Shadow AI at Work: What To Do Before You Ban the Tool
Two thirds of office professionals have used AI at work they believed was not permitted. Roughly half faced a warning or disciplinary action. The behaviour is still there. Contain the data first, then find the broken process underneath.
26 Aug 2026 · 10 Mins read

A support officer at a 30-person logistics firm has eleven customer complaints in the queue and a phone that will not stop. One of the complaints runs four paragraphs and contains a name, an address, an invoice number and an accusation.
She opens a personal AI account on her phone, pastes the complaint in, and asks for a draft reply. She gets one in nine seconds. It is good. She sends it.
Nobody approved this. Nobody will hear about it. And the business has just learned something useful about itself, if anyone is willing to read it.
The short answer
If staff are using AI tools you did not approve, do two things in this order.
Deal with the data first. Work out what information went into which tool, on whose account, and whether it included customer or employee personal information. Australia's privacy regulator recommends that organisations do not put personal information into publicly available generative AI tools at all, so this is the part that carries real exposure.
Then read the workaround before you remove it. An employee who reaches for an unapproved tool has shown you where your official process is too slow, too manual, or missing. Ban the tool and you keep the broken process, plus you push the behaviour somewhere you cannot see it.
After that, choose deliberately between three responses: govern it, redesign it, or automate it. Most businesses skip to a policy memo, which is none of the three.
What counts as shadow AI
Shadow AI is any use of an AI tool inside your business that sits outside your approved systems and oversight. Personal ChatGPT, Claude or Gemini accounts. Free web tools. Browser extensions. An AI note-taker quietly joining client calls. A meeting summariser nobody registered.
One point catches Australian businesses off guard. The OAIC's AI guidance adopts the definition of a deployer used in the federal government's AI work: any individual or organisation that supplies or uses an AI system to provide a product or service. Deployment can be internal. If your organisation is using AI to provide a product or service, including internally, you are a deployer.
Deployer is a descriptive category rather than a legal status that creates obligations on its own. Internal use still counts as deployment. Whether the Privacy Act applies to your business, and what it requires of a particular use, depends on the organisation and the information involved. Both questions are answered further down.
The scene at the top of this article is illustrative. The OAIC's guidance, however, contains its own worked example, and it runs close to the same ground. Under the heading asking whether an organisation can enter personal information into a publicly available generative AI chatbot, the regulator describes employees at an insurance company entering a customer's claim details, including sensitive health information, and asking the chatbot to prepare a report assessing whether to accept the claim.
The regulator's reading is that by entering that information, the insurance company disclosed it to the owners of the chatbot. Not used. Disclosed. That distinction changes which rules apply, and it is covered further down.
How common is this in Australian businesses?
Here is where most articles on this topic go wrong, including some we would otherwise recommend.
Two credible sources appear to disagree violently about Australian AI adoption.
The Australian Bureau of Statistics ran its Business Characteristics Survey across nearly 7,000 businesses between October 2025 and February 2026. It found around 12 per cent of Australian businesses reported using AI in the workplace in 2024 to 2025. Among small and micro businesses, around 11 per cent. Among large businesses, 35 per cent.
Intuit's 2026 AI Impact Report put regular AI use among Australian small and medium businesses at 69 per cent as at January 2026, up from 40 per cent in July 2024.
Twelve per cent against sixty-nine per cent. It is tempting to call the difference hidden AI use and move on. That would be wrong, and if you repeat it in front of someone who reads methodology sections, you will lose the room.
Three things explain most of the gap, and none of them is shadow AI.
Reference period. The ABS asked about the financial year ending 30 June 2025. Intuit measured January 2026, roughly six months later, during the steepest part of the adoption curve. Intuit's own series puts July 2024 at 40 per cent, so the two surveys are describing different moments.
Definition. Intuit counts any AI use, including free tools and features built into software the business already pays for. A bookkeeper using an AI feature inside their accounting package counts. That same business, asked by the ABS whether it "uses AI in the workplace", may reasonably answer no.
Sample. The ABS runs a probability sample across the whole business population. Intuit surveys its own customer base, businesses already running cloud accounting software, which is a digitally engaged population by construction.
So the two-survey gap proves nothing on its own. The real evidence for shadow AI comes from a different question entirely: instead of asking a business what it does, ask individual employees what they do.
The number that actually matters
PagerDuty's 2026 Shadow AI Survey, conducted by Wakefield Research among 1,250 office professionals in non-IT roles across Australia, Japan, the United Kingdom and the United States between 9 and 20 April 2026, asked people about their own behaviour.
Two thirds, 66 per cent, said they had used AI tools at work while believing it was not permitted under company policy. Eighty-eight per cent had shared work-related information with public AI tools. Broken down: 43 per cent shared emails and other correspondence, 40 per cent shared meeting notes or summaries, 34 per cent entered customer data, and 31 per cent shared financial information or confidential company documents and strategies.
Separately, 86 per cent said they worked at an organisation they believed had AI policies in place.
Those are two measures of one surveyed population, not a cross-tabulation. PagerDuty did not publish the overlap, so nobody can say what share of that 66 per cent were sitting inside a policy they knew about. Keep the caveat and the picture is still stark. In a population where the large majority believe their employer has AI policies, two thirds have used AI they believed they were not allowed to use.
That is a fair measure of the distance between the policy an organisation thinks it has and the behaviour happening inside it.
The size effect runs the wrong way
The instinct is that this is a big-company problem, something that happens where there are too many staff to watch.
The same survey points the other way on the metric that matters most. Of respondents at companies with fewer than 1,500 employees, 40 per cent had entered customer data into public AI tools, against 27 per cent at larger organisations.
Read the sample before carrying that number too far. Every respondent worked at an organisation turning over at least US$500 million, so even the smaller group is large by Australian standards, and this is not a measurement of Australian small business. What it shows is that customer-data exposure got worse as organisations got smaller, right across the range measured. Fewer controls, fewer people between an idea and an action, more improvisation. None of those conditions improve on the way down to 30 staff.
Why the ban usually fails
Say you ban it. The behavioural data suggests what happens next.
In the PagerDuty survey, 29 per cent of respondents were unsure whether their use of AI was permitted at all. Another 33 per cent said they would hide their use to avoid scrutiny from managers or leadership, and 30 per cent because of restrictive policies or fear of peer judgement. Thirty-nine per cent said they would rather use AI without telling anyone, rising to 47 per cent at companies above US$1 billion in revenue. And 81 per cent believed the rules were applied differently to leadership than to everyone else.
Much of this is not defiance. It is ambiguity, plus a reasonable belief that the rules are enforced unevenly. A ban does very little to ambiguity and quite a lot to visibility.
Consequences are already being applied, and they are not producing compliance. Among those who used AI tools that may not have been allowed, 53 per cent received informal feedback or guidance to discontinue use, and 48 per cent faced formal consequences such as a warning or disciplinary action. Those people were told to stop, informally or on the record. The overall rate is still 66 per cent.
There is also a cost to the ban that rarely gets priced. In the same survey, 77 per cent said their employer's AI restrictions were limiting their professional growth or career mobility, and 75 per cent said they would be likely to look for a job offering better AI skills development. Restricting the tool is not a neutral act.
An older data point makes the same case more bluntly. ExtraHop's October 2023 research found 32 per cent of organisations had banned generative AI tools, yet only 5 per cent said employees never used them at work. The study is dated and the tools have changed. The mechanism has not.
There is a governance version of the same trap. Cisco's 2026 Data and Privacy Benchmark Study, covering 5,200 professionals with data privacy responsibilities across 12 markets, found that while three in four organisations reported having a dedicated AI governance body, only 12 per cent described those structures as mature. Having a policy and having governance are different achievements. The gap between them is where shadow AI lives.
Hour one: contain what you can, and be straight about what you cannot
Most advice on this topic says "contain the breach". That is half true, and the honest half matters more.
The OAIC warns that once personal information has been entered into an AI system, particularly a generative AI product, it will be very difficult to track or control how it is used, and potentially impossible to remove from the system. You cannot reliably claw it back. Treat any advice that promises otherwise with suspicion.
What you can actually do:
- Establish the facts. Which tool, whose account, what was pasted, when, and how often. Ask without threatening, or you will get an incomplete answer and never know it.
- Classify what went in. Public marketing material is one situation. Internal pricing is another. A customer's name, contact details, complaint history or health information is a third, and it is the one with legal consequences.
- Stop the flow. Turn off training and data-retention settings where the tool allows it. Move the person onto an approved route the same day, not once a policy exists.
- Assess whether it is notifiable. If your business is covered by the Privacy Act and personal information has been disclosed in a way likely to cause serious harm, the Notifiable Data Breaches scheme may apply. That is a question for your privacy adviser or lawyer, quickly.
- Write down what happened. Not to build a case against the employee. To have a record when you review your controls in three months.
Do not start with discipline. You are about to ask this person to explain their workflow honestly, and you get one attempt at that conversation.
The four questions
Once the data is handled, forget the tool for a moment. Reconstruct the job.
Four questions usually tell you whether you have a policy problem, a process problem, or an automation opportunity.
1. What task were they trying to finish? Identify the output, not the app. "Using ChatGPT" is not a task. "Turning a messy customer complaint into a reply that sounds professional and does not escalate" is a task. You cannot fix what you have described as a tool choice.
2. What information did they use? Public material, internal intellectual property, or personal information about a customer or staff member. These carry different consequences, and the third changes what you are legally required to do next.
3. Why was the approved route slower or unavailable? Be specific. Is the system slow? Is there no integration, so a person is copying data between two apps by hand? Was the person never trained on the tool you already pay for? Is the approved route fine, and they did not know it existed? Four different causes, and only one of them is solved by software.
4. What safe, supported route should replace it? Workflow repair, clearer policy, an approved assistant, or custom automation. Decide on purpose. The most common failure here is buying a tool to solve a training problem.
Automation appears once, at the end, as one option out of four. The whole exercise takes about twenty minutes.
What Australian privacy law actually requires
Two points where published commentary is frequently wrong.
The small business exemption has not been removed
Under the Privacy Act 1988, businesses with an annual turnover of $3 million or less are generally exempt. A large amount of content published in 2026 states that this exemption is being removed on 10 December 2026. As at the date of this article, that is incorrect.
Removal of the small business exemption sits in a proposed second tranche of privacy reforms. The Attorney-General confirmed in February 2026 Senate estimates that the government is progressing a tranche two bill, but no bill has been introduced and no commencement date has been set. The Productivity Commission has been publicly critical of several tranche two proposals, so the final shape is not settled either. Treat any specific date you read as commentary, not law.
Being under the threshold is a narrower shelter than it sounds. You are covered regardless of turnover if you are a health service provider, if you trade in personal information, or if you are a Commonwealth contractor.
And from 1 July 2026, tranche 2 businesses that become reporting entities under the AML/CTF regime are covered by the Privacy Act for their AML/CTF-related activities, whatever their turnover. That captures real estate professionals, lawyers, conveyancers, accountants, trust and company service providers, and dealers in precious metals and stones. Coverage is triggered by actually providing a designated service, not by turnover and not by enrolment alone. The OAIC estimates more than 100,000 small businesses are affected, and has published dedicated guidance and a template collection notice for them.
Plenty of small businesses are also contractually bound to Privacy Act standards because a larger client required it in a supplier agreement. Check your contracts before concluding the Act does not reach you.
From 10 December 2026, you have to disclose automated decisions
This one has a date, and the date is close.
The Privacy and Other Legislation Amendment Act 2024 introduced new subclauses APP 1.7 to 1.9. From 10 December 2026, an APP entity must include information in its privacy policy where it has arranged for a computer program to use personal information to make a decision that could reasonably be expected to significantly affect an individual's rights or interests.
Two details matter more than the headline.
First, the obligation is not limited to fully automated decisions. It also reaches arrangements where a computer program does something substantially and directly related to making the decision. A human signing off at the end does not automatically put you outside it.
Second, the obligation applies to decisions made from 10 December 2026 regardless of when the arrangement was put in place. There is no grandfathering for systems you set up last year.
The OAIC released an issues paper on 18 May 2026, submissions closed on 15 June, and it intends to publish final guidance by September 2026. Commentators who have read the issues paper describe the regulator as signalling a broad interpretation.
It is a transparency obligation rather than a right to contest, which makes it sound minor. It is not minor for a business with shadow AI, for one reason:
You cannot disclose an automated decision you do not know is being made.
If a staff member is running applicant screening, pricing, credit assessment or customer triage through a personal AI account, that activity is invisible to whoever writes your privacy policy. Finding it is not a policy exercise. It is a mapping exercise, and it has a deadline.
Worth noting alongside this: in January 2026 the OAIC began its first privacy policy compliance sweep, examining around 60 organisations across sectors including real estate agencies, pharmacies, licensed venues, car rental businesses, car dealerships, and pawnbrokers. Privacy policy compliance is being actively checked, and not only at large companies.
The rest of the OAIC guidance, briefly
The OAIC published its guidance on privacy and the use of commercially available AI products on 21 October 2024, updated 17 January 2025. Worth knowing:
- Pasting personal information into a public chatbot is generally a disclosure, not merely a use, because the information leaves your effective control. That is a higher bar under APP 6.
- Inferred, incorrect or artificially generated information about an identifiable person is still personal information. A hallucination about a real customer is personal information you now hold.
- Using AI to generate or infer personal information counts as collection under APP 3.
- The OAIC recommends, as best practice, that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools.
- Due diligence should not be set and forget. Regular review, staff training and monitoring across the life of the product.
One line from that guidance is worth pinning above the desk of whoever signs off on software: AI products should not be used simply because they are available.
Govern, redesign, or automate
Every workaround resolves into one of three answers.
Govern it. The task is legitimate, AI genuinely helps, and the fix is a safe route plus a clear rule. An approved tool with the right data settings, a short written policy people can follow, and training. Cheapest option, and the correct one more often than vendors would like.
Redesign it. The task should not require a human relay at all. Someone is copying information between two systems by hand because those systems do not talk to each other. Automating the copying preserves a process that should not exist. Fix the process.
Automate it. The task is high volume, the rules are stable, the data boundary is clear, and human judgement is needed only at defined points. Custom automation earns its cost here, provided the human review step stays in the design rather than being removed as a rounding error.
Get the diagnosis wrong and you will pay for software that solves a training problem, or write a policy for a plumbing problem.
What this article does not claim
Worth stating plainly.
The ABS figures describe Australian businesses of all sizes. The PagerDuty figures describe large organisations in four countries and are not a measurement of Australian small business. The Cisco sample does not include Australia. The Intuit figures come from a survey of its own customer base. No survey cited here measured shadow AI in Queensland small businesses specifically, because as far as we can establish, that survey does not exist.
What these sources establish is narrower and still useful. This behaviour persists in organisations with far more governance resources than yours. Customer-data exposure got worse as organisations got smaller across the range measured. Enforcement is being applied and is not producing compliance. And the gap between an organisation believing it has a policy and its people following that policy is very large.
Nothing here is legal advice. If personal information has left your control, talk to a lawyer or privacy adviser about your obligations, including whether the Notifiable Data Breaches scheme applies.
Frequently asked questions
Should we ban AI tools at work? Rarely as a first move, and almost never as the only move. Contain the data exposure immediately, then work out what task the tool was doing and why the approved route failed. A ban without a replacement route pushes the same behaviour onto personal devices where you cannot see it. In PagerDuty's 2026 survey, 48 per cent of people who used AI outside policy faced formal consequences, and 66 per cent were still doing it.
Is it illegal in Australia for staff to put customer data into ChatGPT? It depends on whether your business is covered by the Privacy Act, which generally applies to businesses turning over more than $3 million, with exceptions that apply regardless of size. Where the Act applies, entering personal information into a public tool is usually a disclosure under APP 6 and needs to be authorised by the original purpose of collection, by consent, or by a recognised exception. The OAIC recommends as best practice that organisations do not do it at all.
Does the Privacy Act apply to my small business? Not if your annual turnover is $3 million or less, unless you fall into a covered category. Those include health service providers, businesses that trade in personal information, Commonwealth contractors and, since 1 July 2026, tranche 2 reporting entities under the AML/CTF regime, for their AML/CTF-related activities. Contracts with larger clients frequently impose the obligations anyway.
Has the small business exemption been removed? No. Its removal is part of a proposed second tranche of privacy reforms that the government has said it is progressing. No bill has been introduced and no date has been set. Content claiming a 10 December 2026 removal date is confusing the exemption with the separate automated decision-making obligation, which does commence on that date.
What is changing on 10 December 2026? New APP 1.7 to 1.9 take effect. APP entities must disclose in their privacy policy where they have arranged for a computer program to use personal information to make decisions that could reasonably be expected to significantly affect an individual's rights or interests. It reaches programs that do something substantially and directly related to the decision, not only fully automated ones. The OAIC intends to publish guidance by September 2026.
Can we just delete the data from the AI tool? Usually not with any confidence. The OAIC warns that once personal information has entered an AI system, it will be very difficult to track or control and potentially impossible to remove. Turn off retention and training settings, stop further exposure, and assess your notification obligations. Do not assume deletion is available.
How do we find shadow AI without turning it into a witch hunt? Ask about tasks, not tools. People will tell you how they get a slow job done far more readily than they will admit to breaking a rule. Make it clear you are looking for broken processes, then act on what you hear, or you will not be told twice.
Bring us one workflow.
In a discovery call we will run the four questions with you on a real process and give you a straight answer: govern it, redesign it, or automate it. Sometimes the answer is that you do not need us. We will say so.
No pitch, no lock-in, and you keep whatever we work out together.
Sources
- Australian Bureau of Statistics, Business adoption of Artificial Intelligence accelerates in 2024-25, media release, 25 June 2026. Business Characteristics Survey, nearly 7,000 Australian businesses, fielded October 2025 to February 2026, reference period 2024-25 financial year. https://www.abs.gov.au/media-centre/media-releases/business-adoption-artificial-intelligence-accelerates-2024-25
- Intuit QuickBooks, AI Adoption in Australia: 2026 Impact Report, published 12 May 2026. Survey of more than 34,000 small and medium business owners across Australia, the United States, Canada and the United Kingdom, combined with anonymised data from QuickBooks businesses. https://quickbooks.intuit.com/au/blog/news/ai-impact-report-australia-2026/
- PagerDuty, 2026 Shadow AI Survey, conducted by Wakefield Research, published 11 June 2026. 1,250 office professionals in non-IT roles at organisations with minimum annual revenue of US$500 million, across Australia (n=250), Japan (n=250), the United Kingdom (n=250) and the United States (n=500), fielded 9 to 20 April 2026. Press release, which carries the 88 per cent figure, the data-type breakdown and the enforcement figures: https://www.pagerduty.com/newsroom/shadow-ai-workplace-survey-2026/ Blog analysis, which carries the size breakdown and the concealment figures: https://www.pagerduty.com/blog/ai/shadow-ai-workplace-survey-2026/ Full report and methodology: https://www.pagerduty.com/resources/ai/learn/survey-office-professionals-used-ai-tools-at-work-despite-not-being-allowed
- ExtraHop, The Generative AI Tipping Point, October 2023. https://www.businesswire.com/news/home/20231017367100/en
- Cisco, 2026 Data and Privacy Benchmark Study, published 26 January 2026. 5,200 IT, technology and security professionals with data privacy responsibilities across 12 markets. https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m01/ai-data-privacy-investments-governance-cisco-report.html
- Office of the Australian Information Commissioner, Guidance on privacy and the use of commercially available AI products, published 21 October 2024, updated 17 January 2025. https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-the-use-of-commercially-available-ai-products
- Office of the Australian Information Commissioner, Australian Privacy Principles Guidelines, Chapter 1: APP 1, on the automated decision-making obligations commencing 10 December 2026. https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-1-app-1-open-and-transparent-management-of-personal-information
- Office of the Australian Information Commissioner, Consultation on Guidance for Transparency in Automated Decision Making, issues paper released 18 May 2026, submissions closed 15 June 2026. https://www.oaic.gov.au/engage-with-us/consultations/consultation-on-guidance-for-transparency-in-automated-decision-making
- Office of the Australian Information Commissioner, Privacy guidance for reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act. https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/privacy-guidance-for-reporting-entities-under-the-anti-money-laundering-and-counter-terrorism-financing-act
Got a workflow that should run itself?
Tell us where the friction is. We will show you what is worth automating — and what is not.