Why AI Inventories Fail After 90 Days, And How to Build One That Doesn't
Most AI agent inventories are built with good intentions and adequate effort. They fail not because of poor execution but because of a structural mismatch: they are built as documents, and documents decay. The AI agent estate they describe continues to change after the document is completed, and the document has no mechanism to reflect those changes.
The 90-day failure pattern is consistent across organisations that have built inventory programmes without programmatic discovery. Within 90 days of completion, the inventory is materially inaccurate. Not because governance teams stopped caring, but because the rate of change in enterprise AI deployments outpaces any document-based update process.
An AI agent inventory that was accurate on day one and is not maintained programmatically will be materially inaccurate by day 90. The question is not whether this happens. It is how many unrecorded agents will have appeared, and what risk they carry.
The Four Decay Vectors
1. New SaaS AI features
Enterprise SaaS tools add AI features continuously through product updates: Gemini in Google Workspace, Copilot in Microsoft 365, Einstein in Salesforce, AI-assisted features in CRM, ITSM, and productivity tools. These features appear without a procurement event. No change request is raised. No IT approval is sought. The inventory built last quarter does not reflect the AI capabilities present in the tools the organisation is already using today.
2. Employee OAuth authorisations
Employees authorise third-party applications (AI tools, automation platforms, productivity integrations) by connecting them to their organisational accounts through OAuth. These authorisations happen daily, across the organisation, without IT visibility. Each one creates an AI agent with access to organisational data. None of them triggers an inventory update.
3. Low-code and no-code AI automations
Microsoft Power Automate, Google Apps Script, Zapier, and similar platforms enable business users to build AI-enabled automations without developer involvement. A marketing team member who builds a Power Automate flow calling the Azure OpenAI API to summarise customer feedback has created an AI agent. It will not appear on the inventory unless someone in the team thinks to report it. Which they may not, because they may not think of it as an AI agent.
4. Agent configuration changes
Existing AI agents change. OAuth scopes expand when additional features are enabled. Agents are repurposed for new use cases. Data access permissions change when users change roles or when file permissions are updated. An agent that was classified as low-risk at inventory time may be medium or high-risk today based on changes that occurred in the interim.
Why the 90-Day Window Is Specific
90 days is not an arbitrary threshold. It reflects the typical cadence of organisational change in enterprise AI deployment. Most organisations see significant changes to their SaaS tool landscape on a quarterly basis: new tool deployments, major version updates with AI features, procurement renewals that include AI add-ons. Each quarterly cycle adds a layer of AI capability that a document inventory from the previous cycle does not capture.
It also reflects the regulatory examination risk. An FCA supervisor or ICO auditor asking for the AI agent inventory is asking for the current state. An inventory that is 90 days old (with four decay vectors operating throughout that period) is not the current state. It is a historical document.
The Document Inventory vs the Living Inventory
The failure mode of document inventories is not solvable by updating the document more frequently. Weekly manual updates would reduce the decay rate but cannot eliminate it, because the update process relies on someone knowing that a change occurred and reporting it. The decay vectors above all involve changes that bypass the reporting mechanism.
A living inventory solves the problem at the architectural level: instead of asking people to report changes, it detects changes programmatically. By querying workspace admin APIs at regular cadences (Google Workspace Admin SDK, Microsoft Graph API, Salesforce connected apps, OpenAI workspace admin) a living inventory discovers what is actually running, independent of what has been reported.
Each discovery cycle compares the current enumeration to the previous one. New agents appear as additions. Removed agents appear as deletions. Configuration changes appear as modifications. The inventory reflects the current state because it is generated from the current state, not from accumulated reports.
Further reading: How to Build an AI Agent Inventory and Spreadsheet AI Inventories Are Already Obsolete.
What a 90-Day-Proof Inventory Requires
- Programmatic discovery. The inventory is generated by querying admin APIs, not by collecting self-reports. Discovery runs on a cadence (monthly minimum) that is shorter than the quarterly change cycle.
- Automated change detection. Each discovery cycle identifies additions, modifications, and removals since the previous cycle, producing a change log that is part of the evidence record.
- Signed dating. Each cycle produces a signed, dated snapshot of the inventory that can be verified as current as of the cycle date. The chain of signed snapshots provides a historical record of the inventory's evolution.
- Classification on discovery. New agents discovered in each cycle are classified immediately, using a deterministic methodology that produces consistent results. Classification is not deferred to a periodic review process.
- Threshold alerting. High-risk agent discoveries or significant configuration changes trigger alerts to the governance function, rather than waiting to be identified in the next scheduled review.
How AETHER Pulse Prevents the 90-Day Failure
AETHER Pulse implements all five requirements above. Its monthly discovery cycles query workspace admin APIs across seven platforms, detecting additions, modifications, and removals since the previous cycle. Each cycle produces a signed evidence pack (a dated, cryptographically signed snapshot of the agent estate at that point). New agents are classified immediately. The chain of monthly signed packs provides a continuous, verifiable inventory record that does not decay between cycles.
For regulated firms that have built document inventories and are now aware of the 90-day failure pattern, AETHER Pulse provides the architectural upgrade: from document to living inventory, from self-reporting to programmatic discovery, from decay to continuous accuracy.
Frequently Asked Questions
How quickly does a document inventory become inaccurate?
The rate of decay depends on the organisation's AI adoption rate. In most regulated financial services firms in 2026, the AI agent estate is changing at a pace that makes a document inventory materially inaccurate within 60 to 90 days of completion. High-adoption environments (where business users actively deploy AI tools) may see significant inaccuracy within 30 days.
Can we use AETHER Pulse alongside our existing document inventory?
Yes. AETHER Pulse's discovery results can be compared to an existing document inventory to identify the gap: which agents are present in the environment but not in the inventory. This comparison is itself a valuable governance exercise, and the results provide the baseline for transitioning from document to living inventory.
How do we handle the agents we find that were not in our existing inventory?
Discovery of unrecorded agents is the expected and intended outcome. Each discovered agent should be classified, assessed for risk, and either brought into the governance programme through retrospective review or assessed for revocation. The discovery process identifies the gap. The governance process addresses it.
Working on Article 26 readiness, deployer-side governance evidence, or AI agent risk at a regulated firm? We'd value 15 minutes of your perspective.
Start a conversation