When AI tools, models, or agents are missing from inventories, the institution cannot prove which services, vendors, and dependencies are in scope. That weakens third-party oversight, concentration-risk analysis, and incident response because compliance evidence is built on incomplete records. The practical failure is not just undocumented software, but ungoverned regulated exposure.
What breaks first when AI tools are missing from a DORA inventory?
The first failure is governance visibility. If a bank or other regulated firm cannot enumerate AI tools, models, agents, vendors, and supporting services, it cannot show what is actually in scope for oversight, testing, incident handling, and third-party risk controls. The gap is operational as well as compliance-oriented: unknown tools are also unknown dependencies.
Why incomplete inventory data undermines DORA control objectives
DORA expects firms to manage ICT risk from a known asset and dependency base. When AI tools are missing, the organisation loses the ability to classify whether a service is internal, outsourced, embedded in another platform, or materially dependent on a third party. That makes control coverage uneven, because the policy may exist while the actual AI estate remains partly invisible.
Inventory quality also affects concentration-risk analysis. If multiple business functions rely on the same model provider, hosted agent platform, or shared AI service, the firm needs that relationship mapped before it can judge whether a single outage, misconfiguration, or provider incident has systemic effect. Without that map, management may underestimate the blast radius of a vendor failure or of common-mode dependency.
For regulated firms, this is not a paperwork issue. Inventory is the evidence layer that links controls to real services, so if the inventory is wrong the assurance story is wrong as well. EU Digital Operational Resilience Act (DORA) requires ICT third-party risk management and incident handling discipline that depends on knowing what is in scope.
What becomes harder to detect, respond to, and prove
Incomplete inventories weaken incident response because responders do not know which AI tools can access which data, workflows, or external services. That slows containment, vendor contact, credential review, and impact assessment. It also creates blind spots for logging and control testing, because the team may be validating the wrong tools while the real exposure sits outside the register.
AI inventory gaps are especially dangerous when the tool can act, not just answer. An agent connected to email, code, CRM, or internal knowledge stores can create business impact even if no one intended to deploy it as a formal production system. NHIMG’s Shadow AI and AI Agent Discovery Guide is useful here because discovery is the prerequisite to assigning ownership and control.
When the missing item is a tool with real operational authority, the issue can move from undocumented software to uncontrolled action. That is why regulated organisations should treat an incomplete AI inventory as a control failure, not merely a discovery backlog.
Why AI inventory gaps turn into regulated exposure
The practical consequence is that oversight breaks at the point where evidence should connect asset, provider, and control. If the firm cannot tie an AI tool to a business owner, a vendor, a risk classification, and an incident path, then it cannot credibly argue that the service is governed under the DORA operating model.
That is why inventory work needs to capture not only visible applications but also embedded assistants, model endpoints, agent frameworks, plug-ins, and delegated access paths. NHIMG’s Identity Security Regulatory Map is a practical reference for seeing how control obligations cross regulatory lines once identity-bearing access and vendor oversight are in play. In financial services, Financial Services Identity Security Guide helps frame why third-party access and regulated dependencies must be documented before they can be controlled.
Risk and Threat Considerations
Uninventoried AI tools create a hidden attack surface. If an unmanaged model or agent has access to data, APIs, or user workflows, defenders may miss both the path into the environment and the path out of it, which makes abuse harder to spot and harder to contain.
Failure mechanism: Unknown AI services can bypass normal governance gates, so third-party exposure, privileged access, and dependency concentration are not reviewed until after an incident or audit challenge exposes the gap.
Impact: The organisation faces weaker incident triage, incomplete vendor oversight, and higher likelihood that regulated exposure is discovered too late to contain efficiently.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
DORA provides the primary governance reference for this topic.
| Framework | Control / Reference | Relevance |
|---|---|---|
| DORA | GV.SC-01 — Supply Chain Risk Management Strategy | AI tools and vendors must be inventoried to manage ICT third-party exposure. |
| GV.RM-01 — Risk Management Strategy | Missing AI assets break the risk picture needed for DORA governance decisions. | |
| RC.RP-01 — Recovery Planning | Unknown AI dependencies slow incident response and recovery scoping. | |
| Recommendation — Inventory AI services and third parties before assigning oversight and resilience controls. Include unmanaged AI services in the operational risk register and assurance cycle. Map AI dependencies so incident recovery can target the right services quickly. | ||
Practitioner Guidance
What to prioritise: Start by reconciling the AI tool register against procurement, SSO, cloud, endpoint, and API data so you can distinguish sanctioned production use from shadow adoption. The useful question is not whether the tool is approved in principle, but whether it can influence regulated workflows or hold dependency on a third party.
What to verify: For each AI entry, verify owner, vendor, data touchpoints, access paths, and whether the tool can execute actions or only generate output. If any of those fields are missing, treat the record as control incomplete, not merely metadata incomplete.
Practitioner takeaway: In a DORA context, an incomplete AI inventory is a control-gap signal, because you cannot govern, assess concentration, or respond reliably to what you have not formally brought into scope.
Related resources from NHI Mgmt Group
- What breaks when AI tools can store and reuse credentials outside approved channels?
- What breaks when AI tools are used outside official channels?
- What breaks when teams allow employees to use public AI tools outside a controlled gateway?
- What breaks when AI tools are used outside the approved registry?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org