top of page

Shadow AI: Your Business Is Already Using AI. Do You Know Where?

Sep 2
10 min read
Laptop dashboard showing an AI use inventory across sales, meetings, marketing, finance and customer service, categorised as keep, control, stop or scale.
An AI inventory turns scattered experimentation into something a business can see, assess and manage.

Ask a business owner how their company is using AI and you might hear:


“We’re not really using AI yet.”

But look a little closer.


Someone in sales is using ChatGPT to improve a proposal before it goes to a customer. Marketing is using an AI feature built into a platform the business already pays for. Meetings are being recorded and summarised by an AI transcription service. Someone in finance is asking an AI assistant to help make sense of a spreadsheet. An employee receives a difficult customer email, pastes it into an AI tool and asks for help drafting a response.


None of these things required an AI strategy. There was no transformation program. No implementation project. No formal decision to “adopt AI.”


But the business has adopted AI anyway.


This kind of informal or unapproved use is increasingly described as shadow AI. And for many businesses, it may be their first real stage of AI adoption.


The immediate reaction can be to see shadow AI as a governance problem that needs to be stopped. Sometimes it does. But it can tell you something else as well.


It can show you where people have already found ways for AI to make their work easier.


Before deciding what AI, your business should buy, build or ban, it is worth finding out what is already happening.



Shadow AI Is Already Part of How Work Gets Done

AI adoption hasn’t waited for formal AI strategies.


Microsoft and LinkedIn’s 2024 Work Trend Index found that 84% of Australian knowledge workers surveyed were using generative AI at work. Among Australian AI users, 78% said they were bringing their own AI tools to work.


More recent Australian research points to the same bottom-up pattern. In 2025, the Reserve Bank of Australia interviewed 105 Australian firms about technology investment and AI. It found that adoption was often relatively piecemeal and employee-led rather than employer-led.


The RBA sample was weighted towards larger, established firms, so its adoption levels shouldn’t be treated as representative of Australian small businesses. But the behaviour it identified is important.


We tend to imagine technology adoption happening from the top down: a business identifies a requirement, evaluates products, approves a purchase, implements the technology, trains employees and then adoption begins.


Generative AI can reverse that sequence.


An employee encounters an AI tool, tries it on a problem and discovers it works. Then they try it again. Before long, AI is part of how they perform a particular task, even though nobody has formally changed the business process.


Australia’s National AI Centre now warns organisations that, whether they have an approved AI policy or not, some staff are likely already using AI at work without management knowing.


That doesn’t necessarily mean employees are doing something reckless. It means the barrier to adopting AI has become incredibly low.


And that makes visibility the first operational challenge.



AI Can Enter Your Business Without Anyone “Adopting AI”

Shadow AI isn’t just an employee secretly using ChatGPT.


AI can enter a business in several ways.


The most obvious is through direct AI tools. Someone creates an account with ChatGPT, Claude, Gemini, Copilot or another AI service and starts using it for work.


But there is another route that is becoming increasingly important: AI embedded inside software the business already uses.


Productivity software, meeting platforms, marketing applications, CRM systems, design tools, customer-service platforms and other SaaS products increasingly include AI capabilities. A business can therefore gain new AI functionality without making a separate decision to adopt an AI product at all.


Then there are employee-created AI workflows. This happens when someone moves beyond occasional prompting and develops a repeatable way of using AI to complete part of their job.


A salesperson might take notes from a customer meeting, ask AI to summarise the customer’s requirements, generate a first draft of a proposal, improve the language, review it and send it to the customer. There may be no formal automation involved. But AI has become part of a real business process.


If you ask your team, “Does anyone use ChatGPT?” you will discover some of your AI footprint.


A much better question is: “Where does AI touch the work in our business?”



The Tool Isn’t the Most Important Thing to Discover

Imagine two employees both tell you they use the same AI assistant.


The first uses it to brainstorm generic ideas for social media posts. The second pastes customer records into it and asks the model to analyse which customers are likely to buy a particular service.


Same technology. Very different data. Very different purpose. Very different consequences if something goes wrong.


Simply creating a list of AI tools therefore isn’t enough.


What you really want to understand is: Tool Data Task Output Destination.


Take a customer email as an example. An employee receives an unhappy customer message, pastes it into an AI assistant and asks it to draft a professional response. They review and edit that response before sending it to the customer.


Now we can see the actual AI use and ask useful questions. Did the original email contain personal or confidential information? What happens to information entered into the AI service? Is the employee using a personal account or an organisation-managed account? Is the AI response always reviewed before being sent? Could the AI make a commitment to the customer that the business didn’t intend to make?


What initially looked like “someone uses AI” has become a business process we can actually evaluate.


The Office of the Australian Information Commissioner recommends that organisations conduct due diligence before using commercially available AI products, including understanding who may have access to personal information entered into or generated by those systems.


The OAIC also recommends, as a matter of best practice, that organisations do not enter personal information, particularly sensitive information, into publicly available generative AI tools because of the privacy risks involved.


The risk isn’t simply that someone is using AI. It depends heavily on what they are giving it and what they do with the answer.



Don’t Start by Banning Shadow AI. Start by Understanding It.

Once a business discovers employees are using unapproved AI tools, the instinct can be to shut everything down until a policy is written.


There will certainly be cases where an AI use should stop immediately. Sensitive information being entered into an unsuitable public AI service is an obvious example.


But treating every case of shadow AI as employee misconduct can create another problem: people stop telling you what they are doing.


The National AI Centre recommends making it safe for employees to disclose their use of AI. Its guidance notes that shadow AI can signal unmet needs, time pressure or curiosity from early adopters.


Suppose someone on your team discovers that a repetitive weekly administrative task that normally takes two hours can be completed in 30 minutes with AI assistance.


You could simply ban the tool. Or you could ask: “What problem have they actually solved?”


Perhaps the particular AI service isn’t appropriate. Perhaps the data being entered needs to be restricted. Perhaps the output needs stronger human review. Those things can be addressed.


But underneath them may be a perfectly valid AI use case. The employee has effectively conducted a small experiment for the business.


The question is what the business should do with what they have discovered.



Run a Simple AI Discovery Exercise

You don’t need a large governance program to start getting visibility. For a small business, a spreadsheet may be enough.


Talk to the people doing the work and capture nine things for every AI tool, feature or workflow you discover:


Tool: What AI tool or AI-enabled feature are you using?

Purpose: What are you trying to accomplish with it?

Data: What information do you give it?

Output: What does it produce?

Destination: Where does that output go next?

Review: Does someone check the result?

Value: What time, cost or effort does it save?

Impact: What happens if the AI gets it wrong?

Owner: Who is responsible for this use?


Don’t limit the exercise to standalone AI products. Ask about AI features inside software people already use, personal AI accounts used for work, meeting transcription and summarisation, drafting emails and proposals, analysing spreadsheets and documents, and repeatable AI workflows.


Most importantly, don’t conduct the exercise as an investigation into wrongdoing. You are trying to understand how work is changing.


The result is the beginning of an AI systems register.


The National AI Centre recommends maintaining a register of the AI systems an organisation uses, including their use cases, accountable people and appropriate governance level. Importantly, its guidance says the register should include AI features embedded in common software packages, not just standalone AI products.


For a small business, the first version doesn’t need to be complicated. You just need enough information to answer: “Where are we using AI, why are we using it, and what does it touch?”



Pay Particular Attention to the Information Going Into AI

During discovery, don’t just look at what people are asking AI. Look at the context they’re providing to get the answer.


An employee might paste in a customer complaint, a contract, a sales pipeline, financial information, employee performance notes, meeting transcripts, internal strategy documents, supplier correspondence, source code or customer records.


Often this isn’t done carelessly. The employee is trying to get a better result.


AI becomes substantially more useful when it has relevant context. If you want an AI assistant to improve a proposal, giving it the actual proposal will usually be more useful than describing the proposal.


That creates a tension. The same context that makes AI useful can contain information the business needs to protect.


Australian cyber security guidance for small businesses warns specifically about accidental data leakage through cloud-based AI tools, unauthorised access to sensitive customer information and the handling of customer data by third-party AI providers.


This is why a useful AI inventory needs to show more than which tools people use. It needs to show what information flows through them.



Classify What You Find: Keep, Control, Stop or Scale

Discovery is useful only if it leads to a decision. You don’t need a complicated risk framework for the first pass. Every use you discover can initially go into one of four categories.


Keep

The use is helpful and relatively low risk. Someone might use an AI assistant to brainstorm generic ideas, improve the wording of non-sensitive material or explain a technical concept. There is little reason to create unnecessary friction around useful, low-risk behaviour. Keep it.


Control

The use has value, but it needs clearer boundaries. Perhaps employees should use an organisation-managed account rather than a personal one. Perhaps certain types of information shouldn’t be entered. Perhaps AI-generated material needs human review before being published or sent to a customer. The goal isn’t to eliminate the use. It’s to make it safer and more repeatable.


Stop

Some uses won’t be acceptable in their current form. The data may be too sensitive, the consequences of an incorrect output may be too high, the tool may not provide appropriate protections, or AI may simply be the wrong solution. Those uses should stop until there is a safer approach.


Scale

This is the category businesses can easily miss. Sometimes shadow AI reveals a genuinely valuable use case.


An employee may have found a way to reduce a repetitive two-hour process to 30 minutes. Several people may independently be using AI to extract information from the same type of document. A sales team may be using AI to turn meeting notes into follow-up actions.


Those patterns are signals. Rather than leaving the capability inside someone’s personal workflow, the business can ask whether it should become an intentional business process.


That might mean an approved AI platform, connecting AI securely to business information, creating a standard workflow, or eventually building an AI agent or automation. But the technology comes later.


First, you have discovered a problem worth solving.



Shadow AI Can Show You Where to Invest

This is the part of shadow AI that gets lost when the conversation focuses entirely on risk.


Your employees are close to the work. They know which tasks are repetitive, where information is difficult to find, which reports take hours to assemble and which customer interactions consume unnecessary time. Increasingly, some of them are experimenting with AI to solve those problems.


Imagine discovering that three people independently use AI every week to summarise long documents. The immediate question might be: “Should they be allowed to use that AI tool?”


But there is another question: “Why do three people need to summarise these documents every week?”


That may reveal the more valuable AI opportunity.


Or perhaps your sales team regularly uses AI to turn meeting notes into follow-up emails. Again, the interesting discovery isn’t necessarily the tool. It’s that your sales process contains a repetitive transition between a conversation and a set of administrative tasks.


Shadow AI can therefore reveal both sides of the same equation: where unmanaged risk exists and where genuine demand for AI already exists.


You need visibility to see either.



From AI Experiment to AI Operations

There is a tendency to begin AI strategy with technology. Which model should we use? Should we buy an AI assistant? Do we need an AI agent? Should we automate this process?


Those questions matter eventually. But they may not be the best place to start.


Before deciding what AI your business needs tomorrow, find out what AI it is using today.


Talk to the people doing the work. Find the tools. Find the embedded AI features. Find the informal workflows. Understand the information going into them and what happens to the output. Look at what is creating value. Look at what creates risk.


Then decide what should be kept, controlled, stopped or scaled.


This turns AI adoption from something happening invisibly across the business into something you can make deliberate decisions about.


And that is the first important shift from AI experiment to AI operations.


The first question isn’t necessarily: “What should we build?”


It may simply be: “What are we already doing?”



References


This article was written by Keith Jenneke, Principal Consultant at Cypher Agency. Keith leads Cypher's Data, Integration, and AI Engineering practice, building governed Modern Data Platforms that make data reliable, integrated, and analytics- and AI-ready, delivered across professional services, resources, and government sectors in Australia.


Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
bottom of page