Short answer: An AI system inventory is a current record of every AI system an organization operates: what it is, what it can do, what data it touches, and who owns it. Automated AI system discovery builds that inventory by reading code, infrastructure, and identity configuration instead of relying on self-reported surveys.
- Every governance step depends on knowing which AI systems exist.
- Discovery reads code, infrastructure, and identity instead of trusting surveys.
- Confirmed capabilities and unverified ones must be reported separately.
Why the inventory comes first
Organizations cannot assess what they have not enumerated. Every downstream step, from risk classification to evidence collection, depends on an accurate inventory. Surveys miss systems, capture intent instead of reality, and go stale quickly, which is why shadow AI is one of the most common findings in AI governance reviews.
What discovery should capture
- Models and agents: which models are used and how autonomously the system acts.
- Tools and integrations: what the system can reach and act on.
- Data and credentials: what personal or sensitive data is present and where secrets are exposed.
- Infrastructure and pipelines: where the system runs and how changes ship.
Confirmed, not assumed
A function in source code does not prove a capability exists in production. Good discovery distinguishes what is suspected from what is confirmed, and it reports gaps honestly when it cannot verify something, such as whether a capability is authorized without identity data.
How Assessed Govern discovers AI systems
Assessed Govern connects read-only to repositories, cloud accounts, and identity providers and produces an AI System Manifest for each system. Credentials and sensitive data are detected but never stored. The manifest feeds the assessment, the CI/CD governance gate, and the determination record.
Questions
What is shadow AI?
Shadow AI is any AI model, agent, or AI-enabled feature in use without being registered in the organization’s approved inventory. Automated discovery across repositories is the most reliable way to find it.
How often should an AI inventory be updated?
Continuously. Models, permissions, and integrations change with ordinary releases, so the inventory should update whenever the code or infrastructure changes.
Does AI system discovery require write access?
No. Discovery only needs read access. Assessed Govern connectors are read-only by design and never modify the systems they observe.
