Shadow AI: How to Identify and Govern AI Use Across Your Organisation
- Gillian Howard
- Jul 8
- 4 min read

Ask a leadership team how their organisation uses AI and you'll get a tidy answer about pilots and approved tools. Ask the staff, anonymously, and a different picture emerges. Contracts summarised in public chatbots, client emails drafted by free AI tools, meeting recordings transcribed by browser extensions nobody vetted, spreadsheet formulas debugged by pasting company data into whatever model was open in another tab.
This is shadow AI, the use of AI tools without organisational knowledge, approval, or oversight, and in most organisations, it is not an edge case. It is the dominant form of AI adoption. Industry surveys consistently find that a large share of employees use AI tools at work without telling anyone, and that a meaningful portion have entered sensitive company information into them.
Why shadow AI happens (and why bans backfire)
Shadow AI is not a discipline problem; it's a demand signal. These tools genuinely make work faster, and staff reach for them for the same reason they once reached for personal Dropbox accounts and unsanctioned SaaS: the official path is slower than the unofficial one. That history also tells us how the story ends if you respond with a blanket ban, usage doesn't stop, it just moves to personal devices and personal accounts, where you have even less visibility and zero control. The organisations that handle shadow AI well treat it as adoption to be channelled, not behaviour to be punished.
What's actually at risk
Shadow AI Risk clusters into four areas. Data leakage is the most immediate: personal information, client-confidential material, and commercially sensitive data entered into public AI tools may be retained, used for training, or exposed, and under the Privacy Act, "a staff member pasted it into a chatbot" is not a defence an Australian organisation wants to test. Quality and accountability come next: AI outputs containing errors or fabrications flow into client advice, reports, and decisions with no human checkpoint and no record of AI involvement. Then there's legal exposure around confidentiality undertakings, professional obligations, and intellectual property in both inputs and outputs. And finally, concentration: critical workflows quietly become dependent on free consumer tools that can change terms, degrade, or disappear without notice.
A 30-day plan to identify and better govern shadow AI
The first step is discovery, and the tone you set determines what you find. Run a short, genuinely amnesty-based survey asking what AI tools people use and for what. Pair it with whatever technical visibility you have, network logs, browser extension inventories, SSO and expense records, because surveys understate and logs lack context; together they triangulate. Expect the list to be two to three times longer than anyone predicted.
The second step is triage. Not all shadow AI is equal. Sort what you find by two questions: what data does it touch, and does it influence decisions about people or clients? A tool that rewords internal emails is a different animal from one summarising client files or screening candidates. This risk-based sorting is what lets you avoid the trap of treating everything as equally forbidden.
The third step is to give people a sanctioned path. Approve a small set of tools, ideally enterprise versions with data protections, where inputs aren't used for training, and publish a one-page acceptable use policy in plain language: these tools are approved, these uses need sign-off, this data never goes into any external AI. Staff follow rules they can remember.
The final step is to make it stick: a lightweight approval route for new tools (if requests take weeks, shadow AI returns), short practical training built around your policy, and a standing AI inventory so the picture you just built doesn't decay. From there, periodic re-discovery becomes routine hygiene rather than a crisis response.
Shadow AI is a governance symptom
Just as unauthorised SaaS purchases made with a credit card can lead to inefficiencies and cost blow outs. Our clients have discovered notable cost savings by assessing their organisation's shadow AI. By providing approved AI solutions, they enhance both personal and operational efficiency, ensuring that the benefits of governance outweigh the cost and risks of unregulated usage.
Here's the deeper point: shadow AI flourishes precisely where AI governance strategies are absent. Organisations with a named owner, a clear policy, approved tools, and a fast approval path experience significantly less shadow AI, not because staff are more obedient, but because the sanctioned path is effective enough that the shadow one isn't worth the risk.
If you want to know how exposed your organisation is, start by measuring your governance posture. Our free AI Governance Maturity Assessment takes five minutes, covers shadow AI's root causes directly, inventory, data rules, approval paths, and gives you the three priorities that matter most for your stage for effective AI risk mitigation.
And if the results are confronting, that's useful information. H & M Enterprise Solutions helps organisations run AI discovery, build acceptable use policies that staff actually follow, and stand up right-sized governance, with deep expertise in the privacy obligations that make shadow AI such a live risk for Australian organisations.
H & M Enterprise Solutions
Insights. Integrity. Innovation.



Comments