Control over AI
Blog
AI governance 6 min read

Which AI systems are used in our organisation?

The Dutch DPA, NIST and the Dutch government's Algorithm Framework all start with the same question: which AI systems do you use? There are several ways to find out. Each one finds a different kind of AI, and no one-off count stays correct.

Abstract waves crossed by a dotted line
Quick answer

Start by separating three kinds of AI: systems you build or buy, AI features inside software you already have, and tools employees start on their own. For the first two, procurement, contracts, your application inventory and vendor release notes are the best sources. For the third kind those sources fail, because nobody requested the tools. A survey tells you why people pick a tool, but misses what they would rather not report. What does find the third kind is observation in the browser: which AI services get opened, continuously, without recording who.

01

The Dutch DPA, NIST and the Algorithm Framework all name the inventory as step one

02

There are three kinds of AI system, and each kind has a different source

03

Procurement and contracts find what the organisation chose itself

04

What employees start on their own only shows up where they work

05

An inventory becomes useful once each system has a decision next to it

A data protection officer reads the Dutch Data Protection Authority's guidance on AI literacy. Step one: map which AI systems you use. She opens the application inventory and finds Copilot, a contract management system with an AI summary, and the model customer service had built last year. Three lines. She knows there are more. She just does not know where to look.

The question sits at the front for a reason. In Aan de slag met AI-geletterdheid (January 2025), the Dutch DPA opens its cycle with identification: which AI systems do you use, who works with them, for what, and with which risks. NIST's AI Risk Management Framework says the same in GOVERN 1.6: mechanisms should be in place to inventory AI systems. And the Dutch government's Algorithm Framework opens its organisational measures with an overview of the algorithms you use (org-00).

Three frameworks from different directions, one starting point. The reason is plain. Without knowing which systems exist, you cannot decide who needs which training, which risk needs attention, or what belongs in the AI register.

Three kinds of AI, three kinds of source

The officer's inventory is not wrong. It was built from sources that can only find one kind of AI. A complete picture means keeping three kinds apart.

AI you build or deliberately buy. A forecasting model for planning, a chatbot on the website, a system that sorts applications. A decision came first, so there is a trail: a purchase order, a contract, a DPIA, a project plan.

AI inside software you already have. Your meeting tool has summarised calls since the last update, your CRM drafts emails, your PDF reader gained an assistant. Nobody made a new purchasing decision. The AI arrived with a version.

AI employees start on their own. A free ChatGPT account, a translation service, a note-taking tool, a browser extension with a writing assistant. Nobody requested it, so there is no trail in the paperwork. This is shadow AI, and in most organisations it is the longest list.

Six ways to find out

Go through procurement, contracts and data processing agreements. The best source for the first kind. What was bought on purpose is on paper somewhere. What is free, or paid for privately, is not.

Put the application inventory next to the release notes. For the second kind you have to check, vendor by vendor, which AI features were added in the past year and whether they are switched on. It is manual work, and it goes stale at the next update. Asking vendors directly, at contract renewal, helps.

Check IT administration and SSO logs. These show which tools run through the organisation's login. That is a good list of what you set up yourself, and so of the approved tools. Shadow AI by definition does not run through that login.

Check network and DNS logs. The proxy log shows chatgpt.com and a string of domains nobody recognises. But only for people in the office, and with no way to tell a free account from a business account on the same domain.

Ask employees. A round of questions per team or a short survey is the only source that tells you why people pick a tool, and what they miss in the one that is allowed. But people report what they are comfortable reporting. In the 2025 study by KPMG and the University of Melbourne, 57 percent of workers hide their AI use from their employer.

Observe where the work happens. Most AI use of the third kind runs through the browser, at the office and at home. Seeing which AI services get opened there also finds the tools nobody reported. The question is how much you record. For an inventory, the service's domain is enough; who opened it and what was on the page turns a count of tools into a record of people.

A longer comparison of these methods, and what each misses, is in how do you find out which AI tools employees actually use.

Why a one-off inventory falls short

The Dutch DPA calls its approach a cycle, and rightly so. Say the officer works through all six sources in October and counts 23 systems. By December the meeting tool has a new AI feature, the secretariat uses a transcription service that did not exist in October, and one tool has changed owner and with it its terms. The list of 23 is not wrong. It describes October.

For the first kind that is manageable: tie the inventory to procurement, and a new system is on the list before it is bought. For the third kind it does not work, because no decision comes first. There, the only way to keep the list current is to see continuously what gets opened. From shadow AI to a current AI register works this out further.

And a list on its own is not a policy. Only once each system has the organisation's position next to it does an employee know what is allowed, and does the officer know where the risk sits.

How it works with BeeSensible

BeeSensible covers the third kind, and the part of the second that becomes visible in the browser.

The extension notices when someone opens an AI tool, including one nobody ever requested. It records only the service's domain, at most once per day per device, with no user id, no path and no page content. This only happens when the organisation has switched on the AI module and the analytics setting.

Each observed domain is matched against a catalogue of 865 AI tools. For each tool it lists the vendor, the country, certifications, whether the tool trains on your data, whether a data processing agreement is available, an EU AI Act classification, documented incidents with a source, and a risk score across six dimensions. The officer does not have to research an unknown domain herself.

Search tool, vendor or categoryโ€ฆ
865 tools
ChatGPT๐Ÿ‡บ๐Ÿ‡ธ
HighAllowed
Claude๐Ÿ‡บ๐Ÿ‡ธ
MediumAllowed
DeepSeek๐Ÿ‡จ๐Ÿ‡ณnew
CriticalNot allowed
Perplexity๐Ÿ‡บ๐Ÿ‡ธnew
MediumNo decision yet
Mistral๐Ÿ‡ซ๐Ÿ‡ท
LowNo decision yet
Midjourney๐Ÿ‡บ๐Ÿ‡ธ
MediumNo decision yet

Every tool, scored for risk

865 AI tools, each scored Low to Critical, with nothing pre-approved or pre-blocked until someone decides.

More about AI Tools

A tool seen in the organisation for the first time lands in the Inbox: newly discovered AI tools awaiting a decision. Everything starts at "No decision yet". The organisation chooses: Allowed, Limited use with a condition it writes itself, or Not allowed. The risk score is advice, not a decision, and BeeSensible never sets a status on the organisation's behalf. Deciding does not have to mean restricting, either. Naming one tool as the route people can use is a decision too. Why four statuses rather than two is explained in four statuses for AI tools.

Systems of the first kind, like that customer service model, can be added to the catalogue as your own tool. They then sit in the same overview, with a status, and can serve as an approved alternative.

Once there is a decision, it appears at the moment someone opens the tool. For a tool that is not allowed, the approved alternative is the first button. Continuing is always possible. How people respond to those notices shows up afterwards in aggregate, and that feeds the next round: is the policy too tight, or is the alternative not good enough? What the AI tools module shows exactly is on the product page.

The officer from the first paragraph still needs her three lines. They come from procurement and contracts, and that is where they belong. What gets added is the list nobody requested, and it keeps itself up to date.

FAQ

Common questions

Why do I need to know which AI systems we use first?

Because everything else depends on it. You cannot build AI literacy for tools you do not know people use, you cannot assess the risk of a system that is not on your list, and an AI register starts from that same list. That is why the Dutch Data Protection Authority puts mapping your AI systems as the first step of its AI literacy action plan.

What counts as an AI system?

For a practical inventory, three kinds work well: AI the organisation builds or deliberately buys, AI features that appear in software you already use, and AI tools employees start online themselves. The AI Act has its own legal definition. For deciding what goes on your list, it is safer to start broad and assess afterwards.

Is an employee survey enough?

No. A survey tells you why people choose a tool and what they miss in the approved ones, and you need that. But people report what they are comfortable reporting. In the 2025 study by KPMG and the University of Melbourne, 57 percent of workers hide their AI use from their employer.

How often should I update the inventory?

For systems you buy or build: at every purchase, change or new version. For tools employees start themselves a fixed moment does not work, because tools appear in between. There, only continuous observation keeps the list current, so a new tool lands on it as soon as it is used.

Can I see which AI tools are used without tracking employees?

Yes. The inventory only needs to know that an AI service was opened in the organisation, which one, and how often. Who opened it, which page, and what was on it adds nothing to the question of whether a decision is needed. BeeSensible therefore records only the service's domain, at most once per day per device, with no user id and no page content.

Portrait of Rens Timmermans of BeeSensible

Would you rather someone showed you?

Rens, BeeSensible

I am happy to give you a twenty-minute tour. Leave your details and I will find a moment that suits you. Calling or emailing works just as well.

Rather talk to someone first? Book a call.

Want a live demo, or a quote for 100+ users? Leave your details and we'll be in touch within one business day.