Skip to content

Governance

14 May 2026 · updated 28 July 2026 · 10 min read

Shadow AI is already in your business

Shadow AI is the use of AI tools inside a business without approval, oversight or a record: staff pasting client data into consumer chatbots, browser extensions reading documents, personal accounts connected to company file stores. It is present in most Australian businesses today, and a ban is the one response reliably guaranteed to make it invisible rather than absent.

What shadow AI actually is

Shadow AI is the use of AI tools inside a business without approval, oversight or a record. It is the direct descendant of shadow IT, the era when staff signed up for Dropbox because the company file share was miserable, with one significant difference. Shadow IT moved files into an unapproved location. Shadow AI sends the contents of those files to a third party, under terms nobody in the business has read, with no log of what went where.

The scale is different too. Signing up for an unapproved SaaS product took a decision, a credit card and usually a conversation. Pasting a contract into a free chatbot takes eleven seconds and feels like using a search engine.

Why good staff do it

This is not a discipline problem, because treating it as one guarantees you never find the real picture.

Someone in your finance team has a reconciliation that takes an afternoon and discovers a tool that does the tedious part in a minute. Someone in operations has to write the same kind of report every fortnight and finds that a chatbot produces a decent first draft. A salesperson is on the road, needs a proposal by morning, and has a phone.

All three are doing exactly what a good employee does: finding a faster way to produce the same output. None of them has been told where the line is, because in most Australian businesses nobody has drawn one. And a policy that says "do not use AI" does not draw a line. It just moves the activity onto personal devices where you have no visibility at all.

The usage does not stop when you ban it. It stops being visible, which is a different and worse outcome.

Where it hides

Most organisations underestimate what is in use, mostly because they only look in one place. In practice it shows up across at least six:

  • Consumer chatbots in a browser tab. The obvious one, and rarely the largest exposure.
  • Browser extensions. Summarisers, writing assistants, meeting note-takers. Many request read access to page content on every site, which includes your CRM and your webmail.
  • AI features inside tools you already pay for. Frequently enabled by default. Sometimes governed adequately, sometimes not, and almost never checked.
  • Meeting transcription bots. They join a call as a participant and record it. Whose account, stored where, retained how long, and did anyone in that meeting consent?
  • Personal accounts connected to company data. An individual's AI subscription authorised against a company Google Drive or OneDrive is one OAuth consent screen away and produces no alert.
  • Code assistants. In technical teams, sending proprietary source and sometimes credentials to a third party.

The pattern is consistent: the things people expect to find are visible and comparatively minor; the significant exposures are the ones nobody thought to look for.

What is exposed

The honest answer is: it depends entirely on the tool and the tier, and that variance is the whole problem.

Enterprise AI platforms, configured properly, generally do not train on submitted data, can be pinned to a region, offer retention controls and produce audit logs. Consumer tiers of the same products do train on submitted data by default, retain it, and give you no visibility whatsoever. The interface is nearly identical. The contractual position is not remotely.

Under Australian privacy law, sending personal information to an overseas AI provider is a cross-border disclosure with obligations attached. That obligation does not disappear because the disclosure was made by an individual employee who did not realise they were making it. It is the organisation's obligation.

Then there is the question that arrives without warning: an enterprise client sends a security questionnaire asking which AI tools you use, what data goes to them, and whether AI-assisted work is reviewed before delivery. If the honest answer is "we do not know", that is a commercial problem now, not a theoretical one.

How to find it

Discovery is the whole first phase, and it works best when it runs on several channels at once, because each finds things the others miss.

  1. Identity provider consents. In Microsoft Entra or Google Workspace, list the third-party applications users have granted access to. This is the highest-value fifteen minutes available and it is almost never run.
  2. Network and SaaS telemetry. If you have a CASB, a secure web gateway or even DNS logs, query for the known AI domains. Traffic volume tells you which are in serious use rather than merely visited once.
  3. Browser extension inventory. Manageable through endpoint tooling in most environments, and consistently the source of the biggest surprises.
  4. Tenant-level AI settings. Which AI features are enabled by default in the platforms you already pay for, and who can turn on more.
  5. Ask people. Explicitly, and with a stated no-blame framing. This finds more than the technical channels combined, and it only works once. If the first conversation produces disciplinary consequences for anybody, you will never get an honest answer again.

The framing for that last one is not complicated: we are working out what to sanction and support, we would rather know what is genuinely useful to you, nobody is in trouble. Meant sincerely, it works.

What to do once you can see it

Discovery produces a list. The list needs three decisions, and they should be made against the consequence of exposure rather than the popularity of the tool.

Block the small number that are genuinely unacceptable: anything with terms granting broad rights over submitted content, anything with a history of breaches, anything whose function is fundamentally incompatible with your obligations.

Sanction with controls the ones that are useful and can be governed: move them onto enterprise tenancies, apply conditional access, configure retention, and put them in the approved list.

Replace the rest with a governed alternative, and this is the part that decides whether any of it holds. The sanctioned option has to be genuinely better than the tool people were using unofficially. Not merely compliant. Better. Faster to reach, at least as capable, and with no additional friction to open. If the approved option is worse, staff will go back to the good one on their phone and you will be exactly where you started, minus the goodwill.

Then the ongoing part, which is where most governance efforts quietly stop:

  • A named owner. One person, not a committee.
  • A lightweight intake for assessing a new tool, measured in hours rather than weeks, because a slow process is a process people work around.
  • A quarterly review of what is in use against what is approved.
  • Monitoring that makes unapproved use visible without surveilling individuals.
  • A refresher whenever the approved set changes materially.

The uncomfortable part

Most businesses find that the shadow AI usage they uncover is producing real value. People are faster. The reconciliation does take a minute now.

Which means the goal is to move that value onto ground where you can see it, log it and answer for it, rather than to switch it off, and to do that quickly enough that nobody feels punished for having found something that worked.

Read next

Want this applied to your operation?

Reading about it only gets you so far. Thirty minutes on one process that frustrates you, and a straight answer on whether it's worth automating.

Book a discovery callSend an enquiry

Gold Coast · Brisbane · Australia-wide

Book a discovery call