Every board pack now has a slide labelled AI. Every regulator is publishing a paper. Every vendor has a responsible-AI page. The instinct is to stand up a new programme: an AI register, an AI committee, an AI policy. That instinct will fail.
There is no separate AI estate.
A model is not a free-floating object. It sits on a cloud account. It is called by a system. It is wrapped by an agent. It is licensed from a vendor. It reads from a database, writes to a ticket, and hands a result to a person who may or may not check it. The data it sees was classified (or not) by a team that does not sit on the AI committee. The vendor that hosts it already has a DPA, a DORA arrangement, and a named owner in procurement. Or it does not, and nobody has noticed because the model arrived through a browser tab.
To govern AI you must govern the ICT estate it is made of and the ICT estate it touches. Vendors. Systems. Agents. Data flows. One graph. Not a parallel inventory.
What you already know, in another language
Security already knows this. You do not run a laptop programme beside asset management. You have endpoints on the estate. Legal already knows this for processors: the question is not “is this AI,” it is who processes which personal data, under which contract, with which subprocessors. GRC already knows this for DORA: ICT third-party arrangements, function criticality, data location.
AI does not create a new category of thing. It creates new nodes and new edges on a graph you were already supposed to keep.
What AI does change is speed and reach. An agent can open a vendor relationship in an afternoon. A team can wire a SaaS model to production data without a change ticket. Tools can give that model a path into systems the CISO has never heard of. The estate now changes faster than a quarterly register can be updated. That is an ICT problem with AI characteristics, not an AI problem with an ICT footnote.
One picture, many views
The work is not to invent a second product category. The work is to see the estate as it is. Name every vendor, system, and agent. Draw the data flows. Assign an owner. Evaluate the rules you already have: access, residency, criticality, contractual terms: against current reality.
When a new model appears, it should land on the same graph as the CRM and the payroll file. When an agent starts calling a third party, that call is a vendor event and a data-flow event. It is not a curiosity for the AI working group.
TPRM, DORA, and agent governance are views on that graph. They are not separate products. If your AI register cannot answer who hosts the model, which systems call it, which data it can reach, and which contract covers that reach, it is not a register. It is a list of names.
Security, legal, and GRC should not keep three copies of that list. They need one living picture, then the views each job requires: findings, evidence, ownership, reports.
The organisations that will keep up are the ones that stop treating AI as a special exhibit. They will treat it as ICT that happens to retrieve, write, and act, and they will govern it at the speed the estate changes.
