Resources 8 min read

AI Inventory and Use-Case Management

What belongs in an AI inventory, how to run the first one without driving adoption underground, and how to keep it true once the initial sweep is over.

Wooden shelves holding rows of colored ring binders, each with a written spine label.

An AI inventory is a current record of the AI systems an organization uses, who owns each one, and what data goes into it. It is the first thing a governance program builds and the thing every other control depends on.

That an inventory comes first is argued at length in AI governance for public-sector organizations. This page is about the artifact itself: what belongs in it, who keeps it, and how it stays true after the first month.

What an inventory is for

Three things, and they are worth separating because organizations often build for one and are then disappointed by the others.

It makes risk assessable. You cannot classify, secure, review or retire a system you have not listed. Every domain in the governance framework takes the inventory as input, and the NIST AI Risk Management Framework places establishing context, its MAP function, before the functions that measure and manage risk for the same reason.

It makes questions answerable. A board asking whether AI is used in decisions about people, a customer asking whether their data trains a model, an auditor asking who approved something: all three are inventory queries.

It surfaces what nobody meant to adopt. The first inventory typically finds more than expected, most of it neither malicious nor careless.

What counts as an AI system for this purpose

Scope this deliberately or the exercise either collapses into everything or misses most of what matters.

A workable definition: anything that generates content, makes or materially informs a decision, ranks or classifies, extracts information from unstructured material, or predicts. That covers generative assistants, retrieval and search over your own documents, transcription and summarisation, scoring and triage tools, and the recommendation features inside products you already own.

It excludes ordinary automation with fixed rules. A workflow that routes a form on a field value is not an AI system, and treating it as one buries the entries that matter.

Include systems you did not buy. Free tools staff use in a browser belong on the inventory precisely because nobody procured them.

The fields worth recording

Nineteen fields, and most entries will have blanks in the first pass. A partially complete inventory is useful; a perfect one that took six months is not.

  • System and vendor: what it is and who supplies it.
  • Owner and business unit: the person answerable, and where they sit.
  • Purpose: what it is used for, in a sentence a non-specialist understands.
  • AI type and model: generative, predictive, classification, retrieval; and the underlying model where the vendor discloses it.
  • Data used and data classification: what goes in, and its sensitivity under whatever scheme you already use.
  • Users: who has access, and roughly how many.
  • Decision impact: whether the output affects a decision about a person.
  • Human oversight: whether a person reviews output before it takes effect, and who.
  • External exposure: whether output reaches anyone outside the organization.
  • Risk tier: the classification from your own scheme.
  • Approval status and review date: whether it is approved, and when that expires.
  • Vendor review, security review and privacy review: whether each has happened, and when.

Three of those carry most of the weight. Owner, data classification and decision impact will drive nearly every subsequent decision, so if the first pass captures only three fields per system, capture those.

How to run the first inventory

Ask, do not audit. The framing determines the quality of the answer, and an audit framing produces an undercount that misleads everything downstream.

Send a short request stating plainly that nobody is in trouble and that the purpose is to find out what is useful. Ask three questions: what AI tools do you use for work, what do you use them for, and does the organization pay for them.

Then find what people cannot tell you. Review the admin consoles and release notes of your major platforms for AI features enabled by default. Check expense claims and card statements for individual subscriptions. Ask your identity provider which applications staff have signed into.

Expect the result to be larger than the estimate. That gap is the finding, not a failure of the exercise, and it is the strongest argument you will ever have for the rest of the program.

Undeclared use is a symptom, and the fix is a route to yes

The tools people adopt without asking are almost always tools that solve a real problem. Treating that as a discipline matter produces the wrong response and drives the next round of adoption further underground.

The durable fix is an approved list and a documented, fast route onto it. An organization that publishes what is permitted and answers requests within a week gets told about new tools. One that publishes only prohibitions finds out at the next inventory.

Where a tool has to be declined, say why, and say what may be used instead. A refusal with an alternative is a governance decision; one without is an obstacle to be worked around.

Use-case management: the part that is not the list

An inventory records systems. Governance decisions attach to use cases, and the distinction becomes important quickly.

One assistant may be approved for drafting internal documents, not approved for anything touching personal data, and under review for customer correspondence. Those are three governance positions on one row of the inventory. If your record cannot express that, it will either over-approve or block a system that is fine for most of what it does.

Practically: allow multiple use cases per system, each with its own purpose, data classification, risk tier, oversight requirement and approval status. This is also what makes approval renewable, because a use case can be retired without retiring the system.

Keeping it current

An inventory decays from the day it is finished. Three mechanisms keep it usable.

A trigger at the point of purchase. Procurement and expense approval should ask whether the product includes AI features, so new entries arrive as they are acquired rather than at the next sweep.

A scheduled re-ask. Twice a year, repeat the short request from the first inventory. It is cheap and it catches the tools that arrived without a purchase.

Vendor change triggers. A supplier changing its model, terms or default settings should reopen the entry. This is the trigger organizations most often lack, and the one most likely to invalidate an earlier assessment quietly.

Four mistakes that make an inventory useless

Recording the technology instead of the use. An entry reading "large language model, Vendor X" tells a reviewer nothing they can act on. An entry reading "drafts first-response letters to benefit applicants, reviewed by a caseworker" can be classified, secured and reviewed by someone who has never met the system.

Letting it become a procurement register. If the only route onto the inventory is a purchase order, everything free and everything bundled is invisible, which is most of the exposure in a typical organization.

Perfectionism about completeness. Teams delay publishing until every field is filled, and the delay costs more than the blanks. Publish with gaps, mark them, and fill them as each system comes up for review.

No maintainer. An inventory with no named owner is accurate on the day it is finished and misleading within a quarter, which is worse than not having one because decisions get made against it.

Where it lives

A spreadsheet is a legitimate answer for most organizations, and a better one than a tool nobody updates. What matters is that it has a named maintainer, one authoritative copy, and a visible last-reviewed date.

Federal agencies operate under a specific requirement here: OMB Memorandum M-25-21 requires federal agencies to maintain an AI use case inventory, alongside a designated Chief AI Officer and minimum risk management practices for high-impact AI. That obligation applies to federal agencies. A business, a school district or a nonprofit may reasonably adopt the same shape, and many do, but it is a choice rather than a requirement placed on them.

Keep the history. When an entry changes tier, changes owner or is retired, record what it was and when it moved. That history is what lets you answer the question an auditor or a board actually asks, which is not what the position is today but when it changed and who decided.

What to do with the finished list

Classify it, assign owners, and set review dates. The inventory is an input to AI risk assessment, and the vendor column is the input to AI vendor risk assessment. If you are building the whole program, the inventory is step two of the ten-step sequence.

LABUSA builds inventories with organizations as part of an AI governance program support, including the part most teams find hardest, which is finding what nobody declared. If you would like help running the first one, get in touch.

About LABUSA

LAB Information Technology Incorporated (LABUSA) is a trusted provider of managed IT solutions, empowering organizations with secure, efficient, and scalable technologies. With expertise spanning cybersecurity, cloud services, enterprise software, and data management, LABUSA helps clients modernize operations, strengthen compliance, and optimize performance. Our customer-focused approach ensures tailored solutions that align with organizational goals while maintaining the highest standards of reliability and security. Headquartered in Houston, Texas, LABUSA serves government agencies, corporations, and nonprofits across the United States and internationally.