Shadow AI: You said five. The audit found twenty-eight.

What a system discovery audit actually turns up, why the gap is so consistent, and why the tools nobody told you about are the ones carrying your risk.

Staff attending an AI awareness training session in an Australian workplace meeting room

I've been working with companies recently to discover Shadow AI use. The conversation goes the same way almost every time.

I ask an executive team how many AI systems the organisation uses. Someone says three. Someone else says four or five, and names them: Copilot, ChatGPT, the chatbot on the website. There is a pause. Then the governance lead tells me later something like, "look, it is probably more like ten or twelve, because I am sure we don't know all of them."

That second answer is the honest one, and it deserves credit. It takes a certain amount of nerve to say out loud that you do not know what is running in your business.

It is also probably still low.

What the audit finds

In the discovery work I have done over the past few months, the number that comes out the other side is usually at least double what the leadership team estimated, and sometimes four or five times. Twenty-five is a common landing point for a mid-sized organisation. I have seen higher.

I want to be careful with that claim, because it is my own experience across a modest number of engagements, not a national survey. Your organisation might come in tidier. But the direction of the gap is consistent enough that I have stopped being surprised by it, and the published research points the same way. Jobs and Skills Australia reports that somewhere between 21 and 27 per cent of workers, concentrated in white-collar roles, use generative AI without their employer’s knowledge or approval. EY’s survey of just over a thousand Australian workers found 68 per cent using AI at work, while only 35 per cent had received any formal training on it.

So the gap is not a story about one badly run business. It is close to the base rate.

Why the estimate is always low

The estimate is not low because people are hiding things, mostly. It is low because of where AI now lives.

It arrived inside software you already bought. Your CRM added a summarisation feature. Your service desk added ticket triage. Your recruitment platform added candidate ranking. Nobody ran a procurement process, because there was nothing to procure. The vendor switched it on in a release note.

There is no invoice to find. The single most reliable way to discover systems is to search the general ledger, and free tiers do not appear there. A tool with no cost centre is invisible to every finance-led control you have.

Personal accounts do not touch your identity provider. Somebody using a personal AI account on a work laptop is not in your single sign-on logs, not in your tenant, and possibly not in any report your IT team currently run.

Browser extensions and plug-ins slip under the definition. A meeting notetaker that joins calls, a writing assistant in the browser, a spreadsheet add-in. Staff genuinely do not think of these as "AI systems", so they do not report them when you ask.

Nobody agrees what counts. Ask "how many AI systems do we use" and people answer about chatbots. They leave out the machine learning scoring in the fraud tool, the forecasting in the rostering system and the resume parser, because those do not feel like AI. They are, and a regulator or an assessor will treat them as such.

Add those together and you can see why an honest, capable governance lead lands on twelve when the answer is possibly twenty-eight. They are counting the AI they chose. The audit counts the AI that is running.

Whiteboard-style chart comparing the four AI systems an executive names, the twelve a governance lead estimates and the twenty-eight a discovery audit finds.

Staff behaviour runs the full range

Here is the part that matters more than the count.

The staff using these tools are, overwhelmingly, trying to do their jobs well. They are not reckless. Many of them are careful in ways that would impress you. In the same organisation, on the same afternoon, you will find behaviour across a spectrum this wide:
•      Conservative and safe. Drafting a plain-language explanation of a process, with no client information in the prompt, and checking the output before it goes anywhere.
•      Reasonable but undocumented. Using a tool that is fine in itself, for work that is fine in itself, with no record that it happened and no way for you to demonstrate it later.
•      Quietly risky. Pasting a de-identified case note into a public tool, where the de-identification was done by eye and takes about four seconds to reverse.
•      Outright dangerous. Uploading a client list, a full participant file, a draft contract or a board pack into a free consumer account, where the terms may permit the provider to use the content, and where your organisation has no contract, no data location, no deletion right and no audit trail.

That last one is not a hypothetical I have invented for effect. The KPMG and University of Melbourne global study of more than 48,000 people found that close to half of employees admit using AI in ways that break their employer’s rules, including putting sensitive company information into free public tools, and that 57 per cent hide their AI use and present the output as their own work.

The common thread across the whole spectrum is that none of it was a decision anyone made. It was a series of individually sensible choices, made by people who had no guidance, filling a gap the organisation left open.

What it actually risks

Six things, in the order they tend to bite.

1.    Data leaves and does not come back. Once client information is in a consumer account, you cannot recall it, you often cannot prove what happened to it, and you may have no contract that would let you ask.

2.    Privacy obligations attach anyway. Australian Privacy Principles do not care which tool the information went into, or whether you approved it. If personal information was disclosed, it was disclosed, and the notifiable data breach clock does not pause for a tool you did not know about.

3.    Confidentiality and contract terms get breached silently. Most commercial agreements, funding deeds and client contracts carry confidentiality clauses drafted long before any of this. A staff member cannot see those clauses from inside a text box.

4.    Decisions get made with no record. When AI output shapes a recommendation, an assessment or an eligibility judgement and nobody records that it did, you cannot explain the decision later, review it, or defend it if challenged.

5.    Accuracy failures land on you. The same global study found 66 per cent of employees rely on AI output without checking it, and 56 per cent report having made mistakes at work because of it. The tool is not accountable for those mistakes. You are.

6.    You cannot govern, report or certify what you cannot see. This is the one that quietly costs the most. IBM’s 2025 Cost of a Data Breach report found 63 per cent of breached organisations had no AI governance policy at all, and 97 per cent of those that suffered an AI-related incident lacked proper AI access controls. Breaches involving shadow AI carried around USD 670,000 in extra cost, roughly a million Australian dollars at current rates, though that is a global average across a large sample rather than a figure you can apply to your own balance sheet.

None of these need a malicious actor. They need an ordinary Tuesday.

Two things make all of it worse


No AI acceptable use policy. Without one, every staff member is writing their own. Some of them will write a good one. The KPMG study found only 40 per cent of employees say their workplace has any policy or guidance on generative AI. In Australia, only 30 per cent of employees say their organisation has one.

No AI awareness training. Only 35 per cent of Australian workers have had formal AI training from their employer, on EY’s numbers, and 72 per cent say they worry about breaching data or regulatory rules when they use AI. That is a workforce that wants to be told where the line is and has not been.

A policy without training is a document. Training without a policy is a conversation. You need both, and neither is expensive compared with the alternative.

AI Awareness training in action. Recognising Shadow AI is a key element.

If you hold a DEWR contract, the arithmetic is sharper

For employment services providers working under the Department’s Third-Party AI Assessment Framework, an undiscovered tool is not just a risk. It is potentially an unapproved use.

The Framework requires a separate application and written approval from the Department for each proposed AI use, before it is implemented, and approved use cases are reviewed annually as part of the Right Fit for Risk process. Read that against a discovery audit that finds twenty-eight systems, and two problems appear at once. First, you cannot apply for something you have not identified. Second, approval is meant to come before implementation, and neither document offers a retrospective path for a tool that has quietly been running for a year.

There is also the internal-use carve-out, which several providers are relying on. It is real, but it depends on the system being fully isolated from all service-related systems and data, and most shadow AI fails that test by default because it sits in your main tenant and authenticates against your normal directory. I have written about where that carve-out runs out in a separate piece.

For a provider, discovery is not the nice-to-have that comes after the policy. It is the thing that tells you how many applications you own.

Where to start this month

You do not need a project to make a real dent. You need an afternoon and a list.

1.    Search the ledger and the card statements for AI vendor names and for small recurring charges under a hundred dollars. Free tiers will not show up, but the paid ones will, and they tell you who has already decided.

2.    Pull some lists from Microsoft 365 or Google Workspace. Every third-party tool a staff member has connected to your tenant is likely sitting in that report right now.

3.    Ask your vendors what AI they have switched on. Your CRM, your rostering system, your service desk, your HR platform. Ask what is enabled by default, what processes your data and where.

4.    Ask staff, without consequence attached. A short, anonymous, genuinely amnestied survey will surface more in a week than a control will find in a quarter. Say plainly that nobody is in trouble, and mean it.

5.    Write it down in one register, with the owner, the data it touches, whether it is approved, and who confirmed that. A register that lists twenty-eight systems honestly is worth more than a policy that assumes four.

The number is not the point. The point is that you cannot make a single defensible decision about AI risk, and you cannot answer a single assessor’s question about it, until you know what is actually running.

If you need help...

If you want a hand with that, there are two ways I usually help.

Staff AI awareness training gives your people the practical line between safe and dangerous use, which is the fastest way to reduce risk in an organisation that has none of the paperwork yet.

The AI Governance Awareness Pack goes further: a discovery audit of the systems actually in use, an AI acceptable use policy written for your organisation rather than a template, and an AI maturity assessment so you know what to do next and in what order.

If you are not sure which one you need, that is usually a sign the audit comes first. Have a look at governanceworks.com.au or email hello@governanceworks.com.au and we can work out which is the right size for the risk in front of you.

Sources: Jobs and Skills Australia, Our Gen AI Transition: Implications for Work and Skills. EY, AI Workforce Blueprint, survey of 1,003 Australian workers, August 2025. KPMG and the University of Melbourne, Trust, attitudes and use of artificial intelligence: A global study 2025, 48,340 respondents across 47 countries. IBM and Ponemon Institute, Cost of a Data Breach Report 2025. Department of Employment and Workplace Relations, Third-Party AI Assessment Framework, September 2025.

Not sure where to start?

Tell me what you're facing. You'll get a straight answer on whether this is the right piece of work, and what it would involve.

Book a conversation