Which of the following is a valid reason to maintain a separate 'AI inventory' or 'AI registry' within an enterprise AI governance program?
- A.B. To maintain visibility into all AI systems in use - including models, data sources, owners, risk classifications, and compliance status - enabling governance, audit, and incident response
- B.A. To track GPU utilization and optimize cloud spending on AI workloads
- C.C. To measure developer productivity by counting the number of AI models created per quarter
- D.D. To identify which AI vendors to replace with in-house models to save costs
Why A is correct
An AI inventory/registry is a governance artifact that tracks all AI systems across the organization: what models are deployed, which business processes they support, what data they consume, who owns them, their risk classification, and their compliance status. This enables: regulatory compliance (EU AI Act Article 12 requires logging; NIST AI RMF recommends inventory), incident response (which systems use a compromised model), and audit readiness. Options A, C, and D are business/financial, not governance, uses.
Know someone studying for AI Security Fundamentals? Send them this one.