30 minutes total. Run in order.
Pull 90 days of card/expense data. Search the vendor list: OpenAI, Anthropic, Claude, ChatGPT, Midjourney, Perplexity, Gemini, Copilot, Jasper, Otter, Fireflies, ElevenLabs. Personal-card reimbursements count double — that's someone who wanted the tool badly enough to float the cost themselves.
DNS / secure-web-gateway logs, top AI domains by unique users: chat.openai.com · claude.ai · gemini.google.com · perplexity.ai · copilot.microsoft.com. You want WHO and HOW MUCH — not blocking yet.
Ask team leads, verbatim: "What AI tools does your team use to get work done? Nobody's in trouble — I need the list to protect it." The amnesty framing is the entire trick. Punish honesty once, and you go blind forever. Asked right, question three finds the tools one and two missed.
Sort everything into the Inventory database as Approved (low-risk, real value) · Approved with rules (fine unless client data, credentials, or regulated data goes in) · Replace (high-risk, a sanctioned tool already does the job). Write it down — that triage IS your first AI policy.