Cases from the MBA and the Vanguard · MBA module — the inventory that showed four AI environments
Subtitle: When technology spreads faster than accountability
On Monday morning, Elena received what looked like a simple request.
Her organisation had been asked to prepare an inventory of the artificial intelligence systems it used: the name of each system, its purpose, the type of data involved, and who was responsible for it.
Elena worked in policy and governance. She expected the task to take a few days.
It did not.
She began with IT.
"Can you send me a list of all AI systems used in the organisation?"
IT sent back a list of officially licensed software.
It was short.
But Elena already knew it was incomplete.
Employees were using ChatGPT. Some had access to Microsoft Copilot. Others used AI functions built into software they had used for years. Researchers experimented with different models. Some employees used institutional accounts, while others occasionally accessed tools through personal accounts.
When Elena approached different departments, the answers became even less clear.
One department replied:
"We don't use AI."
Later, during an informal conversation, an employee from the same department mentioned using ChatGPT to summarise documents and improve emails.
Another department listed Microsoft 365 but was unsure whether Copilot should be recorded separately.
A research team argued that experimental AI tools should not be treated in the same way as operational systems.
IT maintained that it could only be responsible for centrally purchased technology.
Elena realised that the organisation did not have one AI environment. It had several overlapping ones.
There was the AI the organisation had officially purchased.
There was the AI employees openly used.
There was the AI embedded inside existing software.
And there was the AI nobody had formally declared.
The inventory was supposed to create transparency. Instead, it exposed how little central visibility existed.
The deadline was approaching.
Management wanted the document completed quickly. From their perspective, the organisation needed to respond to the request, demonstrate that the issue was under control, and avoid creating an unnecessarily heavy internal process.
Elena understood the concern. If every experimental tool, occasional use of a chatbot, or AI-enabled software feature had to be reported centrally, the inventory could become enormous and outdated almost immediately.
Employees might also begin to see AI governance as another compliance exercise: more forms, more approvals and less freedom to experiment.
But a narrow inventory created another problem.
If only officially approved systems were included, the organisation could produce a clean document that did not reflect how AI was actually being used.
And if an AI-related problem later emerged — involving confidential information, personal data, an automated recommendation, or an external service — the organisation might discover that nobody had ever been formally responsible for knowing that the tool existed.
Elena began asking a different question.
Who actually owned AI governance?
IT controlled licenses and infrastructure, but not every tool employees accessed.
Managers understood their teams' work, but often lacked technical or regulatory knowledge.
Employees knew what they personally used, but might not know whether a tool qualified as an AI system or carried additional obligations.
A central governance function could create standards and oversight, but it could not see every decision being made across the organisation.
The more Elena worked on the inventory, the clearer the problem became: responsibility was distributed, while accountability was not.
On Thursday afternoon, her manager asked for an update.
"Can we submit it tomorrow?"
Elena looked at the spreadsheet on her screen.
The systems she could verify were documented.
Several grey areas remained.
She could submit the inventory as the organisation's best available picture and improve the process later.
Or she could tell management that the organisation was not yet in a position to call the inventory complete — and recommend a broader governance process in which departments and employees would have explicit responsibilities for declaring and reviewing AI use.
The first option would meet the deadline.
The second might create a more credible system.
But it could also delay the response, increase bureaucracy, and turn a limited compliance request into a much larger organisational project.
Management was waiting for her answer.
Elena had to decide what "good governance" meant when complete visibility was impossible.
The traditional response to uncertainty is often to create more control: more reporting, more approvals and clearer central ownership. But AI challenges this instinct because its use can spread faster than any central function can realistically monitor it.
The alternative may be to design governance around distributed responsibility rather than complete central control: clear rules, local ownership, escalation mechanisms and shared accountability. The question is whether an organisation can accept less control in exchange for greater visibility and participation.
Accountability without visibility is not governance; it is paperwork.
A question for the table, a disagreement, what you would have done. The case lead reads every comment; the ones the table takes up enter the chapter as questions from the room, with your name.