
Building the first useful AI inventory
An organisation needs to understand how teams use AI before setting approval rules. This scenario outlines a manageable starting point for governance.
An illustrative scenario. It describes how an organisation can find out where AI is already in use and put proportionate controls around it, not a project delivered for a named customer.
The situation.
A board has asked for an AI policy. The technology team is not certain what is in use, because most of the adoption did not go through a purchase: people signed up to free tools, and several applications the organisation already licences have quietly added assistants.
Why the policy is the wrong first step.
A policy drafted now would describe an imagined estate. It would also be uniform, and uniform controls are simultaneously too heavy for somebody summarising a public document and too light for anything touching a decision about a person.
How the work would go.
Run a short discovery: ask teams directly, review expense claims and application inventories, and check which existing platforms have released assistant features. Record each use with an owner, the data it sees, and whether anything acts on its output. Classify on effect rather than on tool, in three grades. Then set controls to match, and add a small number of AI questions to the purchase process, because that is where the next capability will arrive.
What the organisation ends up with.
A register that reflects reality, a classification anybody can apply without a specialist, and a registration route fast enough that people use it rather than route around it. The policy, when it is written, then describes something that exists.
What would a better working day look like?
Bring us the process you want to improve. We’ll explore the product, technology and delivery work it needs.
