Ask an SME how many AI systems it uses, and the answer is usually a low, confident number: "two or three". Once you build the real inventory, that number multiplies. Not because the company is lying, but because a large share of the AI already running inside an organisation arrived without anyone recording it. That phenomenon has a name: shadow AI.
And here is the practical problem: you cannot govern what you don't know you have. The inventory isn't an administrative task that precedes the real work. It is the real work. Everything else rests on it — risk classification, the usage policy, transparency, evidence. Without an inventory, AI governance is a statement of intent.
Where the AI you wouldn't inventory comes from
Shadow AI arrives through three main routes, and none of them goes through a formal purchasing decision.
The module that switched itself on. This is the quietest route. Your CRM, your ERP, your office suite or your management software receives an update that adds AI features: an assistant that drafts text, a scoring function that prioritises, an automatic recommendation. Nobody bought "an AI". The vendor included it in the new release, and it was switched on by default. The organisation has been using it for months without ever classifying it.
The tool an employee brought in. Someone started using a generative assistant to draft emails, summarise documents or prepare proposals. It works, it saves time, it spreads across the team. It never went through IT or procurement. This is BYOAI — bring your own AI — and it's usually the biggest blind spot, because it can also be sending company data out to services nobody has evaluated.
The feature hidden inside a contracted service. The chatbot in the booking software, the filter in the recruitment system, the route optimiser in the logistics platform. What got procured was the service, not "the AI". But the AI is there, processing data and, sometimes, influencing decisions.
Why this is a regulatory problem, not just a tidiness one
An AI system the organisation hasn't inventoried is still subject to the AI Act and the GDPR, exactly as if it had been bought under a contract with three signatures. The law doesn't distinguish between the AI you decided to use and the AI that slipped in.
That means shadow AI can be triggering obligations without anyone realising:
- An office assistant that processes personal data without a reviewed legal basis.
- A chatbot that interacts with customers without the transparency notice Article 50 requires, applicable since 2 August 2026.
- A candidate-scoring feature that pushes the system into the high-risk category, with the timetable that implies.
- Data leaving the company for a service outside the European Economic Area without a transfer mechanism.
None of these risks shows up on a dashboard if the system isn't in the inventory. And none of them goes away just because nobody looked.
How to build an inventory that actually works
A useful inventory isn't a list of names. It's a living register that captures, for each system, the minimum needed to classify and govern it:
- What it is and what it does: name, vendor, specific function, department that uses it.
- What data it touches: whether it processes personal data and of what kind (identifying data, health data, employee data). This is where half the classification gets decided.
- What role your organisation plays: in almost every case, that of the deployer. Distinguishing this from the provider role is essential, because many obligations — technical documentation, registration — belong exclusively to the provider.
- Origin of the data and the vendor: where processing takes place, whether there's an international transfer.
With that in place, each system can be classified by its risk level and slotted into the right timetable. Without it, everything else floats free.
The inventory is never finished
A common mistake is treating the inventory as a project with a closing date. It isn't one. Shadow AI keeps arriving: every software update can add a new feature, every team can adopt a new tool. The inventory that was complete in March is out of date by June.
That's why it makes sense to treat it as a permanent register, not a document. Adding a system should be easy; reviewing periodically what has changed should be routine. AI governance that works isn't the kind that built a perfect inventory once — it's the kind that keeps its inventory alive.
Start there. Before buying anything, before writing a policy, before classifying risk: ask honestly what AI your organisation is already using. The answer is the foundation everything else is built on.
This article is for informational purposes only and does not constitute legal advice.