AI inventory has moved beyond a list of sanctioned chatbots
A board asks, “How many AI systems are we using?” The operations team exports an approved-tool list. Security exports proxy traffic. IT exports installed software. Identity exports OAuth grants. Engineering exports API keys and MCP configurations. Every answer is internally correct, and none describes the same population.
Current products reflect that fragmentation. Netskope's beta Client AI Discovery periodically scans managed Windows and macOS endpoints for named AI agents, local models, MCP servers, browser extensions, and IDE extensions. Its documentation is unusually useful because it also names the blind spots: signature-only detection, active-user profiles, unmanaged environments, and agents or models inside separate virtual machines and containers.
Drata announced limited-availability AI Agent Governance on August 4 with device sensors, an MCP proxy, and a tamper-evident evidence feed, initially deepest for Anthropic environments. The announcement describes discovery, monitoring, policy simulation, action logging, and governance. Those are vendor claims for a limited-availability product, not independent proof of universal coverage. They still show where enterprise requirements are heading: inventory now includes non-human identity, tool calls, permissions, and evidence, not only a product name.
NIST AI RMF Govern 1.6 states that mechanisms should exist to inventory AI systems according to organizational risk priorities. The word mechanisms matters. A quarterly spreadsheet without feed lineage, owner recertification, exception aging, and closure evidence is not a reliable mechanism. Recent r/AI_Governance and r/Information_Security discussions make the pain concrete: practitioners can see fragments of activity but cannot give leadership a defensible exposure number.