Business IT projects · Across Québec Request a quoteFrançais

AI tool inventory

An AI tool inventory lists the artificial intelligence tools actually used in your business: public chatbots, AI features built into your software, browser extensions, transcription or image generation tools. For each one, it records who uses it, for what, with which account and which data.

Updated on

It is often the first step in AI governance: you cannot govern what you do not know about. In its publication on generative AI (ITSAP.00.041), the Canadian Centre for Cyber Security notes that users may unknowingly provide sensitive corporate data or personally identifiable information in their AI queries and prompts. The inventory helps spot these situations; the rules themselves belong in the AI usage policy.

Short answer

You describe your teams and the AI tools known or suspected: your request is reviewed by the Courtier TI team, then entrusted to the IT services company that will prepare your quote. The method and scope of the inventory are set with you.

What the quote should cover

  • The collection method: questionnaire, interviews, review of accounts and licences
  • Identification of AI features built into software already in place
  • One record per tool: uses, users, account type, data entered
  • Review of each tool's terms of use and settings
  • A ranking of tools by the risks identified
  • A report with recommended next steps: policy, training, vendors to assess
  • The method for keeping the inventory up to date

The steps of an AI tool inventory

  1. Scoping: teams covered, types of tools, confidentiality of answers
  2. Questionnaire or interviews with employees
  3. Review of accounts, licences and AI features enabled in your software
  4. One record per tool and review of its terms of use
  5. Ranking by risk and recommendations
  6. Presentation to management and next steps

What the inventory should record for each tool

  • The tool's name, vendor and version or plan used
  • The teams and tasks it is used for
  • The account type: personal or business account managed by your IT
  • The types of data entered: internal documents, client or employee information, code
  • What the vendor does with the data entered, including whether it is used to train its models
  • The settings available: opting out of training use, deleting prompt history
  • Where the data is hosted, when known
  • The person responsible for the tool in the company

The Government of Canada guide on the use of generative AI, written for federal institutions, recommends understanding how a system uses input data, for example whether it is used as training data and whether it is accessible to suppliers, and using the opt-out feature where possible. Both points are checked tool by tool.

Personal or business accounts

The account type changes a lot. A personal account is outside your settings, access controls and history, and often stays active after the employee leaves. The federal guide also asks public servants to use a work email address to register for AI tools, which helps ensure transparency and accountability.

The Centre's baseline cyber security controls also recommend removing accounts and functionality when employees no longer require them for their tasks (BC.12.3). The inventory tells you which AI accounts exist, so they can be closed or transferred when someone leaves.

Points of the Act to flag

The inventory does not replace a legal analysis, but it flags the tools that deserve a closer look under Quebec's Act respecting the protection of personal information in the private sector. A tool adopted to process personal information may be an information system acquisition project covered by section 3.3 and require a privacy impact assessment. If the information is communicated outside Québec, section 17 applies; if a vendor processes it for you, section 18.3 requires a written contract.

Also flag tools that analyze a person's work performance, preferences or behaviour: the Act classifies these uses as profiling (s. 8.1). And if a tool is used to make a decision based exclusively on automated processing, section 12.1 applies; the AI governance page details these obligations.

Finally, personal information entered into an unapproved tool may, depending on the circumstances, be a confidentiality incident, which includes communication of personal information not authorized by law (s. 3.6). The Incident response page describes what to do.

After the inventory

The inventory feeds directly into the AI usage policy: the list of approved tools, required account type, permitted data. It also guides employee training and identifies the vendors to assess more closely.

Tools and their features change quickly: software already in place may add an AI feature in an update. Plan to update the inventory at a set interval and whenever a new tool or feature appears.

Questions to ask yourself before requesting a quote

  • Which AI tools do you already know are used in the company?
  • Does your current software offer AI features, enabled or not?
  • Do employees use personal accounts for work?
  • What sensitive data circulates in your teams?
  • Do you already have an AI usage policy?
  • Who will receive the report and decide on next steps?

Pitfalls to avoid

  • Presenting the inventory as a hunt for culprits: employees then hide their uses
  • Forgetting AI features built into software already in use
  • Listing tools without recording the data entered
  • Ignoring personal accounts
  • An inventory done once and never updated
  • A report with no concrete next steps

What to specify in your request

  • The approximate number of employees and the teams covered
  • The AI tools known or suspected
  • The main software used in the company
  • The types of sensitive data you handle
  • Existing policies to take into account
  • The deliverables wanted: inventory, report, recommendations

You can then describe your project: the team will contact you to clarify your needs and provide a quote.

Frequently asked questions

What is shadow AI?

It refers to AI tools used at work without being approved or known to those responsible, often with personal accounts. The inventory is designed to find them, without a punitive approach, so they can be governed.

How do we find out which AI tools are used?

By combining several sources: a questionnaire or interviews with employees, a review of accounts and licences, and checking the AI features offered in software already in place. Answers are more candid when the exercise is presented as a status review.

What is the difference between the inventory and the AI usage policy?

The inventory describes the current situation: which tools, for what, with which data. The AI usage policy sets the rules going forward. The inventory often comes before the policy and later helps check that it is applied.

Should personal accounts be banned?

That is a decision for the policy. A business account lets you apply your settings and close access when an employee leaves. The Government of Canada guide also asks public servants to use a work email address to register for AI tools.

How often should the inventory be updated?

Set a frequency in the policy, and also update the inventory when a new tool arrives or when existing software adds an AI feature.

AI tool inventory

Usage policy, tool inventory and Law 25

Request a quote