
Blog Post
What an AI Usage Inventory Cannot Tell You
September 10, 2026
Three reads from surfaces most organizations already own produce a usable AI usage register in a morning. Entitlement, from the identity provider, showing who is licensed for what. Activity, from network or gateway logs, showing who reached which destination and how much. Identity, from the directory, showing who those people are and which scopes they sit in.
The register answers more questions than people expect. It also has a fourth column with no source in that set, and the difference between an empty column and a zero is where programs get themselves into trouble.
What Can Three Columns Answer?
A surprising amount, and it is worth being specific because the register gets undersold as a starting point when it settles several questions outright.
Whether a tool is in use at all, by how many people, in which functions and whether that is growing. Whether people are using the licensed tier or reaching the same vendor by another route. Which licenses nobody touches, which is both a cost finding and a decommissioning candidate. Which identities in regulated scopes reach AI tools at all, which narrows every subsequent assessment. Finally, which destinations account for most volume, so effort goes where the traffic is.
Which Makes It Worth Shipping Immediately
Those answers are available in days rather than quarters and they support real decisions. A program waiting for a complete register before producing anything has chosen to answer nothing for six months, and building the inventory is the step where most programs stall rather than the step where they finish.
What Is the Fourth Column?
What was sent. Not which tool, not by whom, not how much, but the content of the interaction, which is the one attribute none of the three sources can supply.

The identity provider records an entitlement rather than a session. Network logs record a volume inside an encrypted tunnel. The directory records a person. None of them can read the content, and this is a property of where they sit rather than a limitation somebody could configure away.
Why Does That Column Matter More Than the Others?
Because it is the one the obligations ask about. Whether regulated data was sent, whether an output influenced a decision about a person, whether a use case falls into a high-risk category, whether human review occurred. Every one of those is a content or context question, and the three-column register is silent on all of them.
What Is the Difference Between Empty and Zero?
The distinction that decides whether the register helps or misleads. A blank column reads as an absence of findings rather than an absence of measurement.
A register showing no sensitive data exposure looks like a good result. Where the column was never populated, the correct reading is that nothing was measured, and those two states are visually identical in a spreadsheet. Somebody presenting that register upward will be understood to be reporting the first, and the misunderstanding is entirely predictable.
How Do You Prevent That?
Label the column rather than leaving it blank. An entry stating not measured, with a note naming which source would be required, is a materially different artifact from a blank cell in a table. It also converts the shortfall into a roadmap item somebody can fund, since a named missing source is a purchase decision and an unlabeled blank is nothing.
What Would Fill It?
Three sources, each partial, and the choice between them is a coverage decision rather than a product preference.

An agent inside the browser reads the interaction as it happens and covers managed browsers only. The tool's own compliance interface returns governed conversations and knows nothing about sessions outside the corporate tenant. A gateway performing decryption reads the traffic and misses anything bypassing corporate egress or running locally.
Which Should You Choose?
Whichever matches where your usage happens, which is a question about your environment rather than about the products. In an estate with high device management and most traffic through corporate egress, a gateway covers a lot. In one with substantial unmanaged device use, it covers less than the demonstration suggested, and an AI Interaction Data Fabric joins whichever sources are available rather than depending on any one being complete.
What Else Is Missing Besides Content?
Two attributes that are neither content nor activity, and both catch programs out.
Which account a session ran under, meaning whether somebody used the corporate workspace or a personal one on the same domain. The three-column register shows a licensed user reaching a licensed tool and cannot tell you which of those two happened, which tracking use across business units covers in detail.
The second is what the tool does with input at that tier, which comes from the vendor rather than from your environment. Whether it trains on submissions, how long it retains them and whether an enterprise agreement is in place are properties of the contract and the tier, and they change the meaning of every row in the activity column.
Does This Register Satisfy Any Obligation?
Partly, and being precise about which part is what makes it defensible rather than optimistic.
Requirements to maintain an inventory of AI systems are substantially addressed, since the register names the systems and who uses them. Requirements to classify systems by risk are not, because classification depends on the use case rather than the tool. Requirements to demonstrate human oversight, retain interaction logs or evidence data controls are not, since all three concern the interaction. A register presented as inventory evidence is accurate. Presented as compliance evidence it overstates, and producing evidence on somebody else's timeline is when the difference becomes visible.
What Is the Honest Position to Take?
Stating that the organization knows which AI tools are in use, by whom and at what volume, and does not currently measure what is being sent to them. Said deliberately with the reason attached, the position is defensible. Discovered by an examiner reading a register with a blank column, it is considerably less so.
How Long Do the Three Columns Stay Accurate?
Not long, and the decay rates differ enough that treating the register as a single artifact with one refresh cycle guarantees part of it is stale.
Entitlement changes when licenses are assigned or removed, which happens continuously in a growing organization and is the column most likely to be quietly wrong. Activity changes daily and is the reason a register built once describes a week rather than a state. Identity changes with joiners, leavers and role moves, and a leaver still holding an AI license is both a cost item and an access finding.
Which Argues Against a Quarterly Refresh
All three columns come from systems that are already running, so the register can be derived continuously rather than assembled periodically. A quarterly exercise produces a document, and a continuous derivation produces a current answer. The work of building it once is the same either way, which makes the periodic version the more expensive choice over a year.
What Should Trigger a Closer Look?
A new destination appearing against a known identity, a volume moving well outside that person's own history, and a license active for somebody who has left. All three are computable from the three columns alone, without the content source, which makes them the highest-value alerts available before anything else is acquired. A register that expires behaves the same way any other point-in-time assessment does.
What Should You Do With the Ceiling?
Treat it as the plan rather than as a disappointment, which is the practical reframe.
Build the three columns, use them for the questions they answer, and label the fourth as unmeasured with the source that would fill it named. Then decide whether that source is worth acquiring based on which obligations apply to you, since an organization with no regulated data and no consequential decisions may reasonably stop at three columns. One with either has a specific and costable next step rather than a vague sense of being incomplete.
Which Order Should the Columns Come In?
Identity first, because it narrows everything else. Knowing which people sit in regulated scopes turns a whole-estate problem into a subset, and the activity column is far more informative when read against that subset than across everyone. An AI data fabric maintains all four continuously once established, and the first three are available before any of that exists.
Label the Column You Cannot Fill
Three reads from existing systems produce a register that answers whether a tool is used, by how many people, in which functions and at what volume, which supports real decisions within days. The fourth column, what was sent, has no source among them, because entitlement records, encrypted volume and directory state cannot see content by construction. The fourth column is the one the obligations ask about, so the register is operationally useful and compliance-incomplete at the same time. Leaving it blank invites it to be read as zero. Kovrr's AI Security and Governance Platform builds the first three from telemetry and joins whichever content source your environment can supply.
To see an AI usage register assembled from your own systems, with the unmeasured columns named, book a demo mapped to your own estate.
AI Usage Inventory FAQs
Speak to an ExpertWhat can a three-column AI usage register answer?
More than it gets credit for. Whether a tool is in use at all, by how many people, in which functions and whether that is growing. Whether people are using the licensed tier or reaching the same vendor another way. Which licenses nobody touches, which is both a cost finding and a decommissioning candidate. Which identities in regulated scopes reach AI tools at all, narrowing every later assessment. And which destinations account for most volume, so effort goes where the traffic is.
What is the fourth column and why is it empty?
What was sent. Not which tool, not by whom, not how much, but the content of the interaction, which none of the three sources can supply. The identity provider records an entitlement rather than a session, network logs record a volume inside an encrypted tunnel, and the directory records a person. All of that is a property of where those sources sit rather than a limitation somebody could configure away, so the column stays empty regardless of how well the first three are built.
Why does the difference between empty and zero matter?
Because a blank column reads as an absence of findings rather than an absence of measurement, and those two states look identical in a spreadsheet. A register showing no sensitive data exposure looks like a good result, while the correct reading where the column was never populated is that nothing was measured. Anyone presenting that register upward will be understood to be reporting the first. Labeling the column as not measured, with the source that would fill it named, prevents the misreading.
What would fill the content column?
Three sources, each partial. An agent inside the browser reads the interaction as it happens and covers managed browsers only. The tool's own compliance interface returns governed conversations and knows nothing about sessions outside the corporate tenant. A gateway performing decryption reads traffic and misses anything bypassing corporate egress or running locally. Which to choose is a question about where your usage happens rather than about the products.
Does a usage register satisfy compliance obligations?
Partly. Requirements to maintain an inventory of AI systems are substantially addressed, since the register names the systems and who uses them. Requirements to classify systems by risk are not, because classification depends on the use case rather than the tool. Requirements to demonstrate human oversight, retain interaction logs or evidence data controls are not, since all three concern the interaction. Presented as inventory evidence it is accurate, and presented as compliance evidence it overstates.
What is missing besides content?
Two attributes that are neither content nor activity. Which account a session ran under, meaning whether somebody used the corporate workspace or a personal one on the same domain, since the register shows a licensed user reaching a licensed tool and cannot distinguish those. The second is what the tool does with input at that tier, which comes from the vendor rather than your environment, covering whether it trains on submissions, how long it retains them and whether an enterprise agreement is in place.




