

A small internal summarisation aid does not need the same process as a system assessing job applicants. A practical classification considers impact, data, autonomy, reach and reversibility. The harder an error is to detect and reverse, the stronger testing and approval should be

Current risk frameworks for generative AI identify issues including fabricated content, information integrity, privacy, cybersecurity and problematic human AI configurations. For operations, this becomes a concrete question: how will we notice when this tool is wrong, and who can stop the consequence?

Models change behind a familiar name

An approved product may respond differently after a provider update, use new data sources or gain additional actions. The register therefore needs change events. Relevant version changes trigger a fresh sample test. Critical processes may need the option to pin a known version

Pricing models change behaviour too. A move from a flat licence to usage based agents can create unexpectedly high API costs. Usage limits and budget alerts belong to operations, not merely accounting

Check for prompt injection in every external input

An agent can follow instructions contained in documents, web pages or email that an attacker has planted. The more tools it has, the greater the possible impact. Content should be treated as untrusted data, tool permissions tightly limited and critical actions confirmed before execution. Logs need to show which source and action were involved

A realistic introduction

  1. combine browser extensions, expenditure, the SSO catalogue and a team survey
  2. record use and data class first rather than banning everything immediately
  3. review high impact uses and sensitive data first
  4. publish approved alternatives and understandable rules
  5. process changes, expiry and shutdown regularly

The access management overview complements the register with roles and technical access. The goal is not a museum of every app ever opened. It is a living map of AI use from which accountable people can make real decisions