The AI Inventory Crisis Nobody Is Talking About
Ask a CIO how many AI systems are operating in their organisation and most will give you a number. Ask them how confident they are in that number and most will pause.
The honest answer, for the majority of enterprises in 2026, is: we do not know. We know what we approved. We have considerably less visibility into what is actually running.
This is the AI inventory crisis. It is not a future problem. It is happening now, in most regulated enterprises, and it is getting worse as AI adoption accelerates. Microsoft Copilot is rolling out at enterprise scale. Salesforce Agentforce is being deployed by revenue teams. Individual employees are connecting AI tools to shared organisational data through OAuth grants that IT has never reviewed. The inventory gap is widening faster than most governance functions can close it.
This article explains why the inventory gap exists, why it matters more than most organisations currently appreciate, and what a credible AI inventory programme actually looks like in 2026.
Most enterprises can tell you what AI they approved. Very few can tell you what AI is actually running. The two lists are not the same.
Why AI Inventories Are Becoming Mandatory
Two years ago, maintaining an AI inventory was best practice. Today it is a regulatory obligation, and for regulated firms in the UK and EU, the obligation is already in force or imminent.
EU AI Act Article 26 requires deployers of high-risk AI systems to maintain documentation of the AI systems they use and to monitor their operation. You cannot document what you have not inventoried. You cannot monitor what you do not know is running. The inventory is not a precursor to compliance. It is compliance.
FCA SYSC 8 governs material third-party arrangements, which increasingly includes AI agents procured from vendors or built using third-party AI APIs. The FCA expects firms to identify these arrangements, assess their materiality, and demonstrate oversight. An AI agent that was never formally identified cannot be formally overseen.
The ICO's AI Governance and Accountability Framework, specifically Control 4 on transparency and accountability, requires organisations to maintain awareness of AI systems that process personal data. Most enterprise AI agents process personal data in some form.
Taken together, these obligations mean that for FCA-regulated firms, the AI inventory is not optional. It is the foundation on which every other governance obligation depends.
How Copilot, ChatGPT, Gemini, and Agentforce Create Visibility Gaps
The AI inventory challenge is made significantly harder by how enterprise AI is actually being deployed. The model of a single, centrally approved AI system is not what most organisations are living with. Instead, they are managing an expanding population of AI capabilities across multiple platforms, deployed at different speeds by different teams, with varying degrees of IT involvement.
Microsoft Copilot
Microsoft 365 Copilot is deployed at the Microsoft tenant level but operates through user-level permissions. Its data access scope is determined by what each user has access to, not by a centralised permission model. A Copilot deployment that is technically within IT's control can expose sensitive data through individual users' over-provisioned permissions. The inventory question for Copilot is not simply "is it deployed?" It is "what data can it access, for which users, under what permissions, and has that been reviewed?"
ChatGPT Enterprise and OpenAI Assistants
Organisations with ChatGPT Enterprise have a degree of admin visibility into usage. Organisations where employees use personal OpenAI accounts with ChatGPT plugins connected to shared organisational data (Google Drive, Outlook, Slack) have significantly less. Those plugin connections create OAuth grants that are visible at the individual platform admin level but are not aggregated anywhere. They will not appear on a manually maintained inventory.
Salesforce Agentforce
Agentforce configurations are typically deployed by sales operations, revenue operations, or CRM teams, often without formal IT or compliance involvement. An Agentforce agent configured to access customer records, generate outbound communications, and update CRM data is performing regulated-adjacent functions at scale. Whether it appears on the AI inventory depends entirely on whether the team that deployed it thought to tell anyone.
Google Workspace AI Features
Google's AI features (Gemini in Gmail, Workspace AI in Docs and Sheets, Apps Script integrations) are embedded in tools that employees use every day. Many employees are not aware they are using AI. They are using Google Docs and Gmail, which now have AI features. These features are not systematically inventoried because they were not installed. They appeared as product updates. They nonetheless process potentially sensitive data at significant scale.
The inventory gap is not caused by bad governance intentions. It is caused by the speed and embeddedness of AI deployment outpacing the governance processes designed for a slower, more deliberate technology adoption model.
Why Spreadsheets Fail
The universal first response to the AI inventory problem is a spreadsheet. Ask IT, procurement, or an AI governance team to produce an AI inventory and you will typically receive a spreadsheet listing the tools they know about, maintained when someone remembers to update it.
Spreadsheets fail for four specific reasons that are directly relevant to regulatory scrutiny:
- They capture sanctioned tools, not actual deployments. The unsanctioned tools (the OAuth-connected plugins, the user-built automations, the shadow AI) do not appear on a spreadsheet maintained by IT because IT did not approve them and therefore does not know about them.
- They are not evidence of monitoring. A spreadsheet is a record. It is not evidence that monitoring of the listed systems occurred, that the list was current as of a specific date, or that any action was taken based on what the inventory showed. A regulator asking for your AI inventory is not asking for a list. They are asking for proof of active oversight.
- They go stale between updates. AI deployments change continuously. New OAuth grants are created daily. SaaS tools add AI features in product updates. A spreadsheet updated quarterly captures a snapshot of a moving target. Between updates, the inventory is inaccurate.
- They cannot detect cross-platform patterns. A spreadsheet lists tools. It does not detect that Agent X on Google is the same logical agent as Agent Y on Microsoft, or that together they create a risk pattern neither presents individually.
The Cost of Unknown AI Systems
The risk of not knowing what AI systems are running is not theoretical. There are three categories of cost that materialise from inventory gaps in regulated firms:
Regulatory exposure
A firm that cannot produce an AI inventory when requested by the FCA or ICO is demonstrating that its AI governance programme is not operational, regardless of what its policies say. The regulatory risk is not just a fine for a specific breach. It is the supervisory consequence of demonstrating that a fundamental governance capability is absent.
Data exposure
AI agents with over-permissioned OAuth grants, or agents that were never reviewed for data access scope, can access sensitive data (customer records, financial data, personnel files) at a scale that no individual user could. The inventory gap is simultaneously a data protection gap. What you have not inventoried, you have not assessed for data access risk.
Incident response failure
When a data incident occurs involving an AI agent, the first question is: what did the agent have access to, and what did it do? An organisation without an AI inventory will spend critical incident response hours, or days, answering a question that should have been answered before the incident occurred.
Building a Living AI Inventory
The response to the AI inventory crisis is not a better spreadsheet. It is a different approach, one built on programmatic discovery rather than self-reporting, and on continuous monitoring rather than periodic snapshots.
A living AI inventory has four properties that distinguish it from a static register:
- Programmatic discovery. The inventory is populated by querying workspace admin APIs across platforms, not by asking teams to self-report. This surfaces the tools that self-reporting misses: the OAuth grants, the user-built automations, the embedded AI features.
- Continuous or regular cadence. Discovery runs on a schedule, not when someone remembers. Each run detects additions, changes, and removals since the last cycle.
- Classification on discovery. Each discovered agent is immediately assessed for risk level, data access scope, and regulatory relevance. The inventory is not just a list. It is a risk-stratified register.
- Signed evidence at each cycle. Each inventory cycle produces a signed, timestamped record of what was found, how it was classified, and what the governance status of each agent was at that point. This is what turns an inventory into regulatory evidence.
AI Inventory as Governance Evidence
The distinction between an AI inventory and AI governance evidence is important. An inventory is a record. Governance evidence is a signed, verifiable artefact demonstrating that the inventory was current as of a specific date, that the agents in it were classified and risk-assessed, and that the appropriate oversight was in place.
For Article 26 purposes, it is the evidence (not the inventory) that regulators require. The inventory is the input. The signed evidence pack is the output that survives regulatory examination.
AETHER Pulse generates both. It discovers AI agents programmatically across seven platforms (Google Workspace, Microsoft 365, OpenAI Assistants, Salesforce Agentforce, Microsoft Copilot Studio, LangSmith, and AWS Bedrock), classifies each using a five-dimensional risk framework, detects eight cross-platform toxic-combination patterns, and generates HMAC-SHA256 signed evidence packs at configurable cadences. The evidence pack is the inventory, classified, signed, and verifiable.
Published methodology: aetherpulse.app/methodology
Frequently Asked Questions
How many AI systems does a typical regulated firm have?
The honest answer is: more than they think. Organisations that have run programmatic discovery typically find two to five times the number of AI agents they expected, because programmatic discovery surfaces the OAuth grants and user-built automations that self-reporting misses.
Do embedded AI features in SaaS tools count as AI systems for inventory purposes?
Yes, where those features access organisational data or perform functions that affect regulated activities. Microsoft Copilot in Outlook, Gemini in Google Docs, Salesforce Einstein. These are AI systems processing organisational data. They belong in the inventory.
How do we manage the discovery of AI agents we did not know about?
Discovery of unknown agents is the expected outcome of a systematic inventory exercise. The appropriate response is to classify each discovered agent, assess its risk level, take proportionate action where risks are identified, and document the process. Discovering unknown agents is not a failure. It is the inventory working as intended.
What is the right cadence for AI inventory updates?
Monthly is a defensible minimum, aligned to risk committee meeting cycles. Higher-risk environments may warrant more frequent cycles. The cadence matters less than the consistency. A monthly cycle consistently executed is more defensible than a quarterly cycle with gaps.
Working on Article 26 readiness, deployer-side governance evidence, or AI agent risk at a regulated firm? We'd value 15 minutes of your perspective.
Start a conversation