AI inventories need models, prompts, tools and data
You cannot govern AI you cannot list, and a list of models is not enough.
The useful inventory covers which models are in use, what prompts are driving them, what tools they can call, what data they can reach and who owns each one. Most organisations do not have this, which is why shadow AI is so hard to talk about concretely. It is the same principle as asset inventory, and it is at the same early stage.
More on AI supply chain
- A model file is executable trust in another formIt looks like data until you open it
- Dataset provenance matters for security and governanceWhere did this batch come from?
- Model version changes can be security changesOne plate swapped inside
- Third-party AI APIs extend the data boundaryThe fence moves with the call
- Evaluation data can leak into trainingIt has already seen the exam
- Fine-tuning credentials are production credentialsThe bench feeds the floor
