Most organizations discover AI agents later than they should. A team builds a workflow assistant, a vendor adds agentic features, an engineer connects a model to internal tools, or a business group adopts a browser-based automation product. By the time governance hears about it, the agent may already be touching data or taking action.
Discovery has to be designed as an operating process, not a one-time questionnaire.
Start with the obvious signals
Look at code repositories, dependency manifests, API gateway logs, cloud usage, model provider invoices, vendor expense reports, browser extensions, automation platforms, and internal app catalogs. These sources will not find everything, but they create a first map of where AI and agent behavior may exist.
Search for model SDKs, orchestration frameworks, tool-calling libraries, vector databases, prompt files, retrieval services, and scheduled automations. A system does not need to call itself an agent to behave like one.
Ask better intake questions
A survey that asks do you use AI will miss important systems. Ask whether software can generate content, make recommendations, call tools, retrieve internal information, update records, send messages, run code, or trigger workflows. These questions reveal autonomy and data access.
Require owners to identify purpose, users, data categories, connected tools, human review points, model provider, environment, and launch status.
Include vendor AI
Many agents will not be built internally. They will arrive through CRM, support, HR, procurement, analytics, security, development, and productivity platforms. Vendor assessments should ask whether AI features can access customer data, train on company content, generate external output, or take action through integrations.
If a vendor agent can operate inside company workflows, it belongs in the inventory.
Treat unknowns as work items
Discovery will produce incomplete records. That is normal. The important thing is to preserve unknowns: unknown owner, unknown data access, unknown autonomy, unknown retention, unknown tool permissions. Each unknown should become a follow-up item with an owner and due date.
Keep discovery continuous
AI agent discovery should run continuously through code scanning, procurement intake, security reviews, product launches, employee tool requests, and periodic attestation. The inventory should change as systems change.
The goal is not to police every experiment. The goal is to know when an experiment becomes a system with data, users, tools, or external impact. That is where governance must start.