A board that asks what AI is running in the company is asking you to mark the book to market — and “we don’t know” is a mark of zero.

Why the Board Question Matters Now

The question has moved from conference panels to audit committees. Directors who spent 2024 asking “what’s our AI strategy?” are now asking a much harder question: what AI is actually running in this company, right now, and what can it touch? It sounds like an inventory request. It’s actually a solvency check on your control environment.

The honest answer at most companies is that nobody knows. Browser AI in every department, Copilot seats provisioned faster than they’re tracked, developer agents like Cursor and Claude Desktop on half the engineering fleet, and MCP servers wiring models into source trees with no procurement record anywhere. The estate grew bottom-up while the org chart argued about ownership.

The numbers say the question is arriving on schedule:

Signal Number Source
CIOs with agents already deployed / deploying within a year 17% / 42% Gartner CIO survey
Unauthorized agent transactions caused by internal violations through 2028 ≥80% Gartner
Environments showing ungoverned AI activity on first scan 88% Ospiri research
Guardian-agent share of agentic AI spend by 2028 5–7%, up from <1% Gartner (Feb 2026)

When 80% of the incident risk is endogenous — oversharing, misuse, misguided behavior rather than external attack — an inventory isn’t a compliance nicety. It’s the position report for a book you’re already long.

The Four Books You’re Actually Holding

Most executives picture “AI in the company” as one line item. It’s at least four distinct positions, each visible to a different part of your stack — and each with a blind spot.

Surface Examples Who sees it today What they miss
Browser AI ChatGPT, Gemini, Perplexity in a tab Proxy / CASB Pasted data context; personal-device usage
Embedded SaaS agents Microsoft 365 Copilot, Slack AI, Salesforce Einstein, Zoom AI Companion The SaaS vendor’s own admin console Cross-tenant correlation; what the grant actually reaches
Standalone desktop agents Cursor, Claude Desktop, Cline, Aider, Goose Usually nobody Local file access, spawned processes, credential reach
Local MCP servers & skills files stdio connectors into source trees and internal systems Nobody — zero proxy traffic The entire integration layer
Citizen-built apps & flows Power Automate, prompt-built internal tools Platform admin, partially Post-publish behavior and data drift

Note the pattern: visibility degrades exactly as risk concentrates. The proxy sees the least dangerous surface well and the most dangerous surface not at all.

The One-Hour Answer: Anatomy

Here’s the bet: you don’t need an endpoint rollout to answer the board. A zero-install inventory, built from systems you already run, produces a ranked answer in about an hour.

  1. Identity provider first. Pull OAuth grants and app registrations from Entra or Okta. Every SaaS-embedded agent and most browser AI leaves a grant trail — this is your fastest census of sanctioned-ish usage.
  2. Egress second. Proxy and DNS logs from Zscaler, Netskope, or your SASE layer surface the browser AI estate and any cloud-calling agent, ranked by volume and department.
  3. Repos third. Scan GitHub for skills files, agent configs, and MCP manifests. This is where the invisible integration layer becomes legible — declared data sources, declared permissions, named owners.
  4. The LLM bill fourth. Per-user and per-agent token consumption is already computed for billing. A dormant service account burning tokens overnight is an agent nobody registered.
  5. Rank by exposure, attach owners. Merge the four feeds, resolve to people and business units, and sort by data sensitivity — not by tool name.

Be honest about what the hour doesn’t buy: kernel-level ground truth on what local agents actually touched. That’s the agent observability layer, and it comes later in the sequence. But “84% of the estate, here are the known gaps” is a board-grade answer. “We’re evaluating vendors” is not.

From Inventory to Exposure

A tool list is not a risk posture. The board doesn’t want to know that Bob uses Cursor; it wants to know what the firm is exposed to if Bob’s agent misfires. That translation is a scoring exercise:

Agent Risk Score = (Permission Scope × Reversibility) + (Frequency × Drift)

Factor What it measures Where the data comes from
Permission Scope What the agent can reach — files, credentials, egress OAuth grants, manifests, endpoint telemetry
Reversibility Whether the worst action can be undone Action taxonomy — a summary is reversible, a deletion is not
Frequency How often the agent acts unattended Token telemetry, scheduler configs
Drift Divergence from baseline behavior over time Behavioral analytics on the agent, not the user

Roll it up per business unit and you get the slide the board actually wants: exposure concentrated in three departments, top ten risks in plain language, and the two or three decisions that need budget. That’s agent governance expressed as a risk report, not a philosophy statement.

The Answer That Gets CIOs Replaced

One warning from the field. “We blocked ChatGPT” feels like an answer, and it’s the worst one available. Prohibition drives usage to personal devices, marks your visibility to zero, and tells the board you traded the upside for a control you can’t verify. Boards have read the same Gartner CIO survey you have — they know the business is deploying agents either way. The story they want is enablement with guardrails: we can see the estate, we can score it, and we have an enforcement point for the positions that exceed our limits. For a fuller picture of how enterprises are structuring that answer, the sequencing matters more than the vendor list.

What CISOs Should Do This Quarter

Step Action Output Effort
1 Run the zero-install inventory (identity + egress + repos + billing) Ranked AI estate with owners Days
2 Score the top 50 agents on the risk formula Exposure-by-business-unit view 1–2 weeks
3 Draft the board slide: exposure, gaps, three funded decisions One page, plain language Days
4 Pilot kernel-level observability where exposure concentrates Ground truth on the riskiest 10% 2–4 weeks

The Bottom Line

The board’s AI question is a mark-to-market request, and an unanswered inventory is an unmarked book. The raw census takes an hour with systems you already own; the translation into exposure, owners, and funded decisions is what separates a briefing from an incident post-mortem. The teams that answer well don’t claim total visibility — they show the map, name the gaps, and put an enforcement point where the exposure concentrates. If your team is sizing this for a board cycle this quarter, request a working session. We will walk through your environment, run the one-hour inventory against your actual identity and egress data, and scope a deployment. Plan for 90 minutes.