Practical AI and SaaS for Business

Shadow AI in Your Business: How to Audit What Your Team Is Actually Using

Your staff may already be using AI tools you never approved. Here is how to find out what is actually happening, why it matters under Australian privacy law, and what to do about it.

Last verified: 18 July 2026. References checked against current legislation.

Editorial Perspective

You run a business with staff who've started using AI tools on their own, and you don't actually know which ones, or what they're doing with your clients' data. That's not just a technology gap, it's a Privacy Act exposure you're carrying without realising it. In five minutes, you'll know exactly how to find out what's really happening, and what to do first once you do. No IT background required.

This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.

If someone on your team has quietly started using an AI tool to get their work done faster, you are not alone, and you are not necessarily doing anything wrong. What most small business owners do not realise is that those unofficial tools, the ones no one approved and no one set up, can carry real legal risk under Australian privacy law. This guide explains what shadow AI is, why it matters for a business like yours, and how to run a straightforward audit to find out what is actually happening before it becomes a problem.

In short: Shadow AI means AI tools your staff are using that your business never formally approved or reviewed. If those tools are processing customer data or any personal information, your business may be breaching the Privacy Act 1988 without knowing it. The fix is a simple audit followed by a clear policy. Both are covered below.

This article is general information, not legal advice. For advice on your specific Privacy Act obligations, consult a qualified privacy professional.

What Is Shadow AI, in Plain Terms?

Shadow AI is any artificial intelligence tool a staff member uses for work without the business formally reviewing or approving it. It is the equivalent of someone signing up for a new software subscription on the company credit card without telling anyone, except the risks are different because AI tools typically process and sometimes store the data you put into them.

Common examples include a bookkeeper pasting client financial data into ChatGPT to draft a summary, a receptionist using an AI transcription app to record and summarise client calls, or a sales team member uploading a customer list to an AI email tool to write follow-ups. None of these are unusual things to do. Most of the people doing them have no idea there is anything to worry about.

The problem is not the technology. It is that the data went somewhere the business did not choose, under terms the business never read, to servers the business does not control, without the customers who provided that data being told it would happen. Under Australian privacy law, that sequence of events is exactly what the Privacy Act 1988 is designed to catch.

Why This Is a Privacy Act Problem, Not Just an IT Problem

The Privacy Act 1988 applies to most Australian businesses with an annual turnover above $3 million, and to all businesses that handle health information, operate a residential tenancy database, or provide services to the federal government. Many professional services firms fall inside this threshold, and even those that do not are still bound by specific obligations around sensitive client data.

Australian Privacy Principle 8 (APP 8) requires that before you disclose personal information to an overseas entity, you take reasonable steps to ensure that entity will handle that information in a way consistent with the APPs. Most AI tools are operated by US companies, running on US servers. When your staff paste client names, contact details, financial records, or health notes into those tools, your business is likely triggering APP 8, and in most cases no steps have been taken to ensure the overseas provider meets Australian standards.

The Office of the Australian Information Commissioner (OAIC) has made clear that a business cannot avoid APP 8 obligations simply because a staff member acted without the business's knowledge. If the tool was used in the course of business, the business is accountable. Ignorance of what your staff are using is not a defence.

Privacy Act deadline note: Changes to the Privacy Act 1988 are being phased in following the government's response to the Privacy Act Review. Some of these changes tighten obligations around automated decision-making and data handling by AI tools specifically. For the current state of play on upcoming deadlines, see our Privacy Act automated decision-making deadline guide.

How Much Shadow AI Is Actually Happening?

More than most business owners expect. Microsoft and LinkedIn's 2024 Work Trend Index found that 78% of AI users bring their own AI tools to work, rather than using tools their employer provided. Australian-specific data is limited, but there is no reason to think Australian workers behave differently. If your business has more than five staff, it is extremely likely that at least one person is using an AI tool for work that no one in management knows about.

The tools involved are rarely exotic. The most commonly found in shadow AI audits are ChatGPT (the free or personal-plan version), Google Gemini, Microsoft Copilot accessed via personal accounts, Otter.ai or similar transcription apps, AI writing assistants like Grammarly or Wordtune, and browser extensions that use AI to summarise or rewrite content. These are mainstream, well-marketed tools. Your staff are using them because they work, and because no one told them not to.

The Shadow AI Audit: How to Find Out What Is Actually Happening

An audit does not need to be a formal IT review or a confrontational staff investigation. For most businesses under 50 people, it takes about a week and most of that time is spent having a handful of straightforward conversations. The goal is information, not blame. People will be more honest if they know you are trying to understand the situation, not discipline anyone.

Step 1: Ask Your Team Directly, and Make It Safe to Answer

The fastest and most accurate source of information about what tools your team is using is your team. A short, anonymous survey works better than a meeting for the first pass, because people are more likely to be honest when they do not feel personally exposed. A three-question survey is enough: what AI tools do you use for work tasks (if any), what tasks do you use them for, and what data do you put into them?

Frame the survey as part of making AI use better and safer, not as a compliance crackdown. You will get more accurate responses, and the process sets the right tone for whatever policy you introduce afterwards. Google Forms or Microsoft Forms works for this, and takes about 20 minutes to set up.

Step 2: Check Browser Extensions and Installed Apps

Browser extensions are where a lot of shadow AI lives, because staff often install them for a specific task and forget they are running in the background. Ask your IT person, MSP, or a reasonably tech-confident team member to review the extensions installed on work browsers. Common AI extensions to look for include Grammarly, Otter.ai Sidebar, Jasper AI, ChatGPT integrations, and any extension with "AI", "write", "summarise", or "assistant" in its name.

For Windows-managed devices, your MSP can typically pull a list of installed software. For unmanaged or personal devices used for work (a common situation in smaller businesses), you are relying on staff disclosure from Step 1. This is one of the reasons bring-your-own-device (BYOD) policies matter for privacy compliance, and it is worth flagging if your business does not have one.

Step 3: Check SaaS Subscriptions and Credit Card Statements

Staff sometimes pay for AI tools themselves and expense them, or put them on a company credit card without notifying anyone. A single month's business credit card statement, filtered for software or SaaS-looking charges, often reveals tools no one in management knew about. Look for small monthly charges ($10 to $50 AUD range) from vendors whose names are not immediately recognisable.

Common culprits to search for: Anthropic (Claude), OpenAI, Notion AI, Copy.ai, Jasper, Writesonic, Otter.ai, Fireflies.ai, and Zapier (which connects many AI tools). If your business uses an expense management platform, run the same filter there.

Step 4: Review Meeting and Communication Tools

Many video conferencing platforms now include built-in AI features that are enabled by default. Microsoft Teams with Copilot, Zoom with AI Companion, and Google Meet with Workspace AI can all be recording, transcribing, and summarising your business meetings without anyone in the business making a conscious decision to turn that on. Check the admin settings for whichever platforms you use to confirm what AI features are active and where that data goes.

This category is different from individual staff decisions, because these are often vendor-side feature rollouts that happen silently. A 2024 Zoom update, for example, enabled AI Companion for all eligible accounts by default. If you did not log in and check, it was probably running.

Step 5: Map What Data Is Going Where

Once you know what tools are being used, the next question is what data is going into them. For each tool identified, answer two questions: what type of information is being entered (names, contact details, financial data, health information, meeting recordings, internal business data), and where does that data go when it is submitted (is it stored by the vendor, used to train AI models, retained for how long, on which country's servers)?

Most major AI tools publish data handling policies, but they are not always easy to find or read. The key things to look for are whether the vendor uses your inputs to train their models, whether data is stored beyond your session, and whether data can be requested for deletion. For any tool handling Australian personal information, data going to US servers needs to be assessed against APP 8 before you decide to formally approve that tool.

What to Do With What You Find

The audit gives you a picture of what is happening. The next step is deciding what to do about each tool you found. The practical approach is to sort them into three categories: approved for continued use, conditionally approved pending a data handling review, and not approved for use with client or personal data.

Tools that handle only internal, non-personal business data (writing internal memos, summarising public information, drafting internal process documents) generally carry low risk and can be approved quickly. Tools that touch personal information about clients, customers, patients, or third parties need a proper review of their data handling terms before approval. Tools with no clear data handling policy, unclear overseas data transfer practices, or that explicitly use inputs for model training should not be approved for use with personal information until those issues are resolved.

The most important practical step is getting this into writing. A clear, short AI policy tells your staff exactly what they can and cannot do, gives you a documented position if a complaint ever arises, and makes the next audit much easier because staff know what to report. Our free AI staff policy template for Australian businesses covers all of this and takes about 30 minutes to complete for a business under 50 people.

The Australian Privacy Angle: What the Rules Actually Say

For a full treatment of how the Privacy Act 1988 applies to AI tools in Australian businesses, see our detailed guide on AI and the Privacy Act in Australia. The short version for a shadow AI audit is this: the Privacy Act cares about what happens to personal information, not how it ended up in a particular system.

If a staff member pasted client data into an unapproved AI tool, your business is likely the entity responsible under the APPs, because the information was collected and used in the course of your business activities. The fact that the staff member acted without authorisation does not remove the business's obligation. What it does affect is your internal response, but not your external liability.

APP 6 requires that personal information only be used or disclosed for the primary purpose it was collected, unless an exception applies. Feeding client information into an AI tool for a purpose the client did not anticipate when they shared their details is a use the client would typically not expect, and that matters under APP 6. The combination of APP 6 and APP 8 is why shadow AI creates genuine compliance risk, not just a theoretical one.

Industries With Elevated Risk

Shadow AI risk is not equal across all industries. Four categories of Australian SMBs face elevated risk because of the type of data they routinely handle.

Accounting and bookkeeping practices handle financial data, tax file numbers, and personal income details for dozens or hundreds of clients. Staff putting client financial data into AI tools to draft reports or explanations creates immediate APP 8 exposure. The Australian Institute of CPAs and Chartered Accountants ANZ have both issued guidance on member obligations around AI and client data.

Allied health and medical administration businesses handle health information, which is classified as sensitive information under the Privacy Act and carries stricter obligations. AI transcription tools used in clinical settings, or AI tools used to summarise patient communications, require specific consent and data handling reviews before they are appropriate for use.

Legal and conveyancing practices face professional conduct obligations on top of the Privacy Act, meaning a data breach involving client information could trigger both a privacy complaint and a professional disciplinary process. AI tools used to draft or review legal documents need particularly careful data handling assessment.

Recruitment and HR functions in any business handle employee and candidate personal information, including potentially sensitive categories. AI tools used to screen resumes, draft job ads, or summarise candidate notes need to be reviewed for both privacy compliance and potential discrimination risk under Australian law.

Your Audit Checklist

For a printable checklist version of this audit process, see our companion guide: AI policy checklist for Australian businesses. It covers the audit steps, approval criteria, and policy rollout in a single document you can work through with your team or hand to your MSP.

The five audit steps in brief: run a staff survey on current AI tool use, check browser extensions and installed software, review credit card and expense statements for SaaS charges, check admin settings on communication platforms for enabled AI features, and map what data is going into each tool identified. Once you have the picture, sort tools into approved, pending review, and not approved categories, then document the outcome in a written policy.

Methodology (Real-World, Verified)

This guide is researched against primary regulatory sources and official regulator guidance, verified as of the date shown, and written for a business with no dedicated compliance function.

Related reading: our can staff upload customer data to AI tools.

Related reading: our Claude AI review for Australian business.

Try our free AI Tool Pricing Tracker to check current AUD pricing across the major AI platforms.

Try our free AI Privacy Risk Scorer to score your current AI tool setup against Privacy Act requirements.

Related reading: our free AI acceptable use policy template and our AI governance by region.

For the broader AI risk management picture beyond shadow AI, see our AI risk management hub.

What is shadow AI and why does it matter for my business?

Shadow AI is any AI tool your staff are using for work that your business never formally reviewed or approved. It matters because most AI tools process and store the data entered into them, often on overseas servers. If that data includes personal information about your clients or customers, your business may be in breach of the Privacy Act 1988 without knowing it, because the Privacy Act holds the business accountable for how personal information is handled in the course of business, regardless of whether management authorised the specific tool being used.

Does the Privacy Act apply to my small business?

The Privacy Act 1988 applies to businesses with annual turnover above $3 million, and to all businesses that handle health information, operate a residential tenancy database, or contract with the federal government, regardless of size. If you are under the $3 million threshold and do not fall into those specific categories, the Act does not automatically apply, but state-level privacy laws and professional conduct obligations (for example, for accountants, solicitors, or health practitioners) may still require you to handle personal information responsibly. For a fuller explanation, see our guide on AI and the Privacy Act in Australia.

Is it okay for my staff to use ChatGPT for work tasks?

It depends on what data they are putting into it. Using ChatGPT to draft internal documents, write general content, or summarise public information carries low privacy risk. Using it to process client names, contact details, financial records, health information, or any personal data collected from customers is a different matter, because that information goes to OpenAI's servers in the US, triggering APP 8 obligations. The safest position is to set a clear rule: no personal information about clients, customers, or third parties goes into any AI tool that has not been reviewed and approved by the business. A written policy makes that rule clear and defensible.

What should I do if I find staff have already been using unapproved AI tools?

Do not treat it as a disciplinary matter unless personal information was mishandled in a serious way. Most staff using AI tools are trying to do their jobs well, not create compliance problems. Assess what data went into the tool and under what terms, determine if there is an ongoing risk that needs to be stopped, communicate clearly what the business's position is going forward, and document what you found and what you did about it. If client personal information was sent to an overseas provider without appropriate safeguards, you may need to assess whether a data breach notification is required under the Notifiable Data Breaches scheme.

How often should I audit for shadow AI?

A formal audit once a year is a reasonable minimum. AI tools are appearing and evolving quickly, and the tools your staff are discovering and using will change. More practically, a quick check at the start of each year, combined with a standing rule that any new AI tool must be reported before use, covers most of the ongoing risk. The initial audit is the hardest one. After that, the policy and the annual check do most of the work.

Do I need a lawyer to put an AI policy in place?

Not for a basic AI acceptable use policy for most SMBs. The core requirements are clear: define what tools are approved, specify what data can and cannot be put into AI tools, and set out the process for requesting approval of a new tool. Our free AI staff policy template covers this for businesses under 50 people. If your business is in a regulated industry (legal, medical, financial services) or handles sensitive personal information at scale, a legal review of your policy is worthwhile given the professional conduct obligations that layer on top of the Privacy Act.

Find official guidance for your region

Requirements vary by jurisdiction. This article provides general information only. Consult your regional authority or a qualified professional for advice specific to your situation.

The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.

Once you have completed the audit, the next step is a clear written policy your staff can actually follow. Our free AI staff policy template for Australian businesses covers approved tools, data handling rules, and the approval process for new tools, ready to customise in about 30 minutes.

Get the Free AI Policy Template