Shadow AI: finding and controlling unsanctioned AI use
How Australian organisations discover unsanctioned AI tools, assess the real exposure, and bring shadow AI under governance without stopping useful work.
What shadow AI actually is
Shadow AI is any use of artificial intelligence inside an organisation that sits outside the sanctioned inventory: a consumer chatbot pasted with client data, a browser extension summarising contracts, an unapproved transcription tool on a laptop, a marketing agency running your material through a model you have never assessed, or a feature quietly switched on inside a SaaS product you already pay for.
The last category is the one most Australian organisations underestimate. Vendors increasingly enable AI assistants by default in CRM, service desk, HR and collaboration tools. No employee downloaded anything, no procurement decision was made, and yet organisational data is now being processed by a model under terms nobody reviewed.
Why it happens
We have yet to find a case that was malicious. It shows up where a real task is slow and a capable tool is one browser tab away. People are being asked to do more with the same headcount, and something that drafts a decent first response in twenty seconds is an obvious answer to that.
It also thrives whenever the sanctioned path is worse than the unsanctioned one. Lock the approved assistant to a pilot group, limit it to trivial use cases, or make the request take six weeks, and staff will route around it. Read each instance as unmet demand first and misconduct second.
The exposure, stated plainly
The first exposure is data. Personal information, client confidential material, unreleased financials or health records entering a consumer service can breach contractual obligations and, where individuals are identifiable and harm is likely, may fall within the Notifiable Data Breaches scheme under the Privacy Act.
The second is decision quality. Unverified model output that reaches a customer, a regulator or a court carries the organisation's name. Without review, provenance or a record of who accepted the output, there is no defensible account of how the decision was made.
The third is concentration and continuity. Teams build informal dependencies on tools with no contract, no support path and no exit plan. When the free tier changes or the extension is removed, work stops with no owner accountable for restoring it.
Discovery: four signals that find most of it
Network and proxy telemetry reveals traffic to known AI domains and API endpoints. It is the fastest first pass and it establishes scale — how many users, how often, from which business units.
Identity logs show OAuth grants and third-party application consents against your Microsoft 365 or Google Workspace tenant. This is where browser extensions and connected apps become visible, including those with broad mailbox or file permissions.
Expenditure data catches paid subscriptions on corporate cards and expense claims, which usually indicate sustained, serious use rather than experimentation.
Conversation completes the picture. A short, amnesty-framed survey asking teams which AI tools genuinely help them will surface local practice that no log captures — particularly on personal devices and in agency relationships. Ask what task the tool solves, not just which tool it is.
Triage rather than blanket blocking
Blocking every AI domain feels decisive on the day and rarely holds past the month. Usage moves to personal phones, and you lose visibility and control in the same afternoon. Classify what you found instead: how sensitive is the data, and how bad is a wrong answer?
Low sensitivity and low consequence — public content drafting, code snippets from open repositories, internal brainstorming — can usually continue on a sanctioned tool with light guidance. High sensitivity or high consequence — personal information, client confidential material, safety, credit, employment or eligibility decisions — needs to stop until it is assessed and moved onto a controlled path.
Publish the classification. Staff will comply with a rule they can apply themselves far more reliably than with an approval queue.
Want this assessed against your environment?
Send us the specifics and a senior advisor will respond within one business day.
Build the sanctioned path first
The durable control is a sanctioned tool that is genuinely better: enterprise terms that exclude training on your data, tenant-bound processing, identity-backed access, retention you control, logging you can audit, and coverage of the tasks people actually have.
Then remove the friction. Provide it broadly rather than to a pilot group of ten, publish worked examples for the top five tasks in each function, and make the request path a single form with a short turnaround. Adoption of the sanctioned path is the metric that predicts shadow AI decline — not the number of domains blocked.
Bring it into the management system
Discovered AI use should land in one AI inventory with an owner, a purpose, the data classes involved, the assessment status and the review date. ISO/IEC 42001 expects exactly this: a known set of AI systems inside a defined scope, each with accountable ownership and proportionate controls.
Where the use touches personal information, run the privacy assessment alongside the AI risk assessment rather than as a separate exercise. Where it touches a regulated decision, record the human oversight point and who holds it. The ACSC's guidance on engaging with AI is a useful baseline for the technical controls that sit underneath.
Governance that keeps up
Shadow AI is not a one-off cleanup. New tools ship weekly and existing vendors keep enabling features by default. Set a recurring discovery cycle — quarterly at minimum — and add an AI clause to vendor reviews so feature activation is a contractual notification event rather than a surprise.
Report two numbers upward and nothing else: sanctioned adoption, and unsanctioned detections. First rising while the second falls means it is working. Both rising means the sanctioned path still does not cover the work people actually have.
A 60-day sequence
Days 1 to 20 — see it. Run the four discovery signals, consolidate findings into a single inventory, and classify each use by data sensitivity and decision consequence.
Days 21 to 40 — stop the sharp edges. Halt the high-consequence uses, revoke over-permissioned third-party app grants, publish the classification rule and a plain-English acceptable use statement, and brief managers rather than only emailing staff.
Days 41 to 60 — make the right path the easy one. Roll the sanctioned tool out broadly with worked examples, move stopped use cases onto it where they are viable, set the quarterly discovery cadence, and report the two adoption numbers to the executive.
Sources and further reading
- ACSC Engaging with Artificial Intelligence guidance
- OAIC guidance on privacy and the Privacy Act
- ISO/IEC 42001 AI management systems
- Australian Signals Directorate Essential Eight
- OWASP Top 10 for Large Language Model Applications
This article provides general information and decision support. It is not legal advice, audit assurance, certification advice or a guarantee of outcome.
Related reading
Securing enterprise AI adoption: a practical AI security control set
The AI security controls that matter first — identity, data boundaries, model access, logging, human oversight and supplier assurance.
Read articleAI risk assessment: how to assess an AI system before it ships
A repeatable AI risk assessment covering purpose, data, model behaviour, integration, human oversight, failure modes and evidence.
Read articleISO 42001 vs ISO 27001: how the two management systems interlock
What each standard covers, where they overlap, and how to run one integrated management system instead of two parallel programmes.
Read article