Lesson 3 of 11 · Foundations · 3 min read

AI inventory and registers: knowing what AI you run

In brief

An AI register lists every model, agent and AI application in use, with an owner, a purpose and a risk level. Frameworks assume you have one. Credo AI and Holistic AI lead on discovery on our scores; Alice does not describe an inventory feature.

By The Charter Desk, Agentic Governance Compare · Published 2026-09-06 · Vendor pages read 6 September 2026 · Editorial assessment

Why does a register come first?

Every framework on this site starts from the assumption that you know which AI systems you have. The EU AI Act sorts obligations by the risk level of each system. ISO/IEC 42001 asks you to define the scope of your AI management system. The NIST AI RMF's Map function is about understanding each system's context. None of that works without a list.

In practice the list is the hardest part. AI arrives through product teams, through vendors adding AI features to tools you already use, and through developers calling models from code. A register built from a survey is out of date the week it is finished.

What does discovery software do?

Discovery tools build the list from systems rather than from surveys: cloud accounts, code repositories, model APIs and connected applications. Holistic AI says it discovers every model, agent and application, with connections to AWS, Azure and GitHub among others. Credo AI describes discovering AI across agents, models and apps and keeping an agent registry. Pillar Security, SPLX and Lasso each list a discovery or AI-BOM (AI bill of materials) module.

What should a register record?

  • The system: model, agent or application, and its version.
  • The owner: a named person and team.
  • The purpose: what it is for and who uses it.
  • The risk level: under the EU AI Act or your own scale.
  • The data: what it reads, stores and sends.
  • The controls: which policies apply and what enforces them.
  • The evidence: the latest test results and where the logs are.
  • The source: built in-house or supplied by a vendor.

What if your platform has no inventory?

Some platforms on this site start from the control rather than the register. Alice's WonderSuite pages describe testing, runtime guardrails and framework mapping for the apps it protects, but not discovery or an inventory of other AI. That is a real gap for a program whose first task is the register, and it is why Alice scores 2 of 10 here. A common pattern is to keep the register in a governance tool or a spreadsheet and link each entry to the control and evidence records that an enforcement platform produces. Whatever you use, make sure every entry in the register points to its controls and evidence, or the register is only a list.