What is shadow AI?

Shadow AI isn't a technical problem and it isn't really a compliance problem. It's what happens when a tool is obviously useful, easy to reach, and officially unavailable. People don't stop needing the help; they stop mentioning it.

Why capable people do it

It's worth being clear that this is rarely defiance. The pattern looks like:

Each step is individually reasonable. That's exactly why prohibition performs so badly — you're asking someone to work an extra eighty-five minutes to comply with a rule that, from where they're standing, protects nothing visible.

What it actually costs you

An Australian small-business example

A Canberra consultancy working on government contracts bans AI outright, for understandable reasons. No tool is provided and no policy is written beyond the ban.

Eighteen months later an informal conversation reveals that most of the delivery team uses AI daily — on personal accounts, on personal devices, for drafting and summarising client material.

The ban achieved the opposite of its intent. The firm now has the same usage it feared, with none of the controls it could have had, and no idea what has been shared or with which service.

What actually works

The reframe

Shadow AI is usually described as a discipline problem. It's more useful to read it as feedback: staff have found something that materially helps, and the organisation hasn't caught up.

Treated that way, it's not a threat to shut down but a signal about where the demand is. The businesses that act on it end up with better controls and better adoption than the ones that keep tightening a rule nobody is following.

Frequently asked questions

How common is it really?
Common enough that assuming it isn't happening is the riskier position. If your staff have deadlines, personal phones and free tools within reach, some of them are using AI. The only variable is whether you know.
How do we find out?
Ask, without consequences attached. An amnesty question — 'what are you already using, and what for?' — gets far better information than monitoring, and the answers usually point straight at what you should be providing.
Isn't monitoring the answer?
Blocking domains pushes usage to phones, where you have no visibility at all. Detection has a role, but on its own it converts a manageable problem into an invisible one.
What's the actual harm?
Client information on tiers that may train on it, no record of what was shared, work stored in accounts you can't access, and no consistency in how output is checked. Any one is manageable; together they're a genuine exposure.
We already banned it. What now?
Replace the ban with an approved tool and a one-page policy, and say plainly that the previous position didn't work. Staff who've been quietly using AI will tell you far more once it isn't an admission of wrongdoing.

Put this to work

Ad On Group runs AI training and enablement for Australian teams through Ad On AI — a three-month, self-paced program that takes non-technical staff from their first prompts to working AI agents.

Talk to us →

Keep reading

← All resources