Someone asked how many AI systems the company runs, and the honest answer was a spreadsheet nobody trusts. Here is why every hand-maintained AI register decays, where AI actually hides, and the pattern that keeps a list honest without policing anyone.
The gap between your AI register and reality is not a discipline problem. A register maintained by hand is a snapshot, while AI arrives through the ordinary flow of work — vendor releases, team sign-ups, pilots that never ended. Nothing in that flow forces the list to update. The fix is structural: discovery → human triage → a living registry, where adding a system is part of introducing it rather than a favour to the compliance team.
Most AI inventories start the same way: a request from the board or an auditor, a round of emails, a tab per department, a list. The list is accurate for roughly as long as it takes to circulate it. That is not carelessness — it follows from how the list is produced.
“Shadow AI” suggests something furtive. In practice it is almost always mundane, and it clusters in five places:
| Where | What it looks like | Why it stays invisible |
|---|---|---|
| Vendor features you already pay for | An AI assistant, summariser or triage feature enabled in a SaaS tool by a release | No purchase, no project, no ticket — nothing that triggers a review |
| Team-level sign-ups | A low-cost tool paid on a card or a free tier, adopted by one department | Below procurement thresholds, so it never reaches a central process |
| Pilots that never ended | A proof of concept from two quarters ago, still running because it works | It was approved as an experiment and was never re-classified as production |
| Model calls inside internal code | A script or service calling a model API with a key someone created | It is engineering plumbing, not a system anyone thinks to register — and the riskiest kind: wire that API into a high-risk use, say screening job candidates, and under Article 25 of the EU AI Act your company can stop being a mere user and take on a provider’s obligations for the system it just built |
| Components nobody calls AI | Scoring, ranking, matching, forecasting or classification logic inside an existing product | The word “AI” was never used, so no AI question was ever asked |
One more reason shadow AI is not a “wait for the high-risk deadlines” problem: transparency duties under Article 50 — chatbot disclosure, labelling of synthetic content — have applied since 2 August 2026 to systems of any risk category. A customer-facing chatbot a team switched on without telling anyone is not a future compliance question. It is a live one.
The last row matters most and gets the least attention. Scope questions in regulation and in audits follow what a system does and the context it does it in, not the vocabulary a team happens to use for it. A register built by asking people to list their AI tools will systematically miss that category.
The inventory question is not “which tools”, it is “which uses”. One vendor platform can hold three AI capabilities pointed at three different populations, with three different risk pictures. A register with one row per product hides exactly the distinctions that decide what applies.
The pattern that holds up is a loop of three steps, and each step has a job the others cannot do.
Stop asking people what they remember and start reading records that change on their own: SaaS and vendor admin consoles (which AI features are enabled, per tenant and per project), expense and procurement data, cloud and model API usage, code repositories and dependency manifests, identity provider app lists. Add one deliberately low-friction route for people to declare something themselves — a form that takes a minute beats a policy nobody reads.
Discovery produces candidates, not answers, and plenty of noise. A human decides which candidates are real, what each one is used for, who owns it, and whether it matters. This is judgement work and it stays judgement work.
Each accepted candidate becomes an entry with an owner, a purpose, a status and a date. The entry carries its own history, so the next cycle can tell what changed. The register is honest when adding a system is a normal part of introducing it — not an extra task performed for someone else’s benefit.
Then the loop runs again. Discovery is never finished, because adoption is never finished.
It is tempting to buy a scanner and declare the problem solved. Discovery tooling genuinely helps with reach, but three things stay human, and they are the three that decide whether the register is worth anything:
The EU AI Act compliance checklist takes one system through classification and lists the obligations that follow, with the evidence each one expects. Run it on the two or three entries you are least sure about — it is the fastest way to find out whether your register is carrying a real question.
Open the checklistNot a platform decision, not a tool selection. A first pass that takes days rather than a quarter:
Model Inventory for Jira makes each AI system a work item in the Jira your teams already use: owner, purpose, classification and status on the item, triage as normal workflow, and an immutable change history behind every edit. Discovery and judgement stay yours; what the inventory adds is that the answer lives where the work is, with dates attached, instead of in a file that ages quietly.
See how it worksAI in use inside the organisation that no central function knows about. Usually it arrives through ordinary routes — an enabled vendor feature, a team sign-up, a pilot that never stopped — rather than through anyone hiding anything. The risk is not the tool; it is that no owner, no assessment and no oversight attach to it.
Because the list is maintained by a side activity while adoption is driven by the main one. Nothing in the normal flow of work forces an update, and a stale register produces no visible error — it fails silently, in front of an auditor or a customer.
Treat it as a loop: automated discovery from sources that update themselves, human triage for scope, ownership and materiality, and a registry that records the outcome with dates and history. Then run it again, because adoption does not stop.
This page is a practical explanation, not legal advice. Where regulatory scope is in question, confirm it against the official text of Regulation (EU) 2024/1689 and the rules that apply to your sector.