Guide

How to inventory the AI tools in use across your organization

A step-by-step approach to building a continuous inventory of every AI assistant, agent, and LLM tool in use across the organization, spanning Microsoft Copilot and the non-Microsoft tools teams adopt alongside it.

Published For CISO, M365 Product Owner, CIO / CXO
Definition

An AI tool inventory is a complete, continuously updated catalog of the AI assistants, agents, and LLM tools in use across an organization, spanning Microsoft Copilot and the non-Microsoft tools teams adopt alongside it. For each tool or agent it records who owns it, what data it can reach, and the risk it carries. Without an inventory, AI governance is guesswork, because you cannot govern tools you cannot see.

The AI stack most organizations actually run is wider than Microsoft Copilot. Teams sign up for OpenAI, wire Gemini into a workflow, pilot Claude, and adopt coding assistants, often faster than IT hears about it. No native Microsoft tool inventories all of that.

That is the gap an AI tool inventory closes. Discovery across Microsoft and non-Microsoft vendors, one ownership model, and a risk view per tool. Everything else in AI governance, risk classification, access reviews, EU AI Act evidence, builds on knowing what exists. The steps below make that inventory continuous rather than a one-time survey.

Steps

  1. Connect your sources

    Connect Microsoft 365 and the non-Microsoft AI vendors your teams use so discovery draws on real signals rather than a survey. The goal is one place that sees across the whole AI stack, not one silo per vendor.

  2. Discover AI across Microsoft and beyond

    Inventory Microsoft Copilot, Copilot Studio agents, and Microsoft 365 agents, then extend to non-Microsoft tools such as OpenAI, Google Gemini, Anthropic Claude, Glean, and GitHub Copilot. One ownership model across vendors is what keeps oversight consistent.

  3. Capture owner and data reach

    For every tool and agent, record an accountable owner and what data it can reach or was grounded on. This is what turns a vendor list into an assessable governance inventory.

  4. Risk-classify each entry

    Score each AI system by the sensitivity of the data it touches and the breadth of what it can do, so review effort lands on the systems that could actually cause harm.

  5. Review on a cadence

    Re-run discovery on a schedule, because the AI stack changes monthly. New tools appear, agents are built, and an inventory that is not refreshed is out of date within a quarter.

Related connectors

Related reading

Trusted by

MAPALBAMVille de LuxembourgWACKERGRUNDFOSAMGENOsramLufthansaThyssenKruppSunrisePattern