Shadow AI in Australian Workplaces: Why Banning Tools Makes It Worse
Most Australian workers already use AI at work, often without telling anyone. The answer is not a broader ban. What would help are clearer governance, practical training and better visibility.
01
What shadow AI actually is, and what it is not
Shadow AI is what happens when someone pastes a client email into a free chatbot to get help with a reply, and does not tell anyone.
It is the marketing coordinator drafting campaign copy in a personal ChatGPT account because the corporate licence has not been assigned yet. It is the analyst running a spreadsheet through an AI tool they found in a browser extension store. It is the team lead who built a small automation over the weekend, and now half the department depends on it.
The term borrows from shadow IT, the decades old problem of staff using unapproved software, but shadow AI behaves differently in three important ways.
That last point matters, because it changes what a sensible response looks like. With agent mode now available in Word, Excel and PowerPoint for Microsoft 365 Copilot and Microsoft 365 Premium subscribers, the distinction between using an AI tool and letting one act on your behalf has narrowed considerably. If you are not yet clear on that shift, take a few minutes to learn what AI agents actually are.
What shadow AI is not: it is not sabotage, and it is usually not ignorance of the rules. In many organisations, the rules either do not exist or nobody can remember what they say.
02
The number that gives it away
Here is the tension at the centre of this whole issue.
The Australian Bureau of Statistics reported in June 2026 that around 12% of Australian businesses used AI in 2024 to 2025. Large businesses sat at 35%, medium businesses at 22%, and small businesses at about 11%.
Meanwhile, research from RMIT Online and Deloitte Access Economics published in March 2026 found that 84% of Australians use at least one AI tool at work.
These are two different questions, and it is worth being precise about that. The ABS asked businesses whether the business used AI. RMIT and Deloitte asked workers whether they use AI tools in their job. One is an organisational answer, the other is an individual one. They were never going to match exactly.
The gap is the point
Most Australian organisations would answer, “No, we do not use AI.” Most of their staff would answer, “Yes, I do.” The space between those two answers is where shadow AI lives.
03
Why your people are doing it
None of the four reasons below is defiance. That is the useful thing to notice.
1. The sanctioned tool was never explained
Buying licences is not the same as building capability, a point we have made before about why a Copilot licence alone does not deliver value. Someone receives an email saying Copilot is now available, opens it, types a vague request, gets a mediocre answer, and quietly returns to the tool they already know how to use.
The RMIT Online and Deloitte research puts hard numbers on this. Only 48% of Australian workers receive any AI training from their employer, and just 11% get structured, ongoing support. Around 49% teach themselves through ad hoc trial and error.
If half your workforce is learning AI by guessing, you do not have an AI strategy. You have a large, unsupervised experiment.
2. They do not know what they are allowed to do
Ask five people in your organisation whether they are permitted to paste a customer's name into an AI tool. If you get five different answers, or five shrugs, the policy is not the problem. The absence of one is.
3. The approval process is slower than the work
When getting a tool approved takes six weeks and the report is due Thursday, people make a rational choice. Shadow AI is very often a symptom of procurement latency rather than poor judgement.
4. Nobody told them the sanctioned tool could do it
Staff use a free public chatbot for a task their licensed enterprise tool handles better, more securely, and with their own organisational data already connected. They simply did not know.
This is precisely what a short, practical course like AI Prompting Fundamentals or ChatGPT Beginner is designed to fix. Prompting is not inherently difficult, but knowing which tool to reach for is a skill nobody is born with.
04
What it actually costs you
Four risks, in rough order of how often they bite. The fourth is the one almost nobody counts.
Risk 1
Privacy exposure
The Office of the Australian Information Commissioner recommends that organisations do not enter personal information, especially sensitive information, into publicly available generative AI tools.
Its guidance also expects AI use policies, controls restricting the entry of personal information, human oversight, robust training and auditing measures. Note what is in that list. Not just a policy. Training and auditing, named explicitly.
Risk 2
Data you cannot see leaving
With shadow AI you have no record of what went where. That is a problem for any organisation with contractual confidentiality obligations, and a serious one for anyone handling health, financial or government information. You cannot report on an incident you cannot see.
Risk 3
Output quality and rework
Research from BetterUp Labs and Stanford's Social Media Lab found 41% of workers had received AI generated work that appeared complete but was not, costing roughly two hours of rework each time. Unsupervised use tends to produce more of this because nobody has taught people how to check the output.
Risk 4
The capability tax
When AI use is hidden, it cannot be shared. The person who has found an excellent way to summarise tender documents cannot demonstrate it at the team meeting, because doing so means admitting they have been using an unapproved tool. Nothing spreads. Everyone solves the same problem alone.
RMIT Online and Deloitte estimate that lifting half of Australia's beginner level AI users to intermediate proficiency would deliver an $18.9 billion economic dividend, with an individual wage uplift of around $7,000 a year for the worker making that step.
You are not just carrying a risk. You are paying for AI use and getting none of the compounding benefit.
05
Why banning it makes things worse
The instinct is to block the domains and issue a stern email. It fails for a reason that is easy to predict once you have seen it happen.
“If employees are unable to work in the sanctioned tools, they will likely go around the organisation's controls and start using shadow AI, which presents far greater risks.”
Gartner, guidance on managing AI agent sprawl, April 2026
A ban does not remove the demand that created shadow AI. It removes your visibility of it. The work still gets done, just on personal devices, personal accounts and personal phones, where you have no logging, no data controls and no idea it is happening.
Australian analysis of Jobs and Skills Australia's Our Gen AI Transition report reached the same practical conclusion: clearer rules could reduce shadow AI. Ambiguity drives it underground, not sensible permission.
The goal is not less AI use. The goal is less unobserved AI use.
Getting there is a governance capability, not a software purchase. That is why organisations increasingly explore AI Governance Training before they write a single policy line.
06
What works instead: sanction, train, monitor
The loop is simple. The order is what matters, and most organisations attempt it backwards.
Step 1, weeks 1 and 2
Sanction
Name a small number of approved tools. Two or three, not fifteen. State what each may be used for, and what may never be entered into it. Publish the list somewhere people will actually find it.
Step 2, weeks 2 to 8
Train
Use more than one format: a short instructor led course, role relevant examples, and somewhere to ask questions afterwards. Confidence with the sanctioned tools gives people less reason to reach for unapproved ones.
Step 3, ongoing
Monitor
Once tools are sanctioned and people are trained, monitoring becomes reasonable rather than adversarial. You are checking that a system works, not hunting for offenders.
The Digital Transformation Agency's whole of government Microsoft 365 Copilot trial found that 75% of participants who received three or more forms of training were confident using the tool. That is 28 percentage points higher than those who received only one form. If your people use Microsoft 365, Copilot for M365 training is a practical starting point.
Ban and block versus sanction, train and monitor
| Outcome | Ban and block | Sanction, train, monitor |
|---|---|---|
| AI use | Continues, unobserved | Continues, visible |
| Where AI use happens | Personal devices and accounts | Managed environment |
| Data exposure | Unknown and unmeasurable | Logged and bounded |
| Staff response | Concealment | Participation |
| Good practice | Stays with the individual | Spreads across the team |
| Incident reporting | Very little evidence | A record of actual events |
| Capability over time | Flat or divergent | Compounding |
07
Why 2026 makes this urgent
Shadow AI used to mean someone using a chatbot they should not. It increasingly means something with more reach.
Since 22 April 2026, agentic capability in Word, Excel and PowerPoint has been generally available and switched on by default for Microsoft 365 Copilot and Microsoft 365 Premium subscribers. Agents do not just answer. They take multi step actions. Building a basic one no longer requires a developer because tools such as Agent Builder are designed for business users.
That is a genuine productivity opportunity, and exactly what Microsoft Copilot Agent Builder training exists to unlock safely. It is also a new category of shadow.
150,000+
Gartner projects that an average global Fortune 500 enterprise will have more than 150,000 agents in use by 2028, up from fewer than 15 in 2025.
A shadow chatbot conversation is a data risk. A shadow agent is a data risk that keeps running after the person who built it has gone on leave. If your organisation has not decided who may build agents, what data they may touch and who owns their output, it will decide by default, through whoever gets there first.
08
A 30, 60, 90 day plan
Nothing here requires new headcount or a consulting engagement. Run it with the people you have.
Days 1 to 30
Find out what is actually happening
- Run a short, explicitly amnestied survey. Say plainly that no one is in trouble.
- Ask which AI tools people use for work, what they use them for, and what stops them using approved tools.
- Check which licences you already pay for, and how many are genuinely used.
- Identify the two or three highest risk data categories that must never leave your environment.
Days 31 to 60
Sanction and publish
- Approve a short list of tools with clear, specific use cases.
- Write a two page AI use policy with concrete rules. Name the data that cannot be entered and the tools that may be used.
- Add agent clauses: who may build agents, what data they may connect to, who reviews them and who owns their output.
- Brief managers before staff. AI for Business Leaders and Managers is usually the first cohort to train, not the last.
Days 61 to 90
Train and open it up
- Deliver at least three forms of training: instructor led, role relevant examples and an ongoing channel for questions.
- Read what the DTA Copilot trial found about training before designing the programme.
- Create a place where people share what works. A monthly fifteen minute show and tell converts hidden practice into shared capability.
- Re-run the survey. Movement in the “I use unapproved tools” number is your actual measure of success.
09
What the rules require in Australia
Worth being accurate here, because there is a lot of loose commentary about it.
Private sector organisations
Australia has no AI specific statute. The National AI Plan, released on 2 December 2025, did not proceed with the mandatory guardrails proposed in the 2024 consultation. It relies on existing technology neutral law with targeted amendments where gaps appear.
That is not the same as having no obligations. Privacy law, consumer law, confidentiality obligations, work health and safety duties, and existing contracts still apply. The OAIC's expectation of training and auditing is already on the record.
Public sector organisations
Training is now mandatory. The Digital Transformation Agency's Policy for the responsible use of AI in government version 2.0 took effect on 15 December 2025. It states that foundational AI training is mandatory for all staff across the APS, with the first mandatory requirement commencing 15 June 2026 and the remainder by December 2026.
In New South Wales, the AI Operational Policy requires public servants to complete AI literacy and policy training if they use AI in their work, and requires agencies to make those courses available.
If you supply into government, expect this requirement to arrive in your contracts before it arrives in legislation.
Build safe AI capability
Related Nexacu courses
Practical training for the people approving, using and governing AI at work.
AI Governance Training
1 day | $560
Practical governance for leaders and decision makers covering accountability, data governance, risk and responsible adoption.
AI for Business Leaders and Managers
1 day | $595
For the people who need to explain the policy, lead adoption and make informed AI decisions.
AI Prompting Fundamentals
1 day | $595
Practical prompting across tools, so staff get useful results from the sanctioned option.
Copilot for M365
1 day | $490
Help teams do securely in Microsoft 365 what they may otherwise do in a public chatbot.
Microsoft Copilot Agent Builder
1 day | $560
For teams starting to build agents, before they start building them unsupervised.
Training a whole team? Team AI training can be delivered on site or live online, tailored to your policy and tools.
Common questions
Frequently asked questions
Free PDF survey template
Start with the amnestied AI use survey
Ten anonymous questions, the amnesty wording that encourages honest answers, guidance on how to run the survey, and a short guide to reading the results.
Download the survey PDFDo this next
Run the amnestied survey this week. You cannot govern what you have not measured, and most organisations discover that AI use is higher than leadership assumed while the reasons people use unapproved tools are entirely fixable.
Sources
- Australian Bureau of Statistics, Business adoption of artificial intelligence accelerates in 2024 to 2025, 25 June 2026.
- RMIT Online and Deloitte Access Economics, Beyond Prompting: Measuring the Generational AI Gap, 25 March 2026.
- Jobs and Skills Australia, Our Gen AI Transition, August 2025. The 27% figure is sourced to Deloitte Access Economics 2024, cited within.
- Office of the Australian Information Commissioner, Guidance on privacy and the use of commercially available AI products.
- Gartner, Six steps to manage AI agent sprawl, 28 April 2026.
- Digital Transformation Agency, Microsoft 365 Copilot evaluation report, October 2024.
- Digital Transformation Agency, AI policy update: strengthening responsible use across government, 12 January 2026.
- Digital NSW, NSW AI Operational Policy.
- Department of Industry, Science and Resources, National AI Plan, 2 December 2025.
- Microsoft, Copilot's agentic capabilities in Word, Excel and PowerPoint are generally available, 22 April 2026.
- BetterUp Labs and Stanford Social Media Lab, AI generated workslop is destroying productivity, Harvard Business Review, 22 September 2025.
- The Conversation, Many Australians secretly use AI at work. A new report shows clearer rules could reduce shadow AI.


