The AI Exposure Register | Free AI Inventory Template | The Product Unicorn

The AI Exposure Register

Every AI tool and AI-built system running in your business, who approved it, what data it touches, and who reviews the output. One page you fill in yourself, in about 20 minutes. The rows you cannot complete are the finding.

No sign-up. The spreadsheet has dropdowns and a how-to sheet. The PDF prints on one page.

The old constraint on shadow IT was difficulty. Building took a year and a budget cycle, so the approved path was the only path. AI removed that constraint. When building is cheaper and faster than waiting, unapproved systems appear wherever a manual process hurts, and most organizations cannot produce a list of them.

The register is the first exercise we run in an AI assessment. It is not a policy document. It is one page that shows you, in your own numbers, how much of your AI footprint nobody approved, nobody reviews, and nobody owns.

The AI Exposure Register

Every AI system running in your business, on one page. Three example rows show the level of detail. Delete them once you have real ones.

AI tool or systemWhere it is usedWho approved itWhat data it touchesPersonal or company accountBAA or DPA on fileWho reviews the outputWhat happens if it is wrong
Zendesk AI triageSupport, ticket routingJ. Alvarez, VP Customer ExperienceCustomer tickets, contact detailsCompanyYesCX ops lead, weekly sample reviewMisrouted tickets and SLA slips, owned by CX ops
ChatGPT, personal accountMarketing, campaign draftsCustomer segments pasted into promptsPersonalNo
Invoice-matching prototype, AI-builtFinance operationsVendor invoices, bank referencesCompanyUnknownBuilt by an analyst, self-reviewed

Leave blanks blank. A blank cell is data. Count the rows with two or more blanks. That number is your exposure.

How to run it in about 20 minutes

1

Start from memory.

Set a timer for 20 minutes. Write down every AI tool and AI-built system you can name without asking anyone: the tools you pay for, the free accounts, the prototypes a team built with AI dev tools. The gap between memory and reality is part of the finding.

2

Ask each function head.

One question, two parts: what does your team use, and what has your team built. Keep the tone curious, not investigative. You want honest rows, not defensible ones.

3

Fill all eight columns for every row.

Names, not departments. IT is not an approver, a person is. If approval lives in an old email thread, the name on that thread goes in the column.

4

Leave blanks blank.

Do not guess and do not chase answers yet. A blank cell is data. Guessing destroys the reading.

5

Count the rows with two or more blanks.

Those are systems running in your business without governance. Blanks in the data column or the BAA and DPA column go to the top of the list.

Reading the results

  • A complete row is a managed system.
  • A row with blanks in approval and review is an unmanaged system, whatever the tool costs.
  • A blank in the data column is the most expensive kind of unknown. IBM's 2025 breach research found 1 in 5 organizations were breached through shadow AI, adding an average of $670K per incident.
  • If the register is hard to complete, that is not a tooling problem. It means the approved path is slower than your teams' need. Fix the path, not the people.

The register is week one of an AI Compass assessment.

If the blank rows worry you, the next step is structured. The assessment inventories what is running, ranks what should be by ROI and risk, and hands you a roadmap your leadership will approve.