AI for Business

What is shadow AI?

Shadow AI is employees using AI tools the business has not approved. It is already happening in most Australian businesses, and the usual response makes it worse.

6 min readMattingly Intelligence

Shadow AI is the use of artificial intelligence tools inside a business without the knowledge or approval of the people responsible for the business. A commercial manager pastes a customer contract into a free AI tool to summarise it. An analyst uploads a cost file to get help with a formula. A sales manager drafts a tender response in a browser tab on a personal account. None of it appears in any company system, and none of it was reported to anybody.

The term borrows from shadow IT, which described the same pattern with software. Somebody needed a tool, the company did not provide one, and they found their own. Shadow AI moves faster than shadow IT ever did, because there is nothing to install, nothing to buy and nothing for anybody to approve.

Why capable people do it

The uncomfortable part of shadow AI is that it is usually done by good employees doing their jobs well. Public AI tools are genuinely useful. They summarise a forty-page agreement in seconds. They turn rough notes into a readable board paper. They explain a clause. They draft the first version of something that would otherwise have taken a Sunday.

When a business provides no alternative, the choice an employee faces is between doing the work well and following a policy they may not have read. Most people, most of the time, choose the work.

Shadow AI is not an employee discipline problem. It is a tooling gap that employees are solving on their own.

What is actually at risk

The risk is rarely dramatic. It is the steady, unrecorded movement of information out of the business and into a service the business has no relationship with.

  • Customer pricing and margin detail, pasted in to be analysed
  • Contract terms and correspondence, pasted in to be summarised
  • Cost models and supplier rates, uploaded for a calculation
  • Board material and strategy documents, uploaded for a critique
  • Employee and remuneration information, pasted in to be reworded

Two things follow. The first is that the information is now outside your control, and depending on the tool and the account type it may be retained or used to improve the provider’s models. The second is quieter and often worse: there is no record. If a customer or an insurer asks what was disclosed and when, the honest answer is that nobody knows.

How to tell whether it is happening

Shadow AI leaves almost no trace in company systems, because it happens in a browser on an account the company does not own. Network logs catch some of it and miss the rest, particularly anything done on a phone. In practice the signs are behavioural.

  • Written work that has improved noticeably in quality without a corresponding change in time available
  • Long documents summarised faster than anyone could have read them
  • Analysis presented without working, where working used to be shown
  • People asking whether a particular tool is allowed, which usually means it is already in use

Why banning it does not work

The instinctive response is a policy that prohibits public AI tools. Policies are worth having, and a business should be able to say what is and is not acceptable. But a ban on its own has a predictable effect: the behaviour moves to personal devices, where the business can see even less of it, and the people most likely to comply are the ones who were least likely to be a problem.

A ban also asks employees to be less effective on purpose. That is a difficult thing to ask, it is harder to sustain, and it puts the business in the position of having removed a capability its competitors are using.

A policy is useful. A practical alternative is better.

What actually works

Shadow AI stops being a problem when the approved tool is better than the unapproved one for company work. That is achievable, because a public AI tool has a structural disadvantage on exactly this kind of work: it does not know anything about your business.

A public model can explain a contract clause in general. It cannot compare the clause with your standard terms, because it has never seen them. It can describe how manufacturers usually think about changeover cost. It cannot tell you what yours is. A private AI environment that holds approved company information answers the specific question, which is the question people actually have.

Three things need to be true for people to move across. The approved tool has to be at least as good at the work. It has to be as easy to reach — a login and a browser, not a request form. And the business has to say clearly what it is for, because employees who have been quietly using AI for a year will not volunteer that on day one.

A reasonable position for an Australian business

  • Assume it is already happening, and stop treating the question as hypothetical
  • Write a short policy that names what must never go into a public tool, in plain terms
  • Provide an approved alternative that works on company information, inside your own controls
  • Say publicly that the alternative exists, and let people admit what they were already doing
  • Keep a person accountable for the output, whichever tool produced it

The goal is not to stop people using AI. Most of the value they are getting from it is real. The goal is to make sure the useful thing happens somewhere the business can see it.