The AI inventory nobody has
August 31, 2026
4 minute read
Every IT leader our team has talked to this year is getting some version of the same question from their CFO, CISO, or board and almost none of them can answer it. What AI are we actually running? Who owns it? What is it costing us?
IT is doing their due diligence, but it’s really about how AI got in.
Unlike the last wave of SaaS, this one didn’t come through procurement. Engineers spun up OpenAI projects on their own accounts, a PM tried Cursor over the weekend and expensed it, and someone gave an MCP server access to a repo six months ago and moved on. By the time governance made it onto the agenda, the environment was already scattered across a dozen providers and thousands of individually owned seats and keys.
A gut first reaction from most is that IT lost control of AI. We want to push on this assumption because you cannot lose control of something you never had a list of in the first place. Nobody built the list because the tools built for the last generation of the stack weren’t designed to see this generation of it.
Visibility is the actual problem worth solving.
The tools you already own only see slices
The natural first move is to reach for something already deployed. It rarely works because each category sees a slice.
SaaS management platforms see applications. They know the company pays for OpenAI, but they don’t know that there are 47 API keys against that account (6 of which haven’t been used in 90 days).
Finance tools see invoices. They know the number at the bottom of the bill. What they can’t tell you is context like which team is using it or the use case driving it.
Security tools see traffic and identity. They can flag an anomalous call, but they can’t hand you a list of every non-human actor running in your environment along with who’s accountable for each one.
Each of these categories is doing what it was built to do. None of them were built to be a ledger for AI. Without a ledger, the governance conversation always ends the same way: a spreadsheet, a Slack thread, and a promise to circle back next quarter.
You can’t govern what you can’t see
There’s a temptation when something feels out of control to skip ahead to the controls. It’s why most teams write a policy, turn on guardrails, or force new AI purchases through an approval flow.
That’s the wrong order.
A policy that says “all AI usage must be reviewed” means nothing if you don’t know what usage exists. An access control that says “revoke keys from departed employees” means nothing if you can’t produce the list of keys or who they belonged to.
Every mature governance discipline starts from an inventory that someone owns. The reason AI governance has felt impossible for the last two years is that the inventory never existed.
Discovery has to come first.
What that inventory needs to contain
The unit of inventory has to be the entity, not the app. API keys, projects, service accounts, MCP servers, cloud agents, AI assistants, developer seats. Those are what actually do work in the environment whereas an app level view papers over the sprawl that matters.
Teams currently try to stitch together a murky view of the AI in their environments by console hopping, but it falls short because it doesn’t live in one place.
The AI inventory needs an owner for every entity, usage details, cost, and entity specifics like creation date and last use.
What we built
This month we shipped the first phase of BetterCloud AI Governance and it’s built on exactly that idea. A single owned inventory of every AI entity in your environment with ownership, access, and cost context attached to each row.

One table lists API keys, MCP servers, service accounts, projects, cloud agents, and AI assistants across Cursor, Anthropic, and GitHub Copilot. Every entity opens into a provider specific drill down.
An OpenAI key surfaces its project, user, creation date, and last use.
A Cursor seat surfaces spend, request trend, lines added and accepted, most used model, and client version

In the AI tooling tab, total annual and monthly spend, provider count, active versus provisioned users, blended cost per user, and a twelve month trend line so you can answer finance’s burning question on one screen.
What’s next
Discovery is the opening pillar, but not the whole story. Support for AWS Bedrock, Microsoft Foundry, and Gemini Enterprise is coming soon and the pillars beyond discovery, like turning the inventory into active governance, is as well.
If you want to see it, request a walkthrough or read the full product update here.