Start a Conversation
AI & Automation
8 min read
August 31, 2026

How Do You Inventory the AI Tools Employees Are Using?

A practical AI inventory should identify tools, users, business purpose, data, integrations, owners, risk, and value without turning discovery into a months-long compliance project.

How Do You Inventory the AI Tools Employees Are Using?

Most organizations already have an AI environment whether they designed one or not. Employees may be using ChatGPT, Microsoft Copilot, meeting assistants, AI features inside SaaS products, browser extensions, coding assistants, CRM features, marketing tools, and department-specific automation.

The first practical step in AI governance is therefore not writing a large policy. It is finding out what is actually being used.

What should an AI inventory capture?

The inventory does not need to begin as a complex database. For each meaningful AI tool or use case, capture enough information to answer:

  • What tool or AI capability is being used?
  • Which department or users are using it?
  • What business purpose does it serve?
  • What data is entered, uploaded, or accessed?
  • Does it connect to company systems?
  • Who is the business owner?
  • What happens if its output is wrong?
  • Is human review required?
  • What contract or subscription exists?
  • Is the tool approved, restricted, under review, or prohibited?
  • What measurable value is expected?

That is enough to create a useful management view.

Start with discovery, not enforcement

If the first message employees hear is “report unauthorized AI use,” discovery may immediately become incomplete. A better initial message is that the company is building an inventory so useful tools can be supported, risks can be understood, and employees can receive clearer guidance.

The objective is visibility before punishment.

Use multiple discovery methods

Employee and manager survey

Ask teams what AI tools they use, what work they support, and whether employees are paying personally. Keep the survey short enough that people will complete it.

Finance and procurement review

Search corporate-card transactions, expense reports, procurement records, and SaaS subscriptions for AI services and AI-enabled applications.

Microsoft 365 and identity review

Review enterprise applications, OAuth grants, single sign-on, browser integrations, and available Microsoft AI capabilities. This can reveal tools employees may not think of as separate AI products.

Security and web telemetry

Where appropriate, existing security, DNS, browser, CASB, SaaS-management, or endpoint tools may show access to generative AI services. The goal is to identify patterns, not create an unrealistic assumption that every use can be discovered technically.

Application-owner interviews

AI is increasingly embedded inside CRM, ERP, HR, service management, cybersecurity, analytics, and productivity platforms. Ask application owners which AI capabilities have been enabled, tested, or purchased.

Inventory use cases, not only products

One tool can support ten very different risk levels. Using an AI assistant to rewrite a public marketing paragraph is not the same as using it to analyze employee records, customer contracts, source code, security incidents, or regulated data.

The inventory should therefore connect the product to the business use case and data involved.

Create a simple risk tier

A useful first-pass model can classify use cases as low, moderate, or high consequence.

  • Low: drafting, brainstorming, summarizing public or non-sensitive information with routine human review.
  • Moderate: recurring operational workflows, internal company data, customer-facing output, recommendations, or integrated automation.
  • High: sensitive data or decisions affecting employment, finance, legal rights, regulated activity, security actions, customer eligibility, safety, or other material outcomes.

The purpose is not to make the classification perfect. It is to determine which use cases deserve immediate attention.

Assign an owner

Every meaningful AI use case should have a business owner. Technology can govern platforms and security, but the business owner should remain accountable for the process, outcome, exceptions, adoption, and decision to continue or stop the use case.

Decide the disposition of each tool

After discovery, place tools and use cases into clear categories:

  • Approved: acceptable for defined business use.
  • Approved with conditions: allowed only for specified data, users, or workflows.
  • Under review: more information is needed before broader use.
  • Restricted or prohibited: risk, contractual, security, or data concerns outweigh the current value.
  • Retire or consolidate: a better approved capability already exists.

Do not forget AI embedded inside existing software

Organizations often focus on standalone generative AI products while missing AI features added to software they already license. A vendor may enable new summarization, recommendation, transcription, automation, or predictive capabilities during a routine product update.

The inventory process should therefore be continuous enough to capture changes in major business platforms.

Connect the inventory to value

Governance improves when the organization knows not only what could go wrong, but what is worth expanding. Capture the expected benefit for important use cases: time saved, cycle-time reduction, increased service capacity, improved quality, reduced error, better detection, revenue support, or another measurable outcome.

High-value, manageable-risk use cases should move faster. Low-value, high-risk experiments should not consume the same attention.

How often should the AI inventory be updated?

The inventory should be reviewed whenever significant tools, integrations, vendors, use cases, or data practices change. At minimum, create a recurring governance cadence so the inventory does not become a one-time spreadsheet that stops reflecting reality.

The practical starting point

You do not need to know every AI interaction before beginning governance. Start by identifying the major tools and use cases, understanding the data and consequence, assigning owners, and deciding which uses are approved.

Visibility creates the foundation for policy, risk assessment, vendor review, security controls, and measurable AI management.

STRATEGY BEFORE SOLUTIONS

Need an executive perspective on a technology decision?

Start a Conversation
Cyber VirtuesArticle page