top of page

How to Find Shadow AI Before It Finds You

Writer: Bruce Mullan
Bruce Mullan
Jul 16
5 min read

One employee ... one bad prompt ... one company-wide incident ... in one second.

Employees using ChatGPT, Copilot, Claude, Gemini and dozens of other AI tools without approval. Teams connecting AI into their email, spreadsheets, CRMs, procurement platforms and customer databases. Staff uploading sensitive information into AI systems that the organisation doesn't even know exist.


Melbourne Business School's 2025 trust-in-AI research: 60 per cent of Australian workers have concealed their AI use from their employer, and 48 per cent admit to breaching company policy by entering sensitive data into public AI tools.


This is the reality of Shadow AI.


And it is one of the fastest-growing governance risks facing every IT Department right now.

The problem isn't that people are using AI. In fact, that's a good sign if they are. They're trying to improve how they work. The problem is that IT have no visibility into how AI is being used, where sensitive data is going, or whether those AI tools meet security, privacy and compliance requirements.


You can't govern what you can't see.


Watch this 60 second video to understand how Shadow AI causes AI breaches.


When things go wrong

People only start looking for Shadow AI after something has already gone wrong. The witch-hunt starts with something like:


  • Some confidential information was entered into a public AI tool.

  • An employee relied on AI-generated advice that turned out to be incorrect.

  • Compliance asks for an inventory of AI systems.

  • The Board wants assurance that AI risks are being managed.

  • A customer, regulator or insurer asks what controls exist over AI.


Suddenly, all at once and needed yesterday, the same question is being asked by everyone:

"Where is AI actually being used?"


Unfortunately, very few CIOs or IT Managers can answer that question with confidence.


Why Traditional Controls Don't Work


  • Policies don't detect Shadow AI.

  • Training doesn't reveal where AI is being used.

  • Blocking websites encourages staff to use personal devices or alternative tools.


You are relying on assumptions instead of evidence, and without visibility, you have no control.


A Practical Four Step Framework

In practice, getting a handle on shadow AI doesn’t mean banning it. Try this four step framework:


  1. Understanding where and how it’s already used

  2. Setting clear policies and guardrails

  3. Providing secure, approved AI tools

  4. Training people on responsible and effective use


1. Understanding where and how Shadow AI is already used

When I deploy our Shadow AI Discovery platform, you get a clear picture of how AI is actually being used across the business. Rather than relying on surveys or self-reporting, our platform identifies ungoverned AI use, highlights where confidential information may be exposed, and maps AI activity across business units.


Watch this 3 minute demonstration to understand how it works.



The result is a living inventory of AI use cases, giving IT leaders the visibility they need to manage AI confidently. Instead of interrogating people with: "Do you use unapproved AI?"


You can start taking people on a proactive and collaborative journey:


"Which AI uses create the greatest value?"

"Which ones create unacceptable risk?"

"Where should we focus governance first?"


What You'll Discover

Our platform helps you identify:


  • Unapproved AI applications being used by employees

  • Departments with the highest AI adoption

  • AI use involving sensitive, personal or confidential information

  • High-risk AI activities requiring governance or human oversight

  • Duplicate AI tools creating unnecessary cost

  • Opportunities to replace risky public AI with approved enterprise solutions

  • Emerging AI trends before they become governance issues


Why Visibility Matters

Knowing where Shadow AI exists changes the conversation.


  1. Instead of reacting to incidents, you can proactively reduce risk.

  2. Instead of banning AI, you can safely enable it.

  3. Instead of creating policies based on assumptions, you can make evidence-based governance decisions.


Visibility allows you to prioritise education, strengthen controls, improve procurement decisions, protect sensitive information and demonstrate that AI risks are being actively managed.


The Business Benefits

Organisations with effective Shadow AI discovery processes gain:


  • Greater confidence that sensitive information is protected

  • Reduced privacy, cybersecurity and regulatory risk

  • A complete inventory of AI use cases to support governance obligations

  • Better Board reporting and executive assurance

  • More effective AI policies based on actual organisational behaviour

  • Lower software costs by identifying duplicate or unnecessary AI subscriptions

  • Faster adoption of trusted enterprise AI platforms

  • Stronger foundations for responsible AI governance


2. Set clear policies and guardrails

Set temporary “no‑go” boundaries and safe‑use guardrails: Clear statement on what must never be entered into external AI (e.g., personal data, confidential client info, trade secrets). Clarify that staff remain responsible for verifying AI outputs. Require manager approval for AI use in high‑risk decisions or regulated content.


Issue a short, practical AI acceptable‑use guidelines: One‑pager: “Do / Don’t” examples in plain language. Include specific approved tools (if any) and banned categories. Align with existing data protection, security, and conduct policies.


3. Provide secure, approved AI tools

Use enterprise AI platforms with audit logging. Move staff onto managed versions of tools such as ChatGPT Enterprise, Microsoft 365 Copilot and Gemini for Workspace.


Route usage through controlled entry points. For meaningful oversight, don’t chase every tool deploy a centralised, approved “AI portal” for staff


4. Training people on responsible and effective use

Reframe the culture. Reframe Shadow AI use as not a people problem. It is a signal. Every time you find a piece of Shadow AI, you have found a place where someone went BYO AI. You have to get inside people's heads that BYO AI is not OK. Staff need to know consciously where the boundaries are and where they drift into unapproved use, they can self-regulate.


Communications is ongoing. This not a once-off exercise. It's like going to church. The message must come from the top and be consistently reinforced every week.


Consequences. There are serious consequences for AI breaches. So should there be serious consequences for AI misuse by staff? Remember, you won't want to drive shadow AI further underground and you want people to be

open and transparent about what they are doing. See my point earlier on reframing the culture. 


From Invisible AI to Controlled Innovation

Invisible AI can quickly wreck a company's reputation, ruin IT careers and cost time and money in remediation.


You can't manage what you can't see. Now is the time to discover your Shadow AI.


The biggest AI risk to a CIO isn't the tools you've bought, it's the ones your employees are using in secret. When employees copy-paste sensitive company data or client information into unauthorised, free AI tools to speed up their work, your company faces immediate compliance and data privacy liabilities.


If you want to know how to uncover and secure "Shadow AI" without destroying employee productivity, let’s talk.


If you prefer a text response? Just DM me with the words "SHADOW AI" and I’ll send you my detailed 4-step Internal Discovery Framework.


Stay safe,


Bruce

AI. Use responsibly.


ABOUT ME

I partner with mid-size companies to confidently adopt AI, prevent high-profile failures and avoid the expensive mistake.


I write all my own content, you can tell by the odd typo and occasional missing word. I use AI for my research.


To learn about my upcoming public AI Governance workshops visit: Public workshops


To learn more about AI Governance, check out my Hitchhikers Guide to AI Governance Podcast.



Bruce Mullan hosts Hitchhikers Guide to AI Governance podcast
Bruce Mullan hosts Hitchhikers Guide to AI Governance


 
 
 

Comments


CONTACT

If you have a question or request  please contact us today!

© 2026 BY TRIPLE P GLOBAL PTY LTD T/AS Ai Governance Partners -

ABN 96 119 485 791

Thanks for contacting us. we'll be in touch.

bottom of page