How to build an enterprise AI inventory
Short answer
An enterprise AI inventory is a living list: approved, restricted, or blocked, with a named owner, the data classes allowed, whether the system can act, which identity it uses, and a review date. It is not a CMDB project and it is not a certificate. NIST CSF 2.0 Identify is the grouping language — voluntary, not a filing. Microsoft’s agent-adoption guidance tells you to inventory agents and tool integrations, including cross-tenant and guest paths, and to record effective permissions end-to-end.
You cannot least-privilege a tool you have not found. Discovery is overlapping methods, not one scan. How to run those methods is What is Shadow AI and how do you find it? This page is the list those methods fill. It sits under AI agent security for business (safeguard 2).
The Shadow AI Risk Assessment will not scan anything. In about four minutes it tells you which inventory questions you cannot yet answer. Then pull OAuth grants and interview two departments. Do not wait for a platform purchase.
What to put on each row
| Field | Why it exists |
|---|---|
| Name and vendor | The product people actually use, not the holding company. |
| Kind | Chatbot, embedded feature, coding assistant, or agent. Do not collapse them. |
| Status | Approved, restricted (data class or department), or blocked. |
| Owner | A named person. Empty owner = candidate to disable. |
| Account type | Company SSO versus personal account of the same product. They are different rows. |
| Data classes allowed | Mapped to the classification you already use. No parallel AI taxonomy. |
| Can it act? | Send, write, pay, delete — yes/no each. A chatbot that cannot act is not an agent. |
| Identity | Human user, shared login (should be none), or agent principal (Entra Agent ID or equivalent). |
| Tools / scopes | OAuth grants, MCP tools, Graph permissions, browser-extension IDs. |
| Review date / last used | An undated list is a wish list. Dormant agents expand the attack surface. |
Keep the list where the acceptable-use policy can point at it. Do not embed the whole inventory in the policy PDF.
How rows get onto the list
Seven methods, summarized here so this page can stand alone. Each misses a different slice; the Shadow AI article is the how-to.
- DNS, proxy, firewall — consumer chatbot domains and API endpoints. Misses personal phones and AI inside software you already allow.
- CASB or equivalent — unsanctioned SaaS, same unmanaged-device hole.
- OAuth grant review — meeting bots and inbox summarizers that never hit a blocked domain.
- Browser extensions — anything that can read the page.
- Expenses and cards — ChatGPT Plus, Claude Pro, notetaker seats on a department card.
- APIs, MCP, local agents — keys in vaults, MCP configs, Intune-visible local agents. Microsoft Shadow AI (Frontier) is one feed for the last of those on managed Windows.
- Department interviews — the tool that never touches your DNS.
First honest report is intake, not a gotcha. Punishment on first disclosure ends disclosure. Intake sequence is in the Shadow AI article.
Classify before you control
Microsoft’s agent-adoption language classifies agents by purpose, criticality and autonomy. At minimum, tag every row:
- Chatbot — returns text. Needs data class and identity. Does not need the full agent set unless it can act.
- Embedded feature — Copilot inside Word, a CRM suggest, Zoom AI. Often missed because “we don’t use AI.”
- Coding assistant — repo index is a data transfer.
- Agent — plans and calls tools. Needs identity, allowlist, HITL, logs, kill switch on the same row.
Dormant is a decision, not a status you ignore
Microsoft’s Cloud Adoption Framework says that without lifecycle controls, organizations accumulate unused agents that expand the attack surface (alongside shadow AI proliferation and budget overruns). Operational rule:
- If last-used is older than your review interval and nobody will claim the owner field, disable the identity, revoke tokens, and mark the row blocked or retired with a date.
- A paused agent with a live token is not paused. Microsoft’s kill-switch metric includes token invalidation. Same test here.
Cadence that a small team can keep
- Weekly: new OAuth grants and new DNS destinations that look like AI.
- Monthly: owner attestations on anything that can act.
- Quarterly: full pass against expenses, extensions, and two department interviews.
- On incident: add the tool to approved / restricted / blocked the same week, per the AI incident response plan.
This is not a US legal duty invented here. It is how you know what you approved. If you handle CUI, existing contract rules still follow that data into the tool. Completing an inventory does not make you CMMC Level 2 certified or FedRAMP authorized.
Frequently asked questions
Is an AI inventory a CMMC or FedRAMP certificate?
No. An inventory is a control artifact. Completing one does not make the organization CMMC Level 2 certified or FedRAMP authorized. NIST CSF 2.0 Identify is voluntary grouping language, not a filing.
What fields does the inventory need?
At minimum: name, owner, status (approved / restricted / blocked), data classes allowed, whether it can act (send / write / pay / delete), identity (human SSO vs agent principal), tools or OAuth scopes, last-used or review date. An undated list is a wish list.
Is Microsoft’s Shadow AI page the inventory?
No. It is one feed for unsanctioned local agents on Intune-managed Windows, Frontier preview and license-gated. It does not replace DNS, OAuth, expenses, MCP configs, or department interviews.
Should chatbots and agents share one row?
No. Classify by job: chatbot, embedded feature, coding assistant, agent. An agent that can act needs identity, allowlist and a kill switch on the same row. Collapsing them hides the write path.
What do we do with dormant agents?
Microsoft’s Cloud Adoption Framework names unused agents as an operational risk that expands the attack surface. If nobody will claim the owner field, disable the identity, revoke tokens, and mark the row blocked or retired with a date.
Where do we start if the list is empty?
Run the Shadow AI Assessment to see which questions you cannot answer, then pull OAuth grants and interview two departments. Do not wait for a CMDB project.
Does the acceptable-use policy embed the whole inventory?
No. Point the policy at a living list you can update without rewriting the PDF. That is the pattern in How to create a corporate AI acceptable use policy.
Is this a US legal duty?
This article does not invent one. Inventory is how you know what you approved. Contract and CUI rules you already have still follow the data into the tool. EU AI Act duties apply in the Union market, not automatically to every US employer.
Related articles
- AI agent security for business: 12 safeguards — the pillar; inventory is safeguard 2.
- What is Shadow AI and how do you find it? — the seven discovery methods.
- AI security checklist for businesses: 40 controls — discovery is controls 6–10.
- Shadow AI Risk Assessment — private first pass; not a scan.
References
- NIST CSWP 29 — CSF 2.0 (26 February 2024)— Identify. Voluntary framework, not a certification scheme.
- Microsoft Learn — Least privilege for AI agents— inventory agents and tool integrations; record effective permissions.
- Microsoft Learn — Manage AI agents across your organization— unused agents expanding the attack surface.
- Microsoft Learn — Shadow AI in the Microsoft 365 admin center— one feed, not a complete inventory.
Managed network and communications services, SDVOSB. An AI inventory is often a network-and-identity list wearing a new name. This is not a CMMC or FedRAMP certificate. Support: (888) 989-4872 · support@adampulse.us