Doing AI Governance | Edition #60: Building an AI Inventory is your First Governance Intervention


This newsletter provides practical guidance, tools and resources for the real work of governing safe, secure and lawful AI.

Newsletter #60 - July 2026

Feature Article #1

Building an AI Inventory is your First Governance Intervention

By James Kavanagh


Your first meaningful governance intervention is most likely building an AI inventory. It's the first time anyone in the organisation has to sit down and agree, out loud, on what AI is really running and what it's for. That's not an admin task before governance starts. It’s a governance intervention itself.

And it's harder than it looks, because two very different mindsets tend to show up. The policy and legal people reasonably start from harm: who could get hurt, and is this use lawful. The engineering and ops people start from the hazard: what could fail, and how do we test and fix it. Both are right, but they need a mechanism to connect their two perspectives.

If you're the governance practitioner in that room, bridging those two mindsets is your job. This article goes through how you negotiate these different perspectives and centre them on a shared understanding of AI use cases.

💡 Practitioners in our current guided cohort program worked through this very problem in our most recent live session. We took the theory into real discussion and nuance, working through a children's hospital caught between the promise of AI and the risk of moving too fast. From there, every Practitioner built their own AI inventory for real inside VerifyWise, watching the thinking turn into configured tooling.

How many of the AI systems being used in your organisation would be missed if you tried to list them today?

Feature Article #2

Under the hood: model, dataset, interface and agent cards

By James Kavanagh


A use-case map shows where AI is used, misuseed and who it touches. It stops at the at the capabilities of a system, but doesn't help identify where the hazard exists and how it can be addressed. Here's how I document the machinery within an AI system, as model, dataset, interface and agent cards.

For the purposes of technical governance, I break every AI system into four sets of components: the model that produces the output, the datasets feeding it and passing through it, the interfaces where it meets people and other systems, and the agents that act on what the model decides. Right now, agents probably get the most of my attention.

For each component I write the most essential information on one card. Just a page, holding only what a governance conversation needs: what a model is for and what it must never be used for, where a dataset came from and what's sensitive in it, how an interface authenticates and what it exposes to an attacker, how far an agent's authority runs before a human has to sign off. If you're currently just thinking about model and dataset cards, then you might find this approach completes the picture for agentic AI.

"I found the guidance on AI inventory extremely valuable, particularly from the business and technical perspective. Since I am not coming from an AI domain, the practicality of it resonated with me." - Elida, UAE

Course 2 of the AI Governance Practitioner Program: Foundation Track shows how to build AI governance inside real organisations, with real constraints, across teams that don't naturally work together.

What we're working on

Our Foundation Track Practitioner Cohort #1 is in full swing, with 15 AI governance practitioners from all around the world, coming from legal, technology, policy and other backgrounds. Through one complex case study focused on AI governance in a children's hospital, we're working to: identify harms, set principles and commitments, build inventory, diagnose and redesign mechanisms and finally write policies that people will genuinely use. And all of it implemented within the VerifyWise GRC platform. This is hands-on real practice of AI governance - learn the theory and practice with real situations. Foundation Track Practitioner Cohort #2 starts in August, with two groups across two time zones. Spots are filling fast - secure your place here.

Our first specialty course: AI Compliance will be released soon and with it our new AI governance practitioner tool - Balcony. More on that when we release. We will be sharing a special offer with those on the AI Compliance Waitlist, prior to the course being released to everyone, so be sure to join the waitlist here.

As always, reach out if you have questions or need further clarity on any of our work, or if you need help navigating your professional path. We're learning with you and really appreciate your enquiries and feedback.

PS. You're receiving this as a subscriber to communications from AI Career Pro. We respect your privacy, so please unsubscribe through the link below if you do not wish to receive these communications in the future.

PO BOX 7087, Redhead, NSW 2290
Unsubscribe · Preferences

Doing AI Governance

Join over 4,500 subscribers and learn about the real work of AI governance. Moving beyond theory, we focus on the practical application of AI governance in real-world organisations with case studies, tools, templates and guidance. Led by James Kavanagh - the AI governance practitioner who led governance at both AWS and Microsoft.

Read more from Doing AI Governance

This newsletter provides practical guidance, tools and resources for the real work of governing safe, secure and lawful AI. Newsletter #59 - June 2026 Feature Article #1 How I scope compliance obligations for AI governance By James Kavanagh The biggest compliance obligations on your AI systems rarely come from AI regulation. Here's how I work out what actually applies, starting from what the business does, not the law. When practitioners new to AI Governance start scoping their compliance...

This newsletter provides practical guidance, tools and resources for the real work of governing safe, secure and lawful AI. Newsletter #58 - June 2026 Feature Article #1 How I triage AI governance problems By James Kavanagh You get hired to review one AI system. Within hours you find a dozen, and the one everyone's worried about turns out to be the safest of the lot. The systems that should worry you are usually the ones nobody can see. This is the method I use to work out where to start....

This newsletter provides practical guidance, tools and resources for the real work of governing safe, secure and lawful AI. Newsletter #57 - May 2026 Feature Article A new path to demonstrated practitioner capability in AI governance. By James Kavanagh Law has supervised practice before admission to the bar. Medicine has residency. Engineering has years of oversight by senior engineers before obtaining a charter. Each serious profession recognizes that capability builds in stages, and that...