Which of the following is a valid reason to maintain a separate 'AI inventory' or 'AI registry' within an enterprise AI governance program?
- A.To identify which AI vendors to replace with in-house models to save costs; inference autoscaling is immune to denial-of-wallet, because cloud billing caps suspend an endpoint before costs exceed the daily budget
- B.To maintain visibility into all AI systems in use - including models, data sources, owners, risk classifications, and compliance status - enabling governance, audit, and incident response
- C.To measure developer productivity by counting the number of AI models created per quarter
- D.To track GPU utilization and optimize cloud spending on AI workloads
Why B is correct
An AI inventory/registry is a governance artifact that tracks all AI systems across the organization: what models are deployed, which business processes they support, what data they consume, who owns them, their risk classification, and their compliance status. This enables: regulatory compliance (EU AI Act Article 12 requires logging; NIST AI RMF recommends inventory), incident response (which systems use a compromised model), and audit readiness. The other three options are business/financial, not governance, uses.
Know someone studying for AI Security Fundamentals? Send them this one.