G2 - You Can't Govern AI You Haven't Found.
Most AI estates are undercounted: the procured tools, the features that arrived quietly inside vendor upgrades, the shadow tools people rely on but never registered. Governance that covers one hundred percent of a partial inventory covers far less than it thinks.
Where this gets hard
- AI arrives through four doors — built, bought, embedded and unsanctioned — and most inventories watch only the first.
- Vendor upgrades ship AI features into systems you already own, with no procurement moment to catch them.
- Shadow AI isn't malice; it's unmet demand routing around friction — and punishing it drives it deeper underground.
- Nobody owns the inventory, so it decays: last year's spreadsheet quietly becomes this year's fiction.
- Without a trustworthy denominator, ‘all our AI is monitored’ is unfalsifiable.
Where to start
- Run a discovery exercise across all four doors — including expense data and usage signals for the unsanctioned layer.
- Give every discovered system one named owner and one line in a register: purpose, users, data touched.
- Refresh on a schedule, quarterly or better, with the refresh date visible — an undated inventory is an expired one.
- Treat every shadow-AI finding as two signals: fix the perimeter, and fix the friction that created the workaround.
- Report coverage as your first governance headline: the percentage of the estate inventoried, owned and classified.
The companion consulting document on our website includes a four-door discovery checklist and an AI inventory register template.
Part of RMAT's 12-part series on AI governance — Governing AI with Evidence. The companion consulting document — detailed checklists, a risk table, a maturity self-assessment and a 90-day action roadmap — is available on our website. #CEO #AI #Governance #Risk #CIO #CTO