All posts
AI
September 23, 2026

Your AI Inventory Is Missing Most of Your AI

Your AI Inventory Is Missing Most of Your AI

Think about every AI tool running in your organization right now. Not the official list. Not the approved deployments. Everything. The Copilot instances your developers connected last month. The AI features your SaaS vendors quietly enabled by default. The agents your business teams spun up without ever filing an IT request.

Now ask: how confident are you in what is actually out there?

If there is any hesitation at all in your answer, you are looking at one of the most consequential gaps in enterprise risk management today.

The Approved List Is Not the Full Picture

The most consistent finding across AI discovery engagements is that organizations have two to four times more AI running than they initially believed. That number holds across virtually every organization where a serious discovery exercise has been conducted.

One example makes the scale concrete. An organization came into a discovery engagement believing it had 7 agents running. After a few days of automated discovery, the actual count was over 2,500.

That is not a rounding error. That is a fundamentally different picture of risk, and it happens because the vast majority of enterprise AI never goes through a formal approval process. It lives on personal payment cards and expense accounts. It comes embedded in SaaS tools purchased for entirely different reasons. It gets built by developers as one-off utilities and then quietly accumulates permissions far beyond what the original task required.

Every one of those unknown agents is not just unregistered. It is operating without a security review. There are no compliance controls, no periodic audits, no accountable owner, and no record of what that agent has access to or what it was built to do. The gap between 7 and 2,500 is not an administrative inconvenience. It is a potential existential risk event waiting for the right conditions.

Why Your Existing Tools Will Not Find It

The most common response to this reality is to point to the security architecture already in place. CASBs, CMDB, asset management registers, periodic audits, network perimeter monitoring. Those are thoughtful, well-designed systems. They do the job they were built to do. The problem is that they were not built for the AI that matters most, which is the AI that bypassed the formal process entirely.

Network tools see what crosses the perimeter. They do not see thick client tools running locally on a laptop. They do not detect AI features embedded inside SaaS platforms, because the traffic patterns do not reveal the full picture. And they miss entirely any agents running inside the environment that generate no external network traffic. Anything that does not cross the network boundary is effectively invisible to those tools.

Periodic audits produce snapshots. The moment the snapshot is complete, it begins going stale. AI adoption does not pause for quarterly review cycles. New agents get deployed, models get updated, SaaS features get enabled, developers shift integrations. Every one of those changes adds new scope and new risk between the time you take the snapshot and the time someone reviews it.

Manual inventory, which in practice usually means a spreadsheet that gets updated when someone remembers, reflects what people choose to report, not what is actually running. Security might maintain one list. IT has another. Compliance keeps a third. Even when those teams communicate well, the combined picture can still miss a significant portion of the actual AI landscape.

The AI most likely to create real risk is precisely the AI that will not appear in any of those places, because it never went through the process that would have put it there.

What Gets Found When You Actually Look

The specific findings from real discovery engagements make the abstract risk concrete.

In one case, a security team discovered a CRM writing tool that had been running for six months. It was reading customer records, deal notes, and contract data, and sending that information to a third-party platform every time a sales representative used it. Nobody in IT or security knew it existed.

In the same engagement, they found a developer-built deployment agent with administrative-level credentials to production. It was built for one specific task and performed that task well. But over time, the service account it ran under had accumulated access to code repositories, configuration documents, and production infrastructure. None of that was formally registered anywhere.

They also found 12 SaaS platforms with AI features enabled by default, none of which were flagged during initial contract screening. All had been active for eight months. Most had document and email read access. None appeared in the inventory.

This is not unusual. The pattern repeats across organizations of every size and maturity level. The uncomfortable reality is that an incomplete inventory is not a preparation gap waiting to be filled. It is a live risk condition accumulating exposure every day it goes unaddressed.

The Real Cost of Not Knowing

Organizations that treat shadow AI as a theoretical future concern are understating the problem. The consequences are measurable and arriving now.

Regulatory pressure is the most immediate forcing function. The EU AI Act has set the expectation globally, but even without a direct regulatory mandate, frameworks like NIST AI RMF, ISO 42001, and SR 11-7 all require defensible, auditable AI inventories. Organizations that cannot produce one are already having uncomfortable conversations with auditors and board members, and those conversations will intensify.

Security incidents linked to ungoverned agents are real, and they carry costs in three directions at once: incident response, reputational damage, and regulatory exposure compounding on top of both. The organizations that build discovery infrastructure before a breach consistently come out better than those that scramble to piece together forensics after one.

And the compounding effect is significant. Every new SaaS feature enabled by default, every developer tool connecting to a new MCP server, every business unit adopting unapproved tooling adds to the risk portfolio. The gap between what you manage and what actually exists grows every single week until something actively closes it. The longer shadow AI goes unaddressed, the more forensic work is required to reconstruct what happened and determine disclosure obligations when something eventually surfaces.

What a Complete Inventory Actually Requires

A defensible AI inventory is not a list. It is a continuously maintained system of record that tells you what is running, who owns it, what it can access, and what it has been doing.

Coverage has to span the full surface area. That means cloud native development environments and application repositories. It means endpoint-level tools like local coding agents running on developer laptops. It means code repositories where models are being called inside production applications. It means MCP server connections that extend agent capabilities into sensitive data sources and external systems. And it means the SaaS layer, where AI features get enabled by contract update or product release, often without any signal reaching the teams responsible for governance.

Cadence has to be continuous. A snapshot that is accurate today and stale by next week is documentation, not governance. As soon as new AI is deployed, permissions change, or a new model gets connected, that information needs to surface immediately. The goal is a system that updates in real time and alerts when something new appears, not one that tells you what happened last quarter.

Context has to be rich. For every asset in the inventory, the record should include ownership, the full permission scope showing what data the agent can access, the use case it was built or adopted for, and the behavior history showing how it is actually being used across the organization. That context is what converts a list into something you can act on, and into something you can defend in front of a regulator.

The record has to be system-generated. Manual attestation goes stale as fast as the assessment that produced it. The audit trail that protects an organization is one that is immutable, continuously maintained, and not dependent on anyone remembering to update a spreadsheet.

An Emerging Challenge: Post-Merger AI Governance

One pattern surfacing more frequently is post-merger and acquisition AI governance. When an organization acquires another company, it potentially inherits an unknown volume of AI-related risk. Due diligence has historically included information security and data privacy components, but the post-AI acquisition environment now requires a comprehensive discovery pass across the inherited AI estate.

Some of what the acquiring organization finds will be familiar technology. Some will represent net new adoption requiring immediate assessment and governance. The organizations with continuous discovery infrastructure in place are substantially better positioned to absorb acquired assets without creating new governance gaps, and to give leadership a clear picture of what the organization just took on.

How Airia Approaches the Problem

Airia’s AI discovery integrates across the full technology stack to surface AI assets continuously, including the ones that bypassed every formal process. Within the first 48 hours of configuration, most deployments begin returning results. Within 30 days, organizations have a first-pass report that typically reveals a significantly larger AI estate than initially anticipated, and that gap report is often what creates the internal urgency to move governance forward at pace.

That inventory feeds directly into Airia’s platform for protection and governance. Once an asset is discovered, it becomes eligible immediately for policy attachment, permission review, and runtime security enforcement. The gap from discovery to active governance closes from weeks to hours.

Airia GOVERN generates compliance documentation aligned to EU AI Act, NIST AI RMF, ISO 42001, and other frameworks from the same enforcement record that security teams are already using. The record is system-generated, continuously maintained, and available on demand when a regulator or auditor asks for it.

Airia also includes AI cost control tools for monitoring token consumption and setting budgets at the user, team, and group level, which addresses one of the most consistent operational problems organizations face after expanding AI access without adequate spend visibility. Cost overruns are one of the fastest ways that executive leadership loses confidence in AI programs, and containing them is part of the governance story.

The full sequence runs from discovery to protection to governance to optimization, and each stage feeds the next rather than requiring separate systems with manual handoffs in between.

Four Questions to Ask Your Team This Week

Before the next governance meeting or budget conversation, run through these four questions with your team.

How do you actually track what AI is running right now? Not what was approved. Not what appears in a contract. What is running today, across every business unit, every developer workstation, and every SaaS platform in the environment?

Do your security and compliance teams agree on what that list contains? Fragmented inventories produce fragmented governance. Every decision downstream is only as reliable as the inventory it is built on.

If a regulator asked for your AI inventory today, what would you hand them? A spreadsheet? A description of your process? A system-generated record with full context on every asset? The answer to this question is a clear signal of where your governance program actually stands.

What AI did your development team build or connect in the last 90 days? Developer-introduced AI, including local agents, connected MCP servers, and LLM integrations inside production code, represents some of the highest-risk and least-visible AI in most organizations. Most teams cannot answer this question with confidence. They should be able to.

These questions are not comfortable. That is the point. The discomfort is the signal. AI governance is not a single department’s responsibility. It spans security, IT, compliance, and the business units themselves, and it starts with knowing what is actually running.

See how Airia can help you take control and govern your entire AI ecosystem today. Connect with a member of our team to get started.

Put these ideas to work.

Schedule a 30-minute walkthrough with our team.

Talk through your use case