Every control in an enterprise AI governance program — access review, human oversight, incident response, audit — begins from a list of the systems it applies to. When that list is incomplete, the controls do not fail loudly; they simply never attach to the systems that are missing.
Regulators spent fifteen years teaching the inventory habit — then drew a line around it
On April 17, 2026, the Federal Reserve, the OCC, and the FDIC issued revised interagency guidance on model risk management, retiring SR 11-7 after fifteen years. The revision keeps the inventory principle intact: the guidance states that "an effective model inventory includes sufficient information to understand model risks, so as to support effective model risk management at the individual and aggregate levels." The inventory remains the aggregation point — the one artifact that lets a firm see model risk as a portfolio rather than a pile of exceptions.
But the revision also draws a boundary its predecessor never had to. Generative and agentic AI models, the agencies write, "are novel and rapidly evolving" and are not within the scope of the guidance. Sullivan & Cromwell's analysis notes that the revised guidance also narrows the definition of a model, relaxes third-party validation expectations, and states explicitly that non-compliance will not result in supervisory criticism.
Read those two moves together. The systems proliferating fastest inside enterprises — generative assistants, copilots, agents — now sit outside the one inventory discipline regulators spent a decade and a half enforcing. The agencies were direct about what fills the gap: the organization's own risk management and governance practices should determine the controls for anything out of scope. For banks, that means the model-risk inventory no longer covers what matters most by default. For everyone else, there was never even that scaffolding. Either way, the inventory question now belongs to you.
Obligations attach to systems, including the ones you have not listed
The regulatory duties arriving now are written per-system, not per-company. Under Article 26 of the EU AI Act, a deployer of a high-risk AI system must assign oversight to people with "the necessary competence, training and authority," monitor the system's operation, retain automatically generated logs for at least six months, and inform workers before the system is used on them. Every one of those duties presumes you know the system exists. A system missing from the register does not escape the obligation — it just guarantees the obligation goes unmet, and that you learn this from a regulator or an incident rather than from your own review cycle.
This is why NIST's AI Risk Management Framework puts the inventory in its Govern function rather than treating it as an operational nicety: "Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities." The accompanying playbook is more pointed — it recommends policies that inventory all models or systems where feasible, and that define the attributes each entry must carry: documentation, links to source code, incident response plans, and a named, reachable owner. An inventory without an accountable contact per row is a spreadsheet, not a control.
The uncounted systems are now showing up in breach economics
The cost of the gap has stopped being hypothetical. IBM's Cost of a Data Breach research found that 20% of studied organizations suffered a breach linked to shadow AI — unsanctioned tools operating outside any register — and that those incidents added as much as $670,000 to the average breach cost. Sixty-three percent of breached organizations had no AI governance policy at all, and 97% of organizations that suffered an AI-related breach reported lacking proper AI access controls. The 2026 edition of the same study, as Cybersecurity Dive reports, found the share of security incidents involving shadow AI more than doubled year over year.
Notice what kind of control failed in those numbers. Access control is an inventory-dependent control: you cannot restrict, log, or review access to a system you do not know is running. The same dependency holds for every other safeguard an enterprise program promises. Oversight rosters, log retention, incident playbooks, vendor reviews — each one is scoped by the inventory and silently voided by its gaps.
An inventory is not one governance control among many. It is the precondition that decides whether the rest of the program is real.
An inventory is not one governance control among many. It is the precondition that decides whether the rest of the program is real.
What a working inventory contains, and what it triggers
A working enterprise AI inventory has three properties that the failed ones lack. First, it registers capabilities, not procurement lines: the AI features switched on inside existing SaaS platforms belong in it alongside the models your teams built and the assistants your employees adopted on their own. Discovery has to be instrumented — SSO logs, network telemetry, expense data — because survey-driven inventories capture only what people remember to admit. Second, each entry carries the attributes that downstream controls consume: a named owner, business purpose, data categories touched, the underlying model and provider, risk tier, approval status, and review date. Third, entries persist through retirement — NIST's playbook recommends retaining decommissioned systems in the inventory for an established period, because the questions auditors and litigators ask are usually about what was running then, not what is running now.
The register earns its keep through what it triggers. Access reviews scoped to inventory rows. Log-retention checks run against every deployed system, not the remembered ones. An incident response plan that can name, within minutes, which systems touch the affected data. That is also what converts the inventory from cost to evidence: when a client, examiner, or acquirer asks what AI you run and how you control it, the answer is a query, not a scramble.
Enterprises rarely lack controls; they lack an accurate account of what the controls apply to. The regulators who invented the model inventory have told you their version no longer covers the AI that matters most — and the breach data shows what the uncounted systems cost. Build the register first, resource it like the control it is, and let every other governance mechanism key off it. Nothing else in the program works until this does.