Ask most Perth business owners whether staff use AI tools at work, and the honest answer is usually "probably, we haven't checked." Shadow AI, free AI tools adopted without IT's knowledge or approval, has quietly become one of the more common ways sensitive business data ends up somewhere it was never meant to go.
What Shadow AI Actually Looks Like
It's rarely dramatic. A staff member pastes a client contract into a free AI tool to summarise it faster. Someone uploads a spreadsheet of customer details to get help building a report. A recruiter pastes candidate CVs into a tool to draft interview questions. None of it feels like a security incident in the moment, it feels like getting work done efficiently, which is exactly why it spreads so quickly without anyone deciding to allow it.
Why It's a Different Risk Than Shadow IT
Unmanaged SaaS tools are a known problem, see our guide to SaaS management, but AI tools add a wrinkle: depending on the platform and account tier, data entered can be used to train the underlying model. That's a much harder thing to walk back than simply cancelling a subscription, and it's not always obvious from the tool's interface whether that setting applies.
Finding Out What's Actually Being Used
DNS and firewall logs will usually show which AI domains staff devices are already talking to, often a wider list than expected. Pair that with DNS filtering to get visibility going forward, and a short, non-confrontational conversation with a few staff. Most people aren't trying to hide anything, they just haven't been asked what they use or told it might be a problem.
What to Actually Do About It
Banning AI tools outright tends to push usage to personal phones, which is harder to see than a blocked browser tab and solves nothing. A more realistic approach: provide a sanctioned option with proper data handling terms, such as Microsoft Copilot under your existing tenant rather than a free consumer account, and set clear rules for what can and can't be entered into any AI tool. That policy needs to be written down, not assumed, our guide to writing an AI usage policy for staff covers exactly this.
Frequently Asked Questions
Isn't this just the same problem as shadow IT?
It's the same underlying pattern, staff adopting tools without IT's knowledge, but the risk profile is different. A free AI tool doesn't just store data somewhere unmanaged, in many cases it can also use whatever's typed in to train the underlying model, which is a harder problem to undo.
How do we find out what AI tools are actually being used?
Start with DNS and firewall logs, which will show traffic to AI tool domains even without any special monitoring in place. A short, honest conversation with a few staff often surfaces just as much, most people aren't hiding it, they just haven't been asked.
Should we just block AI tools outright?
Blocking without an alternative usually just pushes usage to personal phones, which is harder to see and control than a blocked browser tab. Providing a sanctioned option is generally more effective than a ban with no substitute.
What's the highest-risk use case to fix first?
Anything involving client-identifiable information, financial data, or content covered by a confidentiality agreement pasted into a free-tier AI tool. That's the scenario most likely to breach a client contract or, for regulated industries, notification obligations.
We can audit what AI and SaaS tools your team is actually using.
IT Consulting Services →No idea what AI tools your team is actually using?
Call 0433 087 091 for a free, no-obligation IT health check.
Book a Free IT Health CheckFor related reading, see AI Usage Policy for Staff, SaaS Management for Perth Businesses, and ChatGPT vs Microsoft Copilot.