Quick verdict
An AI inventory is a living register of every AI tool, model, API and AI-enabled feature in the organisation, including ones nobody procured. The National AI Centre register is the right idea. A Word or Excel template is a start. It is not enough once vendors ship AI inside products you already pay for, and staff open ChatGPT on a phone.
Build the register so each row can answer owner, data, personal information, destination, vendor, decision, approval, risk, controls, testing and the next review date. That is also the evidence you need for the 10 December 2026 automated-decision disclosures and for any 2027 standard that asks you to show your working.
Best for: Australian mid-market and enterprise teams that know AI is in the building and cannot list it. Honest limit: we will not find every personal ChatGPT chat. We will find the patterns, the paid seats, the vendor flags and the production APIs, and we will name an owner for each row.
Last updated: 31 August 2026.
What should an Australian AI inventory contain?
One row per system or distinct use, not one row per vendor brand. Microsoft 365 Copilot used to draft internal email is a different row from Copilot used to summarise a customer complaint that decides a refund. Same product, different data, different decision, different owner.
The field list we fill on a Power Day
| Field | Why it exists |
|---|---|
| Name and type | Tool, model, API, embedded SaaS feature, or shadow use |
| Business use | One sentence a board member understands |
| Owner / approver / risk lead | Three named people. “The AI committee” is not an owner |
| Status | Shadow / trial / approved / retired |
| Data in | Categories, not a data dictionary. Flag personal and sensitive information |
| Data out / destination | Vendor region, logs, training opt-in, retrieval store |
| Vendor and subprocessors | Contract, DPA, residency, last security pack |
| Decision | None / supports a human / makes or substantially supports a decision that can affect a person |
| Human override | Where, who, how it is logged |
| Risk tier | Your scale. We use four: content-only, internal ops, customer-facing, rights-affecting |
| Controls and tests | Access, retention, evals, red-team, last review date |
| Obligation flags | Privacy Act, Dec 2026 ADM, ACL, APRA, WHS, customer contract, VAISS guardrail |
NAIC’s template covers characteristics, use cases, accountable people and governance level. Keep those. Add data destination, decision, override and obligation flags or you will rebuild the sheet in November when counsel asks about APP 1.8.
Where shadow AI actually hides
Procurement sees Salesforce, ServiceNow, Workday, Microsoft, Google, AWS. It does not see the personal ChatGPT Plus card, the designer’s Midjourney, the intern’s Claude account, or the “AI meeting notes” Chrome extension. On Power Days we pull five sources in the first hour:
- SSO and IdP application lists
- Expense and credit-card merchants that look like AI products
- Browser extension and MDM inventories
- Engineering secret stores and model API keys (OpenAI, Anthropic, Google, Groq)
- Vendor release notes for products already in the stack — search for “AI”, “Copilot”, “assistant”, “summar”
Then we ask each function the same two questions: what do you paste into a model, and what do you let a vendor model write back into a system of record? The second question finds the CRM that now drafts the case note and files it as if a person wrote it.
Four risk tiers that stop the register becoming a junk drawer
| Tier | Example | Default control |
|---|---|---|
| Content-only | Image generation for a blog, no customer data | Acceptable-use + no personal information in the prompt |
| Internal ops | Copilot on internal mail; coding assistant on non-secret repos | Tenant controls, training-opt-out, repo allow-list |
| Customer-facing | Support draft replies, website chat, marketing personalisation | Human send, logging, evaluation set, consumer-law review |
| Rights-affecting | Hire, credit, insurance, hardship, access to a service | Full record, override, testing, Dec 2026 policy text, counsel |
Do not spend the same energy on Midjourney and a credit scorecard. The register’s job is to make that distinction visible.
Why the spreadsheet dies
A workshop produces 40 rows. Two vendor releases later, three rows are wrong and nobody owns the file. Guardrail 9 of the Voluntary AI Safety Standard is record-keeping. A record that cannot accept a change is not a record. The accountability layer we run on a Power Day is the same fields, with an owner and a change history, so a December privacy edit or a 2027 standard request does not start from a blank page.
Unique insight: the first inventory is always incomplete, and that is acceptable if the gaps are named. “Unknown — marketing, personal cards, review 15 October” is a better row than a false “we have no AI in marketing”.
FAQ
Is a National AI Centre Excel enough? For a five-person studio, sometimes. For a company with SSO, four departments and vendor AI features, you need owners and change history or the sheet is stale in a month.
Do we inventory tools staff use on their phones? Yes, as a pattern and a policy row. You will not capture every chat. You can ban personal accounts for work data and offer an approved tenant.
How does this help the December 2026 privacy rule? APP 1.8 needs kinds of personal information and kinds of decisions. Those fields are columns on the register. Detail: ADM privacy rule.
Can this be done in a day? A first living register, yes, if the owners attend. A finished privacy policy and a full ISO 42001 system, no. What the day produces: Power Day.
Related: Prove it · 2026–2027 timeline · Singapore · VAISS guide
