AI enters your estate in five forms — embedded, subscribed, metered, hosted, and hidden. As of August 2, a regulator can fine you over all of them. This episode is how you count yours.
The estimate that most organizations spend at least half again what they believe on AI is flagged in the episode as the host's opinion and cannot be proven. Every other figure is drawn from the named Flexera, FinOps Foundation, IBM, and Zylo reports, and the regulatory dates come from the text of the EU AI Act, the European Commission's July 2026 guidelines, and the Digital Omnibus.
The complete transcript — 3,084 words. Search it, quote it, or send the relevant section to a colleague who needs to see it.
Hey everybody, and welcome back to the Operational ITAM podcast. I'm Bill Van Nort, and today I am keeping a promise with a date on it. On August 2nd, 2026, three weeks ago, a new regulation began to apply to a class of technology assets. Not a security regulation, not a privacy regulation, a transparency regulation aimed at systems that most organizations cannot even count yet.
Article 50 of the European Union's AI Act took effect that day, and the penalty ceiling for getting it wrong is 15 million euros, or 3% of worldwide annual turnover, whichever is higher. Read that again. Whichever is higher. Here is what makes that date matter for this show. Every asset class we have ever covered had years, sometimes decades, to grow up before a regulator came looking.
Hardware got its rules after we had been buying laptops for a generation. Software licensing evolved its enforcement over 30 years. The AI estate did not get that grace period. It is the first asset class in the history of this discipline to arrive with a regulator already attached. And most organizations cannot tell you what is in it. Good morning, good afternoon, or good evening, wherever you're listening from.
This is the show where we take the unglamorous machinery of enterprise technology and make it make sense. Grab your coffee. Today, we inventory the newest asset class in the estate, and by the end of this episode, you will know how to count yours. Last episode, I told you this was coming. I said we would go after the newest asset class in the estate, and the first one to arrive with a regulator already attached.
That was not a teaser written for drama. That was a warning with a date on it, and the date has now passed. So today, we do what this show always does with a new asset class. We define it. We count the ways it enters your estate. We point the fundamentals at it, and we figure out what you can do about it this week, with the data you already have.
But first, the numbers. And I'll name the sources because on this show, we do that. Start with what the asset managers see. Flexera's 2026 State of ITAM report, 512 respondents, asked organizations about visibility into AI software specifically. 31% said they have accurate visibility. 31. And the same report found the share of organizations reporting increased wasted spend on AI software rose 59% year over year.
So we cannot see it, and we are already wasting money on it. Those two findings are not a coincidence. They are cause and effect. Now flip to the finance side of the house. The FinOps Foundation's State of FinOps 2026 survey, their sixth annual, 1,192 practitioners managing over $83 billion in cloud spend. Two years ago, 31% of FinOps teams managed AI spend in any form.
This year, 98%. 98. That is not adoption. That is a category being absorbed whole. And here is the number inside the number. 73% of organizations blew through their AI cost plans. The teams whose entire profession is cost discipline are missing their own AI budgets three times out of four. And then the security side. IBM's cost of a data breach report, the 2026 edition, released July 29th.
602 breached organizations studied. A year ago, that report told us shadow AI, meaning AI tools employees adopted without approval, showed up in 20% of breaches. We covered that in episode 6. The new number is 43%. It more than doubled in one research cycle. Those breaches averaged $5.39 million, and roughly one in five of them drew a regulatory fine.
Sit with that stack for a second. The asset managers can barely see it. The cost managers cannot hold it to a budget. The security teams are getting breached through it. And as of three weeks ago, a regulator can fine you over it. Every function in the building is touching this thing, and nobody owns the inventory.
So here is today's thesis. AI is not one asset. That is the mistake almost everyone is making, including some very expensive consultants. AI enters your estate in five distinct forms, and each form lands in a different budget, under a different owner, with a different risk profile. If you try to manage the AI estate as one thing, you will miss four-fifths of it.
So let me give you the five forms, the same five I use with clients, and I want you to picture your own organization as I go. Form 1, Embedded. AI features switched on inside software you already own. Copilot inside Microsoft 365. Einstein inside Salesforce. The AI assistant your service desk platform just added to your license tier, sometimes with a price change, sometimes quietly.
Embedded AI is the sneakiest form because it does not arrive through procurement at all. It arrives through a product update. Your application count did not change. Your risk profile and your renewal exposure did. Form 2. Subscribed Standalone AI subscriptions bought as SaaS, ChatGPT team licenses, Claude seats, the transcription tool marketing bought, the image generator design bought, the coding assistant engineering bought.
This is the form that behaves most like the software we already know how to manage, seats and renewals and utilization. Which means everything we covered in episode 3 and episode 9 applies. It just applies to products your normalization catalog may not recognize yet. Form 3, metered. Consumption-priced AI, usually through APIs. Tokens in, tokens out, GPU hours, per-request charges.
This is the form that breaks your budget model, because there is no seat count to right size. Spend scales with usage and usage scales with enthusiasm. This is where those blown AI cost plans live. The FinOps Foundation found the single most requested capability across their entire survey was granular monitoring of AI spend. Tokens, requests, GPU utilization. The people closest to the invoices are telling us the meter is the problem.
Remember that because it is exactly where we are going next episode. Form 4. Hosted. Models you run yourself. Open weight models on your own GPUs. Fine-tuned models in your own cloud tenancy. Here the asset is not just the software. It is the model artifact, the weights, the training data lineage, the GPU hardware underneath it. This form looks the most like traditional infrastructure and hides the most novel questions.
Who owns a fine-tuned model? What did it learn from? Can you prove it? Form 5. Hidden, Every one of the first four forms. Unrecorded. The Shadow AI from IBM's report. The department that expensed an AI note-taker. The developer with a personal API key hitting a frontier model with company code. The embedded feature nobody flagged. Hidden is not a fifth kind of technology.
It is the other four wearing no badge. And at 43% of breached organizations, it is currently the most expensive form on the list. Embedded. Subscribed. Metered. Hosted. hidden. Five forms, one name, and the name is the AI estate.
Now this show was built on four questions and I am not about to coin a new framework when the one from episode one still works. Know what you have, know where it is, know what it costs, know when it leaves. Watch what happens when we point them at the AI estate. Know what you have. For AI, this means an inventory across all five forms, not just the subscriptions.
Which products in your estate have AI features enabled? Which teams hold standalone AI licenses? Which API keys exist and to which providers? Which models are you hosting? You cannot answer that from a purchasing report alone, because Form 1 never crossed Procurement's desk and Form 5 never crossed anyone's. Know where it is. For AI, location means something new.
It means where your data goes. Every AI tool is a data flow. When someone pastes a customer record into a chatbot, that record has a new location, and it is not one on your network diagram. This is where asset management and security stop being neighbors and become the same job. Know what it costs. Across five forms, cost lives in five places.
A license uplift here, a SaaS subscription there, a metered API bill that doubled last month, GPU capacity in the cloud invoice and expense reports with vendor names finance has never seen. Nobody sees the total unless somebody assembles it. And this is not a hypothetical gap. Back in episode 9, I gave you Zylo's 2026 SaaS Management Index, finding that 78% of IT leaders were hit with unexpected consumption or AI charges in a single year.
78%. That number was the AI estate announcing itself on the invoice before most organizations had given it a name. Opinion, flagged as my personal opinion. I believe most organizations are spending at least half again what they think they are spending on AI, because nobody has ever put the five forms on one page. I cannot prove that number, so do not put it in a business case.
Assemble your own instead. And know when it leaves. Models get deprecated. Vendors sunset endpoints with 90 days of notice. An AI feature you built a workflow on gets re-bundled into a more expensive tier. The AI estate churns faster than any asset class we have ever tracked, which makes the leaving question, the question this discipline always answers
worst, the one that will bite first. Let's take a quick break. If you're getting value from this show, subscribe wherever you're listening. And if you know somebody who just got asked to inventory their company's AI, send them this episode before their end of quarter. Every episode with full transcripts is at operationalitam.com. Okay, part two, the regulator.
So, the regulator. Article 50 is the transparency article, and as of August 2nd, it applies. In plain practitioner terms, it covers four situations. If people interact directly with an AI system, a chatbot, a voice agent, they have to know it is AI, unless it is obvious. If a system generates synthetic content, that content has to carry machine-readable marking so it can be detected.
If you deploy emotion recognition or biometric categorization on people, you have to tell them. And deepfakes, plus AI-written text published on matters of public interest, have to be labeled. The European Commission adopted implementation guidelines on July 20th, 51 pages of them. And there is one dated exception worth knowing. Generative systems already on the market before August 2nd have until December 2nd, 2026, to comply with the marking and detection piece.
That is a grace period with a fuse on it, not an exemption. And a note of honesty about scope, because precision is the whole brand here. The heavier obligations you may have read about, the named human oversight, the logging requirements for high-risk systems, those sit in a different article, Article 26, and the EU's Digital Omnibus deferred those to December 2, 2027.
So do not let anyone panic you with the wrong deadline, and do not let anyone lull you with it either. Transparency is enforceable now. The high-risk regime has a date, and it is closer than it sounds. Here is why this lands on this show and not just on your legal team's desk. You cannot label what you have not found.
Every Article 50 obligation presupposes an inventory. Which of our systems interact with people? Which generate content? Which are already marking it? Those are asset questions. The regulation assumes you can answer them. 31% visibility says most of us cannot. Compliance work is inventory work wearing a suit. It always has been. Let me make that concrete. Say your company runs a support chatbot on the public website and marketing generates product images with an AI tool for campaigns that reach European customers.
Two ordinary things. As of three weeks ago, the first one needs to be disclosed as AI, where that is not obvious, and the second one needs machine-readable marking under the provider and deployer rules. Now ask the asset question hiding inside the legal one. Did anyone in your organization know both of those systems existed? On one list, before I said that sentence?
In the 31% of organizations with accurate AI visibility, yes. Everywhere else, the regulation is now enforceable against systems nobody has counted.
Okay, time for a listener question. This one comes from Priya in Ann Arbor. And Priya asks: Our CIO came back from a board meeting and asked me for a complete inventory of our AI by end of quarter. I run our asset program. I do not even know what counts. Is Copilot an asset? Is a model an asset?
Where would I start? Priya, first, congratulations, because your CIO just asked you the right question and asked the right person, and both of those are rarer than they should be. Here is my answer. Do not start by defining AI. You will lose the quarter to philosophy. Start with the five forms as your columns and go hunting form by form, because each one has a different place it leaves footprints.
Embedded hides in your existing vendor list. Take your top 20 applications by spend and answer one question per vendor. What AI capability is switched on, and did our terms or price change when it arrived? Subscribed shows up in the places Episode 6 taught you to look. Expense data and single sign-on logs filtered for AI vendor names. Metered lives in your cloud bills and your accounts payable.
Search for the model providers and the API line items. Hosted is a conversation with your platform and infrastructure teams. Ask what models we run and on what hardware. And hidden is the gap between what those sources show and what your asset register admits to. And yes, to your actual question, Copilot is an asset, an entitlement attached to a license you already pay for.
The model your team fine-tuned is an asset too, and I would argue it is the most under-managed one you have because it embodies your data. One page per form, owner, count, cost, and where the data goes. That is an inventory your CIO can govern from. That is where you start.
Now, I told you at the top we were going somewhere new, and I owe you a goodbye first. We have been in a library since episode one. Ten episodes. We walked the circulation desk, the strange section where none of the books are yours, the inspector at the front desk, the late fee notice, the second library behind the boiler room, the weeding cart, the backroom ledger, the serials department, and last episode, the catalog itself.
The library gave this show its spine, because a library is the oldest asset management program on earth, and every lesson it taught us stays true. The cataloging makes the catalog good. The reputation does not transfer with the cart. Nothing in that building gets unlearned. But the estate we just spent this episode describing does not live on shelves.
Metered consumption, models, GPU capacity, spend that flows instead of sits. You do not manage a flow with a card catalog. You manage it the way utilities do. So starting next episode, this show moves into the grid. The power grid. Generation, metering, transmission, rate cases, and a control room where somebody watches the load in real time. Same discipline.
Same four questions. A world built for assets that move. The library closes with full honors, and the lights we switch on next door are the point of the whole tour.
Which brings us to today's principle, and let's take the whole run from the top. Hardware asset management is a custody discipline. Software asset management is an evidence discipline. Audit defense is a process discipline. Settlement is a commercial discipline. Shadow IT is a service discipline. Refresh is an economics discipline. Disposal is a liability discipline. Renewal is a leverage discipline.
Tooling is a judgment discipline. And the AI estate? The AI estate is a governance discipline. Governance, because no single function can hold it. asset management counts it, finance meters it, security watches it, legal answers for it, and governance is the discipline of making those four functions produce one truthful answer.
That is the principle. Class dismissed. Here's your homework, and this one is about an hour. Run a shadow AI census from data you already have. Pull 90 days of expense and purchasing card data and filter for AI vendors and anything with AI in the product name. Pull your single sign-on log and list every application with AI in its name or description.
Then pull your asset register and count how many of those products it contains. Three numbers on one page. What finance is paying for, what identity can see, and what your records admit. The gaps between those three numbers are your hidden form, and that page, dated and signed, is the first artifact of your AI estate program. About an hour.
Most of you will not like your three numbers. Good. A number you do not like is a number you can fund a fix with. Next episode, we walk through the doors of the grid and straight into the meter room. Token-based pricing, GPU hours, and why the number one capability FinOps practitioners say they need right now is granular monitoring of AI spend.
Tokens, requests, utilization. If the AI estate is the new asset class, the meter is where it gets measured, and I will show you how to read yours before the invoice does. That is episode 12. And the case files. The ask stands, and the format stands. One situation, one page, anonymized. The constraint, what you did, what happened. If you are the person who just got handed the AI inventory question, I especially want yours.
Send me one worth working and I will build an episode around it. Details at operationalitam.com. I'm Bill Van Nort, this is the Operational ITAM Podcast. Count all five forms, put the total on one page, and tell your CIO before the regulator asks. Talk to you next week. Take care.
Send it over — anonymized, sanitized, no company names. Real constraints, real politics, real budgets. Situations get worked on air.