Blog · Architecture

Spreadsheet AI Inventories Are Already Obsolete

Eleye Abdi·5 July 2026·7 min read

The spreadsheet AI inventory is the governance equivalent of manually tracking cloud infrastructure in a text file. It worked when there were a handful of AI tools to track. It does not work when AI agents are being deployed continuously, across multiple platforms, by teams that may not think to tell IT.

More specifically: spreadsheet AI inventories fail the regulatory test. They cannot produce a signed, dated record of the inventory that was current as of a specific date. They cannot show that the inventory was produced through systematic discovery rather than self-reporting. They cannot demonstrate cross-platform coverage. They are records of what someone wrote down, not evidence of what is actually running.

A spreadsheet can list the AI tools you know about. AI inventory software discovers the AI agents you do not know about. Under regulatory examination, the difference between these two approaches is the difference between having an inventory and having evidence of an inventory.

The Five Ways Spreadsheet Inventories Fail

1. They capture what IT approved, not what is actually running

Spreadsheet inventories are populated through self-reporting: teams declare the AI tools they are using, IT records them. This process captures formally approved tools reliably. It does not capture tools that employees use without formal approval: OAuth-connected plugins authorised by individual users, low-code automations built by business teams, SaaS tools with embedded AI features that nobody identified as AI.

The population gap between "what is in the spreadsheet" and "what is actually running" is typically two to five times in organisations where programmatic discovery has been run alongside a spreadsheet inventory.

2. They go stale between updates

AI deployments change faster than spreadsheets are updated. New AI features appear in SaaS tools through product updates. Employees authorise new OAuth connections. Teams build new automations. The spreadsheet represents the inventory as of its last update: weeks or months ago. Between updates, the inventory is inaccurate. Even weekly manual updates cannot capture the continuous rate of change in enterprise AI deployments.

3. They cannot detect cross-platform patterns

A spreadsheet lists agents. It does not detect that Agent A on Google and Agent B on Microsoft together create a cross-platform risk pattern that neither presents individually. Cross-platform pattern detection requires stitching together what is happening across platforms simultaneously: architecturally impossible in a spreadsheet.

4. They are not evidence of currency

A spreadsheet is a record. It is not evidence that the inventory was current as of a specific date, because there is no mechanism to verify that the spreadsheet was not modified after the date shown. A spreadsheet dated 1 June 2026 cannot prove to a regulator that the content reflects the state of the AI agent estate on 1 June 2026.

This is the fundamental evidentiary failure of spreadsheet inventories for regulatory purposes. Signed evidence packs (generated at a specific date, cryptographically signed so that modification invalidates the signature) can make this proof. Spreadsheets cannot.

5. They do not scale

An organisation with 20 AI tools can maintain a spreadsheet inventory manageably. An organisation with 200 agents across seven platforms (which describes most large regulated firms running programmatic discovery for the first time) cannot. The manual effort of maintaining currency, checking cross-platform coverage, and documenting classification reasoning for 200 agents exceeds what a spreadsheet-based process can sustain.

What Happens When a Spreadsheet Inventory Faces Regulatory Examination

The failure mode of a spreadsheet inventory in a regulatory context is specific and predictable. The supervisor asks three questions the spreadsheet cannot answer:

First: "How did you identify these AI systems?" The answer "we asked our teams to declare what they are using" does not satisfy a supervisor aware that self-reporting consistently undercounts AI usage by a factor of two to five.

Second: "How do you know this inventory was current as of [date]?" The answer "we updated the spreadsheet on approximately that date" does not establish the inventory's currency. There is no verification mechanism.

Third: "Can you show me what AI agents were operating in your environment six months ago?" A spreadsheet maintains its current state. It does not retain a verifiable historical record.

These three questions define the difference between a spreadsheet inventory and AI inventory software. Software that runs programmatic discovery and generates signed evidence packs answers all three affirmatively.

What AI Inventory Software Provides

  • Programmatic discovery through OAuth grant enumeration: finding agents self-reporting misses
  • Regular cadence: monthly discovery cycles detecting changes as they occur
  • Cross-platform coverage: stitching together agent populations across Google, Microsoft, Salesforce, OpenAI, and other platforms
  • Signed evidence packs: dated, cryptographically signed records verifiable as current and unaltered under examination
  • Historical record: a chain of signed evidence packs over time demonstrating continuous monitoring, not just current state

AETHER Pulse provides all five. It connects via workspace admin APIs: no spreadsheet, no self-reporting, no staleness problem. Each monthly cycle produces a signed evidence pack that is the inventory of record for that date, verifiable under regulatory examination. The investment case is straightforward: the cost of an AI inventory that fails regulatory examination is greater than the cost of software that produces one that passes.

Frequently Asked Questions

How difficult is the transition from a spreadsheet inventory to AI inventory software?

The transition requires API connections to each platform in scope: a one-time setup typically taking days. The spreadsheet inventory can inform initial classification work, since it contains context about how each tool is used that programmatic discovery does not produce automatically.

What if we have hundreds of AI agents discovered by programmatic discovery?

Large agent populations are precisely the use case AI inventory software is designed for. Classification is applied programmatically: each agent assessed against the same criteria, producing consistent results at any scale.

Replace Your Spreadsheet AI Inventory →

Working on Article 26 readiness, deployer-side governance evidence, or AI agent risk at a regulated firm? We'd value 15 minutes of your perspective.

Start a conversation