There's a decent chance someone on your team pasted a client contract, a spreadsheet of financials, or a chunk of source code into a free AI chatbot this week to "just tidy it up" or "summarise it quickly." Nobody asked IT. Nobody flagged it as a data handling decision. It felt exactly as low-stakes as using spellcheck.
This pattern has a name now: Shadow AI, the AI equivalent of Shadow IT, staff quietly adopting AI tools and features that were never assessed, approved or governed by the business. Unlike a rogue app someone installed, Shadow AI often doesn't even feel like installing software. It's a tab in a browser, a feature already built into an app you already use, or an extension someone added in thirty seconds.
What Shadow AI Actually Looks Like
In practice, it's rarely one dramatic incident. It's small, well-intentioned moments that add up:
- Pasting a client's personal or medical details into a chatbot to draft a follow-up email
- Uploading a spreadsheet of pricing, payroll or financial data to "analyse the trends"
- Dropping a chunk of proprietary code into an AI tool to debug it
- A browser extension with an AI "summarise this page" feature quietly reading whatever's open, including internal systems
- Using a personal, free-tier AI account for work tasks because it's faster than asking IT to set up a business one
None of this is malicious. It's usually the opposite, staff trying to work faster and smarter with tools that are genuinely useful. That's exactly what makes it hard to stop with a policy memo alone.
Why This Is a Real Data Security Problem
The core issue is that not all AI tools handle data the same way, and most staff have no way of knowing the difference. Free, consumer-tier AI accounts often reserve the right to use submitted content to train future models, and it's rarely possible to guarantee that data has been fully deleted once it's been sent. Business and enterprise tiers of the same tools typically come with contractual guarantees against training on your data, but only if the business has actually set those up, and staff are actually using them.
⚠️ Once information is submitted to a consumer AI tool, your business generally loses control over where it goes. For businesses handling client health information, financial records or anything covered by the Australian Privacy Act, that's not a hypothetical risk, it can be a reportable data breach.
There's a second, quieter risk too: confidentiality obligations. Client contracts, NDAs and professional conduct rules often require certain information to stay within defined systems. An employee pasting a draft contract into a public AI tool to "polish the wording" can breach that obligation without anyone intending harm.
Why Banning AI Outright Doesn't Work
The instinctive response is to ban AI tools altogether. In practice, this almost always backfires. AI tools save real time, and staff who find them useful will keep using them on personal devices or personal accounts, just further out of view. A flat ban doesn't remove the risk, it removes your visibility into it.
The more effective approach treats this the same way businesses learned to handle Shadow IT: give people a sanctioned, secure option that's genuinely as convenient as the unsanctioned one, so there's no reason to go around it.
What to Actually Do About It
-
1
Write a short, practical AI use policy Not a 20-page document nobody reads. A one-page guide: which tools are approved, what data categories must never be pasted into an AI tool (client personal information, financials, source code, anything under NDA), and who to ask when unsure.
-
2
Roll out a sanctioned business-tier AI tool Microsoft 365 Copilot, Claude for Work, or a business-tier ChatGPT plan all come with data protection commitments that free consumer tiers don't. Once staff have a fast, approved option, the incentive to reach for an unapproved one drops sharply.
-
3
Get visibility into what's actually being used Most businesses are surprised by how many AI browser extensions and tools are already active across the team. A quick audit of installed extensions and sanctioned app usage tells you where you actually stand, before you write a policy for a problem you haven't measured.
-
4
Train staff on what "sensitive" actually covers Most people have never been told that a spreadsheet of client emails counts as personal information under the Privacy Act. A short, plain-English briefing does more than a policy document sitting in a shared drive nobody opens.
-
5
Review this as your Essential 8 and access control posture evolves AI use isn't a one-off project, new tools and features appear constantly. Treat it as an ongoing part of your security review, not a policy you write once and forget.
💡 Curious which AI tool actually fits your business? Our earlier comparisons of Claude vs ChatGPT and Microsoft Copilot vs ChatGPT cover pricing, data handling and business fit in plain English.
The Bigger Picture
AI tools aren't going away, and for most businesses, they shouldn't. Used well, they're a genuine productivity gain. The businesses that get into trouble aren't the ones using AI, they're the ones who never decided how it should be used, leaving that decision to whoever's browser tab is open at 4pm on a Friday. A short policy, a sanctioned tool and a bit of visibility closes most of the gap.
Not sure what AI tools are already active across your business, or how to roll out a sanctioned option properly? BITS can run a quick audit and help you set up Microsoft 365 Copilot or another business-tier AI tool the right way. Book a free consultation and we'll walk you through it.