Skip to content

Service 05

Your team is already using AI. Can you see it?

AI Security & Governance

AI governance is the set of controls that lets a business use AI without losing track of where its data goes. It starts with discovery, finding the AI tools staff are already using without approval, then covers data exposure, an enforceable usage policy, technical controls, and a sanctioned alternative good enough that people actually use it.

Shadow AI discovery and data exposure assessment
An AI usage policy your staff will actually follow
Controls and DLP for AI tools

Shadow AI is already in your business

Right now, somewhere in most Australian businesses, someone is pasting a client contract into a free AI tool to get a summary. Someone else is running customer records through a browser extension nobody approved. A third person has connected a personal AI account to the company file store because it made their week easier.

None of them are being reckless. They are being productive with the tools available, because the tools are useful and nobody has told them where the line is. The exposure is real regardless of intent: data leaving your control, into consumer terms of service, with no log of what went where.

We come from the security side of IT, so we start where a security person would start, with discovery. You cannot govern what you cannot see, and almost every organisation we talk to underestimates what is already in use.

The Shadow AI check

A short, focused engagement that answers one question: what is happening?

Discover

We identify the AI tools in use across the business: through network and SaaS telemetry where it is available, through browser and extension inventory, through the identity provider's application consents, and through a no-blame conversation with the teams themselves. The last one finds more than people expect.

Assess

For each tool: what data is it seeing, under whose account, under what terms, and what is the consequence if that data were disclosed. Ranked by consequence, not by tool popularity.

Decide

Some tools get blocked. Some get sanctioned with controls. Some get replaced by a governed equivalent. That decision is yours; our job is to make it an informed one rather than a reflex.

Control

Technical enforcement of the decision: conditional access, DLP rules, tenant-level controls in Microsoft 365, and monitoring so the next unapproved tool surfaces in weeks rather than never.

A policy people will actually follow

Most AI usage policies fail for the same reason most security policies fail: they are written to protect the organisation from its staff, so staff route around them. A policy that bans AI outright produces exactly one outcome, which is the same usage as before, now hidden.

We write the policy to be usable. Short. Specific about data classes rather than vague about 'confidential information'. Clear about which tools are approved for what. And paired with a sanctioned option that is genuinely better than the one being used unofficially, because that is the only version of this that holds.

  • Which data classes may go into which tools, in plain language with examples
  • The approved tool list, and how a new tool gets assessed
  • What to do when someone realises they have made a mistake, without it being career-limiting
  • Human review requirements for AI-assisted work that leaves the business
  • Disclosure expectations, where a client or a regulator requires them

Australian frameworks we align to

Privacy Act 1988 & the Australian Privacy Principles
How personal information may be collected, used, disclosed and stored, including the disclosure that occurs when data is sent to an overseas AI provider.
Essential Eight
The ACSC's baseline mitigation strategies. AI tools interact with several of them directly, particularly application control, restricting administrative privileges and user application hardening.
Voluntary AI Safety Standard
Australia's national guidance for safe and responsible AI adoption, published by the National AI Centre. Voluntary, and the framework most local governance conversations are now anchored to.
Sector obligations
Where they apply (RTO standards, NDIS practice standards, health records legislation, financial services obligations), the governance model has to satisfy them too.

Where the data sits

Guardrails and approval gates where they matter, logging designed to show what happened, and a clear written answer on where each workload runs and what is retained. We work that out against your obligations rather than asserting it up front, and you get it in plain language rather than buried in a vendor's sub-processor list.

Governance that runs after we leave

A governance engagement that ends with a document has failed. The tools change monthly, staff change quarterly, and the model providers change their terms without asking. What you need is a cadence that catches drift.

  • A named owner for AI governance: one person, not a committee
  • A lightweight intake process for assessing a new tool, measured in hours not weeks
  • A quarterly review of what is in use against what is approved
  • Logging and monitoring that makes unapproved use visible without surveilling individuals
  • A refresher for staff whenever the approved tool set changes materially

What you get

  • A shadow AI discovery report: which tools, which teams, what data
  • A data exposure assessment with risk ranked by consequence
  • An AI usage policy written to be read, not filed
  • Technical controls and DLP configuration for the tools in use
  • A sanctioned alternative, deployed and governed
  • Team training on safe use, plus a governance review cadence

Best fit when

  • Businesses whose staff are visibly using AI with no policy in place
  • Organisations handling client, health, student or financial data
  • Anyone about to face a client security questionnaire that now asks about AI

Frequently asked questions

Is our data safe if we use AI?

It depends entirely on which AI and how it is configured, which is the point of this service. Consumer tools on free tiers generally reserve broad rights over what you submit. Enterprise platforms typically offer materially better terms on training, retention, hosting location and access logging, but the terms differ by vendor, tier and configuration, and whether yours are set that way is a question worth answering rather than assuming. The gap between those two positions is where almost all real exposure lives.

Should we just block AI tools entirely?

We would advise against it, and we say that as people from the security side. Blanket blocks push usage onto personal devices and personal accounts, where you have no visibility and no logs at all. A sanctioned, governed alternative plus a clear policy gives you far better control than a ban that quietly does not hold.

How long does a Shadow AI check take?

Typically one to two weeks depending on the size of the environment and how much telemetry is already available. You get the discovery report and the exposure assessment at the end of it, and the decisions about controls follow from there.

We already have an IT provider and a security stack. Do we need this?

Possibly not for the controls, but usually yes for the assessment. Most Australian MSPs are excellent at endpoint and identity and have not yet built a practice around AI-specific exposure: which tool is seeing what data under whose terms. We work alongside your provider and hand the enforcement to them where that is the sensible split.

Does this help with client security questionnaires?

Directly. Enterprise clients and government buyers have started adding AI-specific questions to their vendor assessments: which tools you use, what data goes to them, what your policy is, whether AI-assisted work is reviewed. A completed governance engagement answers those questions with evidence instead of assurances.

More questions answered on the full FAQ.

Read next

Your team is already using AI. Can you see it?

Tell us about the process you'd point this at. Thirty minutes, no preparation, and a straight answer on whether AI Security & Governance is the right first move, or whether something else on the list is.

Book a discovery callSend an enquiry

Gold Coast · Brisbane · Australia-wide

Book a discovery call