Evidence note: This is original SOS analysis. Named reports, recommendations and vendor announcements are treated as evidence of market direction, not as proof of enacted law or universal performance.

Many organisations know that they are using AI.

Why “we use AI” is no longer an adequate inventory

This analysis forms part of the same operational picture as UK Parliament’s AI Debate Is Moving Towards Lifecycle Accountability and Sovereign AI Is Becoming an Enterprise Procurement Issue.

Far fewer can immediately answer exactly which AI.

That distinction is becoming important.

AI systems can incorporate foundation models, third-party APIs, embedded assistants, open-weight components and specialist agents from multiple suppliers.

Each introduces different questions around provenance, data handling, jurisdiction, security, licensing and supply-chain dependency.

A credible AI inventory therefore needs to go beyond “we use generative AI.”

The provenance record organisations need

It should establish:

model → provider → version → deployment environment → data access → permissions → owner → risk status.

This becomes particularly important in government, healthcare, finance and critical infrastructure.

Procurement teams may need to understand not only whether an application performs well, but what technology actually sits underneath it.

Model provenance is also essential when something changes.

Managing model and supplier change

If a provider updates a model, does the organisation know which workflows are affected?

If a vulnerability is discovered, can impacted systems be identified quickly?

If a supplier becomes unsuitable, can access be revoked or the model replaced?

These are supply-chain governance questions as much as AI questions.

As enterprise AI ecosystems become more complex, organisations need to know exactly what is operating inside them.

You cannot meaningfully assure technology you cannot identify.

Related SOS analysis: See model provenance as supervisory evidence.

SOS perspective

This issue sits within our work on AI governance and assurance: practical systems should preserve evidence, human accountability and proportionate control while delivering useful automation.

Apply this analysis to a practical, accountable AI decision.

Discuss AI model provenance with SOS