Since January 2023, the US National Institute of Standards and Technology (NIST) has maintained an AI risk management framework that became an international reference despite being voluntary. One of its earliest requests, inside the governance function, is easy to state and hard to satisfy: keep an up-to-date inventory of every AI system in use, each one with a named owner.
In the European Union, the requirement went further than a recommendation. Since August 2, 2026, anyone placing an AI system classified as high-risk on the market must register it in a public EU database before putting it into use — not afterward. The logic matches NIST's, only with a deadline attached: if a company cannot list what it runs, it cannot prove it runs anything by the rules.
In practice, almost no company has that list ready. The reason is not a lack of intent — it is that most AI systems in use today never went through a formal process that would have placed them on one. For decision-makers, the question has stopped being "should we adopt an AI policy?" and become "can we list, right now, what is already running?"
What Is Already Required
The Govern function — the first of NIST's four functions, alongside Map, Measure, and Manage — describes the inventory as "an organized database of artifacts relating to an AI system or model": documentation, incident response plans, data dictionaries, links to source code, and contact information for whoever answers for each system. The related guidance is direct: inventory mechanisms need to exist and be resourced according to each system's risk.
In the European Union, Article 49 of the AI Act spells out who registers what: providers of high-risk systems register the system before placing it on the market; public authorities using those systems register their use. The information sits in a public, searchable database maintained by the European Commission.
Both rules start from the same premise: there is no risk management without first knowing what is running. And that is exactly where the gap opens between what the rule says and what most companies actually have on file.
A study by security firm Reco, published in September 2025, measured that gap directly. At small companies, with 11 to 50 employees, the average reaches 269 unapproved AI tools per 1,000 employees. At mid-sized organizations, the number sits around 200 per 1,000. None of those tools went through an approval process on the way in — which means none of them ended up on any inventory.
An AI system inventory is an organized database of artifacts relating to an AI system or model.
Why the Spreadsheet Fails

The most common answer, when an audit or a new rule demands an inventory, is to ask every department to fill out a spreadsheet: "which AI tools does your team use?" The problem starts the day after it goes out: the spreadsheet describes what people remembered to declare, not what is actually in use.
The same Reco study found that 71% of office workers admit to using AI tools without approval from IT. Nobody fills out a spreadsheet reporting their own unapproved use — and that is precisely the use the rule wants listed.
There is also a timing problem. The same research measured that a new AI tool can take more than 400 days to be noticed by the security team, when it gets noticed at all. A spreadsheet updated once a quarter has no chance of keeping pace with that: it always describes an old snapshot of a situation that has already moved on.
The root problem is not the spreadsheet itself. It is trying to reconstruct, from the outside, something that only exists for real inside the day-to-day workflow — each connection, each agent, each document that became a source for answers. A reliable inventory cannot depend on collective memory. It has to be a consequence of how the work happens, not an extra task bolted on top of it.
What Has to Be in Place
An inventory that survives an audit is not built from a manual survey. It comes from an environment where listing is an effect of how each piece gets created, not a separate task.
Corporate identity as the single point of entry. When access to AI comes from the same directory used for email and internal systems, every person and every agent is born attached to a traceable account — not to a personal login nobody else can see.
Every connection with a registered owner and scope. A tool linked to the AI environment comes in with a named owner and a defined scope — what it can reach, and nothing beyond that — instead of a blanket access granted because someone asked for it.
Approved knowledge with a traceable origin. Documents that become a source for answers carry an owner, a current version, and, when the case calls for it, a review step before they count as official. The record of that approval is itself already a line in the inventory.
Reuse through permission, not loose copies. When an agent or a saved routine gets shared with other people, its reach is defined by person, group, or role, and it stays on record who has access to what — instead of scattering into loose copies passed around by message or email.
A record of every creation and change. Creating an agent, connecting a tool, changing a permission: each action gets logged, with a date and an owner. The list the rule asks for comes out of that continuous record, not out of a survey rushed together before an audit.
This is how Skyller was built: identity coming from the company's own directory, permission by role, and a record of every connection and every knowledge source as the default way it works — not as a report produced on request.
What You Gain From an Inventory

The first gain is immediate: when an auditor, a corporate client, or a regulator asks which AI systems the company runs, with what data, and under what approval, the answer already exists and can be pulled up in minutes. There is no need to open an internal project to reconstruct it.
The second gain shows up less in headlines but matters more day to day: without an inventory, every regulatory change turns into a survey from scratch. With continuous logging, adapting to a new rule means reviewing what is already listed, not rediscovering what the company has.
There is also a gain in incident response. If a sensitive document leaks or an automated action produces the wrong result, reconstructing what happened becomes a matter of checking a record — not gathering scattered memories from whoever was involved.
None of this replaces human judgment about risk. But without a reliable list, every risk decision gets made blind, about systems nobody can say for certain even exist.
A Roadmap to Get Started
Before ordering yet another spreadsheet, it is worth testing whether the problem is discipline or architecture, with these four questions:
- Ask for the list of AI systems in use today, with no advance notice. If the answer takes days or comes back incomplete, the problem is not the last spreadsheet — it is that no living record sits behind it.
- Check whether every item on the list has a named owner. A system with no defined owner is exactly the kind of gap a law like the EU's demands be closed before an incident, not after one.
- Measure how long it would take to discover a new tool in use. If the answer involves months, or "we don't know," the current inventory describes the past, not the present.
- Ask what changes if regulation tightens again. If the answer is "we'll have to survey everything all over again," the inventory is not part of the operation — it is a project that repeats with every new rule.






