Back to Blog

How to Build an AI Inventory When Staff Already Use ChatGPT

The National AI Centre wants a register. Procurement will not see half of it. Here are the fields we actually fill on a Power Day.

How to Build an AI Inventory When Staff Already Use ChatGPT

Quick verdict

An AI inventory is a living register of every AI tool, model, API and AI-enabled feature in the organisation, including ones nobody procured. The National AI Centre register is the right idea. A Word or Excel template is a start. It is not enough once vendors ship AI inside products you already pay for, and staff open ChatGPT on a phone.

Build the register so each row can answer owner, data, personal information, destination, vendor, decision, approval, risk, controls, testing and the next review date. That is also the evidence you need for the 10 December 2026 automated-decision disclosures and for any 2027 standard that asks you to show your working.

Best for: Australian mid-market and enterprise teams that know AI is in the building and cannot list it. Honest limit: we will not find every personal ChatGPT chat. We will find the patterns, the paid seats, the vendor flags and the production APIs, and we will name an owner for each row.

Last updated: 31 August 2026.


What should an Australian AI inventory contain?

One row per system or distinct use, not one row per vendor brand. Microsoft 365 Copilot used to draft internal email is a different row from Copilot used to summarise a customer complaint that decides a refund. Same product, different data, different decision, different owner.


The field list we fill on a Power Day

Field Why it exists
Name and type Tool, model, API, embedded SaaS feature, or shadow use
Business use One sentence a board member understands
Owner / approver / risk lead Three named people. “The AI committee” is not an owner
Status Shadow / trial / approved / retired
Data in Categories, not a data dictionary. Flag personal and sensitive information
Data out / destination Vendor region, logs, training opt-in, retrieval store
Vendor and subprocessors Contract, DPA, residency, last security pack
Decision None / supports a human / makes or substantially supports a decision that can affect a person
Human override Where, who, how it is logged
Risk tier Your scale. We use four: content-only, internal ops, customer-facing, rights-affecting
Controls and tests Access, retention, evals, red-team, last review date
Obligation flags Privacy Act, Dec 2026 ADM, ACL, APRA, WHS, customer contract, VAISS guardrail

NAIC’s template covers characteristics, use cases, accountable people and governance level. Keep those. Add data destination, decision, override and obligation flags or you will rebuild the sheet in November when counsel asks about APP 1.8.


Where shadow AI actually hides

Procurement sees Salesforce, ServiceNow, Workday, Microsoft, Google, AWS. It does not see the personal ChatGPT Plus card, the designer’s Midjourney, the intern’s Claude account, or the “AI meeting notes” Chrome extension. On Power Days we pull five sources in the first hour:

  1. SSO and IdP application lists
  2. Expense and credit-card merchants that look like AI products
  3. Browser extension and MDM inventories
  4. Engineering secret stores and model API keys (OpenAI, Anthropic, Google, Groq)
  5. Vendor release notes for products already in the stack — search for “AI”, “Copilot”, “assistant”, “summar”

Then we ask each function the same two questions: what do you paste into a model, and what do you let a vendor model write back into a system of record? The second question finds the CRM that now drafts the case note and files it as if a person wrote it.


Four risk tiers that stop the register becoming a junk drawer

Tier Example Default control
Content-only Image generation for a blog, no customer data Acceptable-use + no personal information in the prompt
Internal ops Copilot on internal mail; coding assistant on non-secret repos Tenant controls, training-opt-out, repo allow-list
Customer-facing Support draft replies, website chat, marketing personalisation Human send, logging, evaluation set, consumer-law review
Rights-affecting Hire, credit, insurance, hardship, access to a service Full record, override, testing, Dec 2026 policy text, counsel

Do not spend the same energy on Midjourney and a credit scorecard. The register’s job is to make that distinction visible.


Why the spreadsheet dies

A workshop produces 40 rows. Two vendor releases later, three rows are wrong and nobody owns the file. Guardrail 9 of the Voluntary AI Safety Standard is record-keeping. A record that cannot accept a change is not a record. The accountability layer we run on a Power Day is the same fields, with an owner and a change history, so a December privacy edit or a 2027 standard request does not start from a blank page.

Unique insight: the first inventory is always incomplete, and that is acceptable if the gaps are named. “Unknown — marketing, personal cards, review 15 October” is a better row than a false “we have no AI in marketing”.

FAQ

Is a National AI Centre Excel enough? For a five-person studio, sometimes. For a company with SSO, four departments and vendor AI features, you need owners and change history or the sheet is stale in a month.

Do we inventory tools staff use on their phones? Yes, as a pattern and a policy row. You will not capture every chat. You can ban personal accounts for work data and offer an approved tenant.

How does this help the December 2026 privacy rule? APP 1.8 needs kinds of personal information and kinds of decisions. Those fields are columns on the register. Detail: ADM privacy rule.

Can this be done in a day? A first living register, yes, if the owners attend. A finished privacy policy and a full ISO 42001 system, no. What the day produces: Power Day.


Related: Prove it · 2026–2027 timeline · Singapore · VAISS guide

Share this article

Share:

Using AI without an evidence trail?

Power Hour onboarding, then a Power Day: inventory, owners, data flows, and a living record. We build the evidence layer — we do not certify you.