AI use case

AI system and model inventory with shadow AI discovery

A governed register of every AI system and model an organization builds, buys or uses, with its owner, purpose, data, risk tier and approval status, kept current by AI that discovers unregistered use, reads the documentation and assembles the evidence a board, auditor or supervisor asks for.

By Len Debets · Last verified 27 September 2026 · 4 public deployments

USD 14,160 to USD 247,500
Indicative value per year
A bank or insurer with 150 AI systems and models in scope of its AI policy. Worked example, see how it is calculated.

What problem does it solve?

AI governance frameworks start from the same question: which AI systems do you run? The NIST AI Risk Management Framework asks for mechanisms to inventory AI systems, the Monetary Authority of Singapore's proposed AI risk management guidelines expect financial institutions to keep accurate and up to date AI inventories, US federal agencies (with limited exceptions) must inventory their AI use cases every year, and the EU AI Act's deployer and registration duties presume an organization knows which high risk systems it uses. Answering the question per system, with an owner, a purpose, a risk tier and evidence of approval, is harder than it looks.

A register kept as a spreadsheet that project teams fill in once, at approval, misses the AI that arrives inside software someone bought, the assistant a team switched on in a SaaS tool, and the prompts employees paste into public chatbots. Use also grows fast: the US Department of Justice reports that its 2025 inventory holds 315 entries, 30.7% more than the year before. Gaps have consequences. In May 2026 CB Financial Services reported a material cybersecurity incident to the SEC after non public customer information at its subsidiary Community Bank was handled with an unauthorized AI based application, the kind of unregistered use that discovery aims to surface early.

  • In its 2025 workshops with 13 banks, ECB Banking Supervision observed that all banks preparing for the AI Act had built up AI systems inventories and a set process to put AI models into production, while data governance adapted to AI was emerging only in a small number of cases.AI workshops with banks 2025, annex (2025)

How does it work?

  1. Define the record. One schema for every AI system: owner, business purpose, users, vendor or in house, model and version, data categories (including personal data), autonomy level, risk tier under internal policy and the EU AI Act, approval status, review date and links to documentation.
  2. Discover what is actually running. An agent reconciles the register against evidence sources: procurement and contract records, SaaS and API usage logs, cloud and model platform accounts, code repositories and network egress to AI services. Anything that looks like AI and has no entry becomes a candidate record for an owner to confirm or retire.
  3. Draft the entry from the documents. Document AI reads model cards, vendor documentation, data protection impact assessments and approval minutes and pre fills the record, citing the page each field came from. The owner confirms or corrects every field.
  4. Classify and route. The draft risk tier and the triggers for deeper review (personal data, decisions about people, customer facing use, material service provider) are proposed by rules plus a model, and a governance officer decides.
  5. Keep it current. Scheduled checks flag records past their review date, models whose version changed, vendors whose terms changed and systems whose usage jumped.
  6. Answer and assemble. Staff and auditors ask questions in plain language ("which customer facing systems use personal data and a third party model?") and get answers with links to the records, and the agent assembles the evidence pack for a named system on request.
Audience
Employee facing
Autonomy
Copilot
Adoption
Early adopters
Channels
Internal tools, Microsoft Teams

What is it worth?

Benchmarks are computed from the public deployments below: one data point per organization per KPI, with who made each claim.

No public deployment has disclosed a measurable outcome yet.

Value drivers: Compliance quality, Risk and loss reduction, Employee productivity, Speed and cycle time.

Indicative value

A bank or insurer with 150 AI systems and models in scope of its AI policy

USD 14,160 to USD 247,500

Specialist time released from inventory upkeep and evidence assembly per year

How this is calculated

Formula: (systems * hoursPerSystem * automationShare + requests * hoursPerRequest * requestReduction) * hourlyCost. The low scenario uses every low input, the high scenario every high input.

InputLowHighBasis
AI systems and models in the register systems, systems100200Editorial assumption for a mid sized regulated firm, counting vendor AI and generative AI tools. Replace with your own count.
Manual effort per system per year to discover, document, attest and review hoursPerSystem, hours per system per year820Editorial assumption covering the owner, the second line reviewer and the inventory administrator. Replace with your own time study.
Share of that effort the discovery and drafting removes automationShare, fraction of effort0.250.45Editorial assumption; no public benchmark exists yet. Owners still confirm every field.
Evidence requests per year from supervisors, auditors and the board requests, requests per year615Editorial assumption. Replace with your own count of inventory related requests.
Hours to assemble one evidence pack by hand hoursPerRequest, hours per request2060Editorial assumption.
Share of evidence assembly time saved requestReduction, fraction of time0.30.5Editorial assumption; assembly still needs a human review before anything leaves the firm.
Fully loaded cost of a risk or technology specialist hour hourlyCost, USD per hour60110Editorial assumption. Replace with your own rate.

What it leaves out: Time released only. It leaves out the value that matters most and is hardest to price: the incidents, fines and failed audits avoided because shadow AI is found early, and the faster approval of new AI use cases once the register is trusted. It also leaves out the cost of the discovery integrations.

Who already uses it?

4 public deployments, strongest evidence first. Grades: A regulator or audit, B the organization itself, C vendor case study, D anonymous or estimate.

Board of Governors of the Federal Reserve System

United States · Government and public sector · 2025

ProductionGrade B

The Federal Reserve Board runs a central AI Program that collects every AI use case in Board work and in functions delegated to the Reserve Banks, checks each against the Board's AI policy, screens it for high impact characteristics and routes it to the matching governance path. Use cases sit in a common repository that supports reporting and ongoing tracking and is validated periodically. The 2025 public inventory records, per use case, the stage, purpose, vendor, data used, personal data involvement and high impact designation.

No outcome disclosed.

Office of Management and Budget

United States · Government and public sector · 2025

ScaledGrade B

US federal agencies must inventory their AI use cases every year, submit the inventory to the Office of Management and Budget and publish the releasable part as machine readable data. OMB consolidates the agency inventories in a public repository with a fixed schema (purpose, stage, vendor, data, risk designation). The 2025 consolidation, as of 13 April 2026, lists 3,611 individually reported AI use cases, 445 of them high impact, plus separately consolidated commercial off the shelf AI uses; the 2024 consolidation listed 2,133 use cases from 41 agency submissions.

  • AI systems inventoried: 3611, 2025 consolidated federal inventory, individually reported use cases in all stages, as of 13 April 2026
    "3,611 individually-reported AI use cases (all stages of development)"
    Claimed by: organization

U.S. Department of Justice

United States · Government and public sector · 2025

ScaledGrade B

The Department of Justice consolidates the AI use cases of all its components into one annual inventory, reviewed by component representatives on its Emerging Technology Board with the Chief AI Officer. The 2025 inventory covers use cases in every stage from pre deployment to retired, combines similar, widely adopted AI use cases into single department wide entries and removes duplicate or mislabeled entries. It holds 315 entries, 30.7% more than the 2024 inventory, which DOJ attributes to closer collaboration between components to accelerate AI adoption.

  • AI systems inventoried: 315, 2025 inventory
    "The 2025 AI Use Case Inventory includes 315 entries, a 30.7% increase from the 2024 inventory."
    Claimed by: organization

Unilever

United Kingdom · Manufacturing · 2023

ScaledGrade C

Unilever built an AI assurance process in which every new AI application, broadly defined to include any prediction or automation, is registered, triaged and rated red, amber or green for effectiveness and ethical risk before it goes into production. Holistic AI co created the inventory and risk management platform that the data ethics team uses to track submissions, completeness and risk ratings across a decentralised global business, with a growing share of assessments mapped to the EU AI Act. No quantified outcome is published in a form that can be quoted as a sentence.

No outcome disclosed.

How do you implement it?

A model agnostic playbook: what to prepare, the order to build in, and what goes wrong.

Data you need

  • A written AI policy with a definition of what counts as AI and a risk tiering method
  • The current register, however incomplete, and the list of approved AI tools and vendors
  • Procurement and contract records that show which suppliers provide AI features
  • Usage logs from SaaS administration, cloud accounts, API gateways and network egress
  • Model cards, vendor documentation, impact assessments and approval records

Systems to integrate

  • Governance, risk and compliance platform or the existing model inventory
  • Procurement and contract management system
  • SaaS management, identity provider and cloud accounts for usage signals
  • Code repositories and model registries
  • Document stores holding model documentation and approvals
  • Ticketing or workflow tool for owner attestations

Complexity: Medium

Keeping a register is easy; keeping it true is the work. Discovery needs read access to procurement, SaaS, cloud and network data, which crosses several owners, and the risk classification needs a written policy before any AI can apply it.

  1. 1

    Write the definition and the schema first

    Agree what counts as an AI system (include vendor features and general purpose assistants), the mandatory fields and the risk tiers. Map the tiers to the EU AI Act categories and to your sector rules so one record answers every framework.

  2. 2

    Seed from what you already know

    Load the existing register, the model risk inventory, the approved tool list and the procurement records. Deduplicate before adding anything new, as the US Department of Justice did when it combined similar, widely adopted AI use cases into single department wide entries.

  3. 3

    Add discovery sources one at a time

    Start with the highest yield signals (SaaS admin consoles, API keys to model providers, network egress to AI domains), and route each unregistered hit to a named owner as a candidate record, not as an accusation.

  4. 4

    Let AI draft, owners confirm

    Pre fill records from documents with a citation per field, then ask the owner to confirm. Measure how often owners correct the draft and fix the extraction where corrections cluster.

  5. 5

    Put the register in the approval path

    No production release, contract signature or tool enablement without a record. This is what keeps the register current after the first clean up.

  6. 6

    Rehearse the evidence request

    Pick one high risk system and ask for the full evidence pack as a supervisor would, time it, and fix the gaps before the real request arrives.

Guardrails

  • The AI proposes records, tiers and links; a named human owner confirms every record and a governance officer approves every risk tier
  • Every field drafted from a document cites the source document and page
  • Discovery reads metadata and usage signals, not the content of employee prompts, unless policy and law allow it
  • The register itself is access controlled and logged, because it maps the organization's most sensitive systems
  • The inventory agent is itself an entry in the register, with its own owner and review date

KPIs to instrument

  • Coverage, the share of discovered AI systems that have a confirmed record
  • Number of unregistered systems found per month and time from discovery to confirmed record or retirement
  • Share of records past their review date
  • Owner correction rate on AI drafted fields
  • Hours to assemble an evidence pack for one system

Human in the loop

Owners attest to their records, the second line approves risk tiers and exceptions, and the AI governance committee decides on retiring or blocking unregistered systems. The AI never changes an approval status or blocks a tool on its own.

Common failure modes

The register is complete on paper only
Teams fill it in once at approval and never again. Tie the record to release, contract renewal and tool enablement, and flag records whose model version or usage changed.
Discovery as surveillance
Reading employee prompts to find shadow AI creates a privacy and trust problem. Use metadata and usage signals first, involve the works council or employee representatives where required, and offer an approved alternative for every tool you block.
Confident but wrong classification
A model tier that looks authoritative gets copied into reports without review. Keep the tier as a proposal until a named person approves it and record who did.
Definition too narrow
Only in house machine learning models get registered, while vendor features and generative AI assistants carry most of the new risk. Include anything that infers outputs from input, as the EU AI Act definition does.

What are the risks and rules?

EU AI Act

Depends on design

Minimal for a system level register of systems and owners with no monitoring of individual employees; it is not listed in Annex III and is the instrument deployers use to meet obligations such as the Article 26 duties for high risk systems and the Article 49 registration of Annex III systems in the EU database. Limited where the plain language assistant that staff and auditors query is not obviously an AI system to its users: under Article 50(1) its provider must then design it so people are told they are dealing with AI. Possibly high risk under Annex III point 4(b) on worker management if the discovery process monitors or evaluates the behavior of individual employees rather than staying at the level of systems and owners.

Guidance

  • Article 49: Registration (European Union, Europe). Providers register high risk systems listed in Annex III in the EU database before placing them on the market or putting them into service (critical infrastructure systems under point 2 are registered nationally), and deployers that are public authorities register their use; an internal register is the practical source for that data.
  • Article 26: Obligations of deployers of high risk AI systems (European Union, Europe). Deployers must monitor the operation of high risk systems, keep logs and assign human oversight, which presumes they know which systems they deploy.
  • MAS Guidelines for Artificial Intelligence (AI) Risk Management, consultation paper (Monetary Authority of Singapore, Asia Pacific). Financial institutions are expected to identify AI usage across the firm, maintain accurate and up to date AI inventories and assess risk materiality.
  • AI RMF Core, GOVERN 1.6 (NIST, North America). Mechanisms are in place to inventory AI systems, resourced according to organizational risk priorities.
  • M-25-21: Accelerating Federal Use of AI through Innovation, Governance, and Public Trust (US Office of Management and Budget, North America). Federal agencies must inventory AI use cases at least annually, submit them to OMB and publish a public version; a useful template for the fields a register needs.
  • AI workshops with banks 2025, annex (ECB Banking Supervision, Europe). Supervisory observations from 13 bank workshops, including AI systems inventories, AI Act self assessments and, as an emerging practice, automated tools that monitor the inventory and workflow.

Controls to put in place

  • A single register with an accountable owner per record and a documented definition of AI
  • Record required before production release, contract signature or tool enablement
  • Periodic attestation by owners and validation of the register by the second line
  • Audit trail of every change to a record, tier or approval status
  • Approved alternatives for common generative AI tasks, so blocking shadow AI does not stop the work

When it went wrong elsewhere

Frequently asked questions

What should an AI inventory record for each system?
At minimum the owner, purpose, users, vendor or in house status, model and version, data used (including personal data), risk tier, approval status and review date. The US federal inventory is a useful public template: the Federal Reserve Board records stage, purpose, vendor, data, personal data involvement and high impact designation for each use case.
How do you find shadow AI without monitoring employees' prompts?
Start with metadata: SaaS administration consoles, API keys to model providers, procurement records and network egress to AI services. Route each hit to a named owner to confirm or retire, and offer an approved alternative, because blocking alone pushes use further out of sight.
Is an AI inventory required by the EU AI Act?
The Act does not set a general inventory duty, but its obligations presume one: deployers of high risk systems must monitor them and assign human oversight, and providers (and deployers that are public authorities) must register Annex III high risk systems in the EU database. Sector supervisors go further: the Monetary Authority of Singapore's proposed guidelines expect financial institutions to maintain accurate, up to date AI inventories.
Can AI maintain the inventory on its own?
No, and it should not. AI can discover candidates, pre fill records from documents and flag stale entries, but an accountable owner confirms each record and a governance officer approves the risk tier. The inventory agent is itself a system in the register.

How to cite this page

Blits.ai AI Use Case Library, "AI system and model inventory with shadow AI discovery", last verified 27 September 2026, https://www.blits.ai/ai-use-cases/ai-model-inventory. Licensed under CC BY 4.0. Method: how we verify use cases.

Changelog
  • 27 September 2026: First published

Related use cases

BankingInsurance

AI copilot for model risk validation and monitoring

A copilot for independent model validation and review, whether run by a bank's validation function, an external tester or a supervisor, that checks model documentation against the model risk standard, generates and scores challenger tests (for generative AI, often with an LLM as a judge calibrated against human experts), watches production models for drift and drafts and consistency checks the validation report. An accountable validator owns every conclusion.

Deployments
3 public, best grade B
Autonomy
Copilot
Cross industryBanking

Generative AI copilot for internal audit

A copilot for internal auditors that drafts planning memos and document request lists from prior audits, summarises large evidence sets, builds risk and control matrices from policies and process documents, and drafts findings and reports, with every statement traceable to its evidence and a qualified auditor accountable for every conclusion.

Deployments
3 public, best grade C
Reported handling time reduction
55%
Banco Bradesco, vendor claim
Cross industryBanking

AI for continuous controls testing and control self assessment

AI that moves control testing from periodic samples to continuous, full population assurance: it collects evidence from source systems, maps each artefact to the control it supports, tests every transaction or record against the control's rule, flags exceptions for a human to judge and prepares the risk and control self assessment from incident and loss data for the business to review.

Deployments
3 public, best grade B
Autonomy
Supervised agent
Cross industryBanking

AI for third party and vendor risk due diligence

AI that reviews a vendor's security questionnaires, SOC and assurance reports, contracts and model documentation against the organization's control requirements, researches the vendor's ownership, sanctions, financial health and adverse media, drafts the risk assessment for a human to approve and keeps the register of material service providers current with ongoing monitoring.

Deployments
4 public, best grade B
Autonomy
Copilot
Cross industryBanking

AI regulatory horizon scanning and obligation mapping

An AI system that continuously reads publications from the regulators and standard setters an organization answers to, classifies each item by relevance and urgency, breaks new rules into individual obligations and maps them to the internal policies and controls that meet them, so compliance owners see what changed and where the gaps are.

Deployments
2 public, best grade B
Autonomy
Assist