All insights
AI security & compliance5 min read

Shadow AI: finding and controlling unsanctioned AI use

How Australian organisations discover unsanctioned AI tools, assess the real exposure, and bring shadow AI under governance without stopping useful work.

By FORTE/CYBERx AdvisoryReviewed by FORTE/CYBERx Advisory14 August 2026

What shadow AI actually is

Shadow AI is any use of artificial intelligence inside an organisation that sits outside the sanctioned inventory: a consumer chatbot pasted with client data, a browser extension summarising contracts, an unapproved transcription tool on a laptop, a marketing agency running your material through a model you have never assessed, or a feature quietly switched on inside a SaaS product you already pay for.

The last category is the one most Australian organisations underestimate. Vendors increasingly enable AI assistants by default in CRM, service desk, HR and collaboration tools. No employee downloaded anything, no procurement decision was made, and yet organisational data is now being processed by a model under terms nobody reviewed.

Why it happens

We have yet to find a case that was malicious. It shows up where a real task is slow and a capable tool is one browser tab away. People are being asked to do more with the same headcount, and something that drafts a decent first response in twenty seconds is an obvious answer to that.

It also thrives whenever the sanctioned path is worse than the unsanctioned one. Lock the approved assistant to a pilot group, limit it to trivial use cases, or make the request take six weeks, and staff will route around it. Read each instance as unmet demand first and misconduct second.

The exposure, stated plainly

The first exposure is data. Personal information, client confidential material, unreleased financials or health records entering a consumer service can breach contractual obligations and, where individuals are identifiable and harm is likely, may fall within the Notifiable Data Breaches scheme under the Privacy Act.

The second is decision quality. Unverified model output that reaches a customer, a regulator or a court carries the organisation's name. Without review, provenance or a record of who accepted the output, there is no defensible account of how the decision was made.

The third is concentration and continuity. Teams build informal dependencies on tools with no contract, no support path and no exit plan. When the free tier changes or the extension is removed, work stops with no owner accountable for restoring it.

Discovery: four signals that find most of it

Network and proxy telemetry reveals traffic to known AI domains and API endpoints. It is the fastest first pass and it establishes scale — how many users, how often, from which business units.

Identity logs show OAuth grants and third-party application consents against your Microsoft 365 or Google Workspace tenant. This is where browser extensions and connected apps become visible, including those with broad mailbox or file permissions.

Expenditure data catches paid subscriptions on corporate cards and expense claims, which usually indicate sustained, serious use rather than experimentation.

Conversation completes the picture. A short, amnesty-framed survey asking teams which AI tools genuinely help them will surface local practice that no log captures — particularly on personal devices and in agency relationships. Ask what task the tool solves, not just which tool it is.

Triage rather than blanket blocking

Blocking every AI domain feels decisive on the day and rarely holds past the month. Usage moves to personal phones, and you lose visibility and control in the same afternoon. Classify what you found instead: how sensitive is the data, and how bad is a wrong answer?

Low sensitivity and low consequence — public content drafting, code snippets from open repositories, internal brainstorming — can usually continue on a sanctioned tool with light guidance. High sensitivity or high consequence — personal information, client confidential material, safety, credit, employment or eligibility decisions — needs to stop until it is assessed and moved onto a controlled path.

Publish the classification. Staff will comply with a rule they can apply themselves far more reliably than with an approval queue.

Apply this to your organisation

Want this assessed against your environment?

Send us the specifics and a senior advisor will respond within one business day.

Native secure submission. Your details are never sold or shared.

Build the sanctioned path first

The durable control is a sanctioned tool that is genuinely better: enterprise terms that exclude training on your data, tenant-bound processing, identity-backed access, retention you control, logging you can audit, and coverage of the tasks people actually have.

Then remove the friction. Provide it broadly rather than to a pilot group of ten, publish worked examples for the top five tasks in each function, and make the request path a single form with a short turnaround. Adoption of the sanctioned path is the metric that predicts shadow AI decline — not the number of domains blocked.

Bring it into the management system

Discovered AI use should land in one AI inventory with an owner, a purpose, the data classes involved, the assessment status and the review date. ISO/IEC 42001 expects exactly this: a known set of AI systems inside a defined scope, each with accountable ownership and proportionate controls.

Where the use touches personal information, run the privacy assessment alongside the AI risk assessment rather than as a separate exercise. Where it touches a regulated decision, record the human oversight point and who holds it. The ACSC's guidance on engaging with AI is a useful baseline for the technical controls that sit underneath.

Governance that keeps up

Shadow AI is not a one-off cleanup. New tools ship weekly and existing vendors keep enabling features by default. Set a recurring discovery cycle — quarterly at minimum — and add an AI clause to vendor reviews so feature activation is a contractual notification event rather than a surprise.

Report two numbers upward and nothing else: sanctioned adoption, and unsanctioned detections. First rising while the second falls means it is working. Both rising means the sanctioned path still does not cover the work people actually have.

A 60-day sequence

Days 1 to 20 — see it. Run the four discovery signals, consolidate findings into a single inventory, and classify each use by data sensitivity and decision consequence.

Days 21 to 40 — stop the sharp edges. Halt the high-consequence uses, revoke over-permissioned third-party app grants, publish the classification rule and a plain-English acceptable use statement, and brief managers rather than only emailing staff.

Days 41 to 60 — make the right path the easy one. Roll the sanctioned tool out broadly with worked examples, move stopped use cases onto it where they are viable, set the quarterly discovery cadence, and report the two adoption numbers to the executive.

Sources and further reading

This article provides general information and decision support. It is not legal advice, audit assurance, certification advice or a guarantee of outcome.

Related reading

Start a useful conversation

Talk to a senior advisor

Tell us the decision, constraint or opportunity. A senior operator responds within one business day.

Native secure submission. No embedded HubSpot branding.