Ask a company for the list of AI systems it runs and you get a procurement export: licensed tools, seat counts, renewal dates. It is an accurate answer to a question nobody asked. The marketing assistant somebody wired into the CRM through a no-code connector is not on it. Neither is the Python script an analyst wrote in March that calls a model API on a schedule and mails the output to four people. Neither is the AI feature in the helpdesk product bought in 2023, which the vendor switched on in a quarterly update and announced in a changelog.
That absence is the whole problem, and it is also where the work starts. Four steps, in a fixed order: find every system that uses AI, classify each by the risk category its use falls into, name the risks that category actually carries, and put a person's name against every mitigation. Most governance material describes the destination and skips the route, which is why leaders who genuinely want to start have nowhere to put their hands. Four weeks is enough for a first pass at all four, and roughly half of that will go to the first one.
On this page
- Week one is detective work
- Two names per row
- Week two: tier, and expect most of it to come back low
- Week three: name the risks the tier carries, not risks in general
- Week four: mitigations with a name on each
- Ship it at eighty percent
Week one of AI governance is detective work
The inventory has to be assembled, because no single function holds it and no single function can hand it to you on request. Four places to look, and you need all four.
IT software-approval records give you the sanctioned tools. Procurement contracts give you the AI clauses buried in third-party software that nobody flagged as AI when it was bought, because in 2022 it wasn't. Privacy and legal give you the Data Protection Impact Assessments (DPIAs): anything processing personal data left a paper trail, and that trail is often the only written description of what a system actually does. Then the code repositories, searched for ML library imports and calls to model API endpoints. That last search is the one that reveals the systems with no owner, no budget line, and no ticket.
What comes out sorts into three categories: built internally, bought from a vendor, or embedded in something you already own — Copilot, Slack, Google Workspace, the CRM, the ticketing system. The third category is the one that surprises people, and it is usually the largest by headcount exposure, because every employee has it and nobody chose it. A structured workflow audit is one way to force all four searches to happen in the same fortnight rather than across four separate quarters.
Two numbers explain why one function cannot supply the list. Gartner's Hype Cycle for Agentic AI 2026 puts business-unit funding at nearly 30% of AI initiatives, which means roughly a third of the estate was never procured through the channel you are searching. And in Gartner's Predicts 2026 note, 56% of IT leaders strongly agree that IT cannot drive generative AI adoption on its own. One caveat I will state plainly, since this is an article about governing what you can actually see: the reprint of that note has its evidence section collapsed. It lists no population, no sample size and no fieldwork dates. Treat it as a 2025 Gartner survey and weight it accordingly.
The ServiceNow and ThoughtLab maturity index from 2026 puts the shape of the gap in one pair: 59% of organisations report using agentic AI, while 9% report meaningful progress on autonomous multistep workflows. Whatever the definitional differences behind those two figures, no company is going to reconcile them from a procurement report.
Two names per row
Every row in the AI inventory needs two names (and this is the part almost nobody writes down): Who owns the system, and who owns the data it touches. They are rarely the same person. The system owner decides what it does. The data owner decides whether it is allowed to do it with that data — consent basis, retention, residency, who else can see the outputs. Skip the second name and you have an asset register that tells you nothing about your actual exposure. It is the same gap that shows up when nobody can say whose credentials an agent is running under.
The strongest evidence I have for this comes from that same Gartner note—with the exact same caveat. Only 14% of application leaders are confident that their current data is secure and well-governed enough to provide substantial value to both AI and human interactions. Meanwhile, 77% plan to prioritize spending on AI-ready data. That means five times as many companies are paying for their future state as those who can actually guarantee the safety of the systems they run today. Gartner projects that this confident group will reach 35% among large organizations by 2030, but keep in mind that's just a forecast, so treat it as one.
ServiceNow's index makes the operational version of the same point: assessing the data requirements for multi-step workflows forces you to update ownership and privacy policies, and those decisions determine which autonomous capabilities can be deployed at all. So treat data governance as a column in the inventory from the first week.
Week two: tier, and expect most of it to come back low
The EU AI Act attaches obligations to categories of use, not to technical sophistication. A retrieval system over your own documentation can be architecturally involved and carry no obligations. A simple scoring rule applied to job applicants carries a lot. Most internal tooling lands in minimal risk, and saying so out loud is the point of this step.
The failure mode here is over-classification: a company applying high-risk controls to a meeting summariser, burning six weeks and all its political capital, and arriving at the system that genuinely needed a conformity assessment with nothing left in the tank. I sat in a room in Grünwald last week where a lawyer, presenting to a dozen Mittelstand directors, called the alternative Compliance mit Augenmaß: a mid-sized company does not have hundreds of high-risk areas, it has six or eight, and concentrating there is what makes the obligation affordable in time and money. His subject was corporate liability generally, not AI. But the structure transfers exactly, though it only works if the logging and oversight floor the Act assumes is already there underneath.
Week three: name the risks the tier carries, not risks in general
Generic risk lists are why governance programmes stall. "Bias, hallucination, privacy" applied uniformly to forty systems produces forty identical registers and zero decisions.
Take each system apart four ways instead: what it is used for and in what environment, what data feeds it, what judgement it automates, and what happens in the real world as a consequence.
The fourth question is where the exposure actually lives. A model that predicts churn and a model that cancels accounts based on the prediction are the same accuracy and entirely different liabilities. A model that drafts a rejection letter and a model that sends it are separated by one integration that somebody enabled on a Tuesday. When people say AI risk is hard to assess, they are usually stopping at question three.
Week four: mitigations with a name on each
The inventory and the risk register are different artefacts, and conflating them is a common structural mistake. The inventory says what exists: system, owner, data owner, version, model type, category. The register says, for each one, what threatens it, how likely, how bad, what control was applied, and what residual risk is being accepted.
That last field needs a person's name attached to it.
Residual risk with no name on it has not been accepted by anyone. It has been noticed and left alone, and that reads very differently in an investigation.
Ship it at eighty percent
Governance functions stall waiting for the inventory to be complete. But that is a trap: it will not be complete, because someone is standing up a new agent this week. An eighty-percent inventory in week four beats a perfect one in month six, for the plain reason that the systems keep running in the meantime and the incomplete register still catches the two or three that matter most.
Run it centralised at first. One team making the tier calls keeps the judgements consistent while the pattern is still forming, and you cannot delegate a classification standard you have not exercised yourself. Federate to the business units once the calls have stopped surprising you. Gartner's read is that high-AI-maturity organisations centralised strategy, governance, application development and data management practices first, which matches what happens when you try the reverse: eight business units producing eight incompatible interpretations of "limited risk."
The scale of the unfinished work is not in dispute across sources. Deloitte's January 2026 survey of 3,235 leaders found 23% using agentic AI at least moderately today, 74% expecting to within two years, and 21% reporting a mature governance model for autonomous agents. ServiceNow puts organisations with implemented AI testing, auditing and risk-assessment processes at 20%. Gartner projects that successful agentic AI governance could cut regulatory compliance costs by around 70% by 2028, a projection with a number attached to it, and an argument for starting early rather than a measured return. The recurring cost is the logging, attribution and guardrails, not the build.
Four weeks of this does not make a company compliant, and selling it internally as compliance is how these programmes lose their budget in year two. What it produces is narrower: a list of what exists with two names on every row, a tier for each item, the specific risks that tier carries, and a named owner against every mitigation and every accepted residual.
So when a supervisory authority, a customer's procurement team, or your own board asks which of your systems they should be worried about and who is accountable for it, someone can answer in the meeting. Most companies start building that answer the week the letter arrives, and by then the answer takes three months and reads like it.