The Rising Threat of Shadow AI (and what businesses should do about it!)

The Rising Threat of Shadow AI an icon of a person uploading a secure document to AI oblivious to the warning signs

1 in 3 workers are secretly using AI, and that’s a major risk for Australian businesses.

Right now, there's a good chance that someone in your business is pasting a client contract into the free version of ChatGPT or Claude to “tidy up the wording”.   Or, perhaps they're dropping a spreadsheet of customer data into another free AI tool to build a quick summary for their manager. Or, maybe they're using their personal AI account to draft a detailed proposal to send to a new client, because it's faster than using the CRM tools at work….

While seemingly innocuous, chances are, the employee is not aware that the data is being stored, transformed and potentially shared with the world. Some may even be hoping they get away with it “because everyone does it”.

But this presents a significant problem for businesses. They don’t know which data is being shared, which tools are being used, and who is sharing their secrets with the world. The lack of transparency and visibility has given rise to a new intellectual property and cybersecurity threat:  Shadow AI.

The Shadow AI threat is real

Shadow AI is a term referring to the unauthorised use of artificial intelligence tools or models by employees without the permission or oversight of an organisation's IT or security teams.  Employees often adopt these free, third-party services to boost productivity, inadvertently exposing corporate intellectual property and violating data compliance rules when they paste sensitive work data into these public platforms.

The extent of the problem was recently brought to light with research from Employment Hero, covered recently by IT Brief Australia which revealed that roughly one in three workers admit they're using AI at work without their employer knowing.

Furthermore, almost half of Australian businesses reported staff using personal AI accounts for work tasks, presenting an amorphous threat.

Why shadow AI is a cybersecurity problem, not just an HR one

We've seen this pattern of “shadow IT” usage before; staff signing up for their own cloud storage, their own file-sharing tools, their own apps, survey tools, software, email platforms etc creating some murkey areas for the transfer of data and ownership,

With shadow AI, the stakes are higher, because AI tools don't just store data - they ingest it, learn from it, and in many cases, retain it on servers you have no visibility over, no contract with, and no control over!

When an employee pastes commercially sensitive information, personal customer data or intellectual property into a free, personal AI account:

  • You lose control of where that data lives. Free AI tools often use uploaded content to train future models, and their data retention and privacy terms are rarely built with your compliance obligations in mind.

  • You lose your audit trail. If a data breach or privacy complaint lands on your desk, "we’re not sure what was shared, how, or when" is not a position any Australian business wants to be in, especially with Privacy Act reforms tightening obligations around data handling.

  • You lose consistency. Different staff using different tools in different ways means there’s no single standard for how AI-assisted work gets checked, verified or secured.

  • You create a licensing and liability grey area. Like all shadow IT, personal AI accounts sit outside your business's contracts, terms of service and indemnities. If something goes wrong, you may have very little legal or contractual protection.

So, what should a responsible Australian business do about shadow AI?

Prohibition has never worked, so we don't think the answer is to ban AI and hope for the best. Staff will simply go further underground with it, and you'll lose visibility altogether. The best solution is to bring shadow AI use into the light, providing some parameters, guardrails and structure behind it.

Consider these 5 steps to bring AI out of the shadows in your business.

1. Conduct a Systems Review. Before you can govern AI use, you need to know what's actually happening in your environment. We help businesses audit which AI tools staff are already using AI tools, sanctioned or not and identify where sensitive data may already be exposed. We can do this in a way that is sensitive

2. Develop an AI Policy. This should be a clear, plain-English policy that tells your people what AI tools are approved, what data can and can't be shared with them, and how to use AI responsibly in their day-to-day roles. Done well, this removes the uncertainty and fosters product and safe use to give staff the confidence to use AI openly instead of quietly.

3. Implement approved AI licensing. Enterprise-grade AI tools (such as Microsoft Copilot or Gemini) come with data handling, privacy and security commitments that free consumer tools simply don't offer. Moving your team onto licensed, business-grade AI tools also closes the biggest gap between "convenience" and "compliance." If they are going to use Claude, ChatGPT or Grok, licensing will go a long way to ensure privacy controls can be uniformly activated and controlled.

4. Cyber security controls built around AI use. This includes access controls, monitoring, and safeguards that reflect how your team actually works, aligned with frameworks like the ACSC Essential Eight, so AI adoption strengthens your security posture rather than undermining it.

5. Perform regular auditing and compliance procedures. An AI policy is only as good as your ability to check that it's being followed. We help businesses activate ongoing auditing and review processes in place, so AI governance becomes an active part of how the business operates and remains cyber secure.

Businesses have a responsibility to manage their staff’s use of AI

Your staff aren't trying to cause a breach. They're trying to do their jobs better, faster, and with the tools they know work. The businesses that get ahead of this won't be the ones that clamp down hardest; they'll be the ones that give their people clear, secure, well-governed ways to use AI with confidence.

If you’re not sure what AI tools are already in use across your business and need help with your AI Policy, get in touch with the IT Strategic team today.

IT Explainer