Inventory discovery should come first because you cannot govern what you cannot see. A policy without a reliable picture of which AI tools are in use will miss shadow AI, unmanaged access paths, and the endpoints that need enforcement most.
Why discovery should precede policy in AI governance
Inventory discovery is the control that makes policy enforceable. If you do not know which AI tools, agents, plugins, or embedded features are already in use, policy writing becomes abstract: you can define approval paths and usage rules, but you cannot target the real estate where those rules need to land.
That matters because the highest-risk exposure is often outside the official stack. Shadow AI appears first in browser extensions, SaaS add-ons, employee-approved trials, and workflow automations, so discovery has to identify the actual tool surface before governance can be meaningfully applied. Shadow AI and AI Agent Discovery Guide shows why the inventory step is the practical starting point.
Policy is still necessary, but it becomes durable only after the organisation knows what it is governing. A policy written too early tends to overgeneralise, miss unmanaged access paths, and leave gaps between formal rules and real usage patterns.
What a reliable AI inventory actually gives you
A useful inventory is not just a list of approved products. It should reveal where AI is embedded, who owns it, which users or teams can invoke it, what data it touches, and whether it has third-party connections, API access, or autonomous actions that need review.
That makes discovery a visibility and enforcement problem, not a cataloguing exercise. The inventory becomes the basis for scoping controls, identifying exceptions, and deciding which uses need stricter approval, logging, or human oversight. NHIMG’s NHI Lifecycle Management Guide is a useful parallel for the lifecycle logic behind inventory, ownership, rotation, and offboarding.
For organisations with multiple AI entry points, the inventory should distinguish sanctioned tools from unsanctioned ones and map each instance to an owner and an enforcement path. That is the difference between a policy document and an operational control plane. For a deeper look at how unmanaged AI gets found in practice, see Shadow AI and AI Agent Discovery Guide.
How to sequence policy after discovery
Once the inventory is credible, policy writing becomes specific instead of theoretical. You can write around actual usage patterns, set approval tiers by risk, define which datasets are off limits, decide which tools require registration, and state which use cases need logging or review before production use.
The right sequence is: discover first, classify second, then write policy around the discovered population. That sequence reduces rework because policy controls are built to fit known systems instead of being retrofitted after an audit or incident reveals a gap.
In practice, the first policy artefacts should address ownership, approved use, escalation, and retirement criteria. A good policy does not try to enumerate every future AI capability; it creates decision rules that can be applied to newly discovered tools as the inventory grows.
Risk and Threat Considerations
When policy comes before inventory, organisations often end up governing the wrong things. Shadow AI can keep operating outside approval workflows, unmanaged integrations can retain access longer than intended, and security teams may believe a control exists when they have not yet found the systems it must constrain.
Failure mechanism: The organisation writes rules without a complete map of deployed tools, so enforcement, monitoring, and exception handling never attach to the actual AI surface.
Impact: Unseen AI usage can create data exposure, unsanctioned access, unreviewed third-party dependencies, and false confidence in governance coverage.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 addresses the attack surface, CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-1 — Inventory and Control of Enterprise Assets | Discovery must identify AI tools before governance can be enforced. |
| Recommendation — Inventory all AI-facing assets before drafting usage policy. | ||
| NIST CSF 2.0 | ID.AM-01 — Identities and assets are inventoried | AI governance here depends on knowing what tools and access paths exist. |
| Recommendation — Create and maintain a current inventory of AI tools and access paths. | ||
| ISO/IEC 27001:2022 | A.5.9 — Inventory of information and other associated assets | Policy depends on knowing the assets and tools already in use. |
| Recommendation — Maintain an inventory of AI tools as an ISMS prerequisite. | ||
| NIST SP 800-53 Rev 5 | CM-8 — System Component Inventory | A complete component inventory is needed before control policy can be applied. |
| Recommendation — Maintain an authoritative inventory of AI-related components and services. | ||
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | Discovered agents need governance where identity and authority are in scope. |
| Recommendation — Register agent identities and constrain their privileges before rollout. | ||
Practitioner Guidance
What to prioritise: Start with high-signal discovery sources such as browser activity, SaaS OAuth grants, API key inventories, endpoint telemetry, and procurement or app-approval records. If the tool can move data or act on behalf of users, it belongs in scope before policy drafting is treated as complete.
What to verify: Confirm that each discovered AI tool has an owner, a business purpose, and a clear enforcement path. If you cannot point to who approves it, who monitors it, and who can retire it, the inventory is not yet actionable.
Practitioner takeaway: Discovery is not a preliminary housekeeping step, it is the control that makes AI policy real; policy written before visibility usually documents intent, not enforcement.
Related resources from NHI Mgmt Group
- Should security teams prioritise shadow AI discovery or policy writing first?
- Should organisations prioritise external exposure or internal credential governance first?
- Should organisations prioritise discovery or access restriction first for shadow AI?
- What should organisations prioritise first: classification, DLP, or AI policy?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org