Shadow AI is the use of artificial intelligence tools by employees for work — without the employer’s knowledge, approval or oversight, usually through public generative AI chatbots opened straight from a browser.
The answer is not a blanket ban, which simply drives use underground. The answer is governance: a clear AI acceptable-use policy, staff training, clear data rules, human oversight of outputs, and proportionate monitoring.
What’s the real issue with shadow AI?
The real issue is a loss of visibility and control — not the technology itself.
Tools such as ChatGPT, Gemini, Claude and Microsoft Copilot are now as easy to use as a search engine — an employee can start using one in minutes, with no procurement, IT involvement or privacy assessment. Shadow AI is rarely malicious: staff are solving a productivity problem, not creating a governance one. But many do not realise that information typed into a public tool may leave the organisation, be retained by the provider, or used to train future AI models.
What does shadow AI look like in practice?
Consider a mid-sized Queensland community services organisation — a composite, with identifying details removed.
Under time pressure, a team leader pasted a full client complaint file — the complainant’s name, health information and investigation notes — into a free public chatbot to summarise and draft a response, then used the output almost verbatim. Three problems surfaced:
- Privacy. Sensitive information about an identifiable individual had gone to an offshore provider, outside the organisation’s control.
- Accuracy. The summary misstated a key date and invented a policy reference that did not exist. Nobody caught it.
- Scale. Management then discovered several staff had been using public AI this way for months.
One prompt engaged privacy, confidentiality, accuracy and record-keeping risks at once — with no policy or oversight in place.
What does the law say?
Australia has no single, comprehensive AI Act yet. But AI does not operate in a legal vacuum — existing laws already apply, in full.
Frameworks to keep front of mind
- Privacy. The Privacy Act 1988 (Cth) and the Australian Privacy Principles are readily engaged when staff enter personal information — APP 6 (use beyond the original purpose), APP 8 (cross-border disclosure) and APP 11 (reasonable security). The employee records exemption may apply to some practices, but not to contractors, applicants or customers, and it does not displace confidentiality, contractual or security obligations.
- Confidentiality and privilege. Feeding privileged material into a public tool may support an argument that privilege has been waived — a no-go zone without legal sign-off.
- Intellectual property. Trade secrets and source code can lose protection once entered into a public tool, and AI output is not automatically safe to use — copyright generally requires human authorship.
- Employment law. Using AI contrary to a lawful and reasonable policy can be a conduct issue. Where AI assists HR decisions — recruitment, performance, discipline — you remain responsible for accuracy and procedural fairness.
- Surveillance and contracts. Any monitoring must comply with surveillance and privacy law and industrial instruments, and client agreements often restrict data storage or prohibit unapproved subcontractors.
The principle is consistent: AI does not displace your existing obligations.
What are the risks for employers?
One action can trigger several at once:
- Privacy, confidentiality and IP breaches — personal, client or investigation material, trade secrets, source code and board papers disclosed externally, with no visibility.
- Inaccurate or fabricated outputs — “hallucinations” and quiet errors. Beware automation bias: because AI answers fluently, staff stop applying judgement. AI is a decision-support tool, not a decision-maker.
- Discrimination and bias — flawed outputs feeding recruitment, promotion or performance decisions.
- Cybersecurity and record-keeping gaps — unapproved apps and plugins with access to emails, files and calendars, and AI meeting assistants creating enduring records of sensitive discussions.
- Breach of professional or contractual obligations — falling foul of client agreements or sector rules.
Our top five tips: what every employer should do
- Assign clear accountability and map current use. Decide who owns AI governance and bring together HR, IT, legal/risk, privacy and the business. You cannot govern what you cannot see, so start by honestly mapping how AI is already being used across your teams.
- Publish a practical AI acceptable-use policy. A good policy enables responsible use rather than merely prohibiting risky use. It should spell out which tools are approved, what information must never be entered (personal information, privileged and confidential material, trade secrets), when approval is required, who reviews outputs, and which uses are off-limits. Draft it to encourage compliance, not avoidance.
- Take a risk-based approach with human oversight. Match controls to impact. Brainstorming, routine drafting and research summaries sit at the lower-risk end; anything touching personal information, privileged material, regulated advice or HR decisions demands stronger controls and genuine human review before an output is relied upon. The higher the legal or human impact, the greater the required oversight.
- Approve tools after due diligence — and train your people. Before approving a platform, check its contractual terms, privacy practices, data retention, model-training use, storage jurisdiction and security controls. Remember that approving a platform is not the same as approving every use or every type of data on it. Then train staff to recognise high-risk information, verify outputs, keep human judgement in the loop, and ask before using AI in doubt.
- Monitor, review and improve — lawfully. Governance is a continuing process, not a one-off. Establish incident reporting, monitor and respond, and review your arrangements as tools and the law evolve. Ensure any monitoring complies with surveillance, privacy and employment obligations, and is transparent to staff.
Frequently asked questions
- Should we just ban AI at work?
No. Blanket bans are hard to enforce, stifle legitimate productivity gains, and usually drive use underground — leaving you with less visibility and more risk. Give staff a safe, governed pathway to use AI instead.
- What information should never be entered into a public AI tool?
As a rule: personal and sensitive information, legally privileged material, confidential client and company information, trade secrets, source code, and anything covered by a confidentiality or client agreement — unless it has been specifically approved for an approved tool.
- Is it safe because of the “employee records exemption” under the Privacy Act?
Not necessarily. The exemption may apply to some employer practices, but it does not cover contractors, job applicants or customers, and it does not remove your confidentiality, contractual, security or other obligations. Treat it as a narrow provision, not a green light.
- Can we discipline an employee for misusing AI?
Yes, where they have breached a clear, lawful and reasonable policy or direction. But any response must be proportionate to the conduct, the clarity of the policy, the sensitivity of the information involved and the consequences. This is far easier to manage fairly when a policy and training already exist.
- Can we rely on AI to help with HR decisions like performance or recruitment?
Only with real human oversight. You remain responsible for accuracy, fairness and procedural correctness. AI outputs can be inaccurate or biased, so they should inform — never replace — a properly reasoned human decision.
- Is AI use actually regulated in Australia yet?
Australia does not have a single comprehensive AI Act, but existing privacy, confidentiality, IP, employment, consumer and contract laws already apply. Voluntary standards and court guidance continue to develop, and we expect greater scrutiny over time.
- Who owns what our staff create with AI?
Don’t assume you do. AI-generated material may not attract copyright protection without sufficient human authorship, and AI-suggested names, logos or designs still require proper IP clearance before use.
- Where do we start if we have nothing in place?
Assign accountability, map current use, approve a small set of tools, publish a practical policy and train your people. You can stand up a workable framework quickly and refine it over time.
How Harrisons can help
Get shadow AI wrong and the cost is real: a privacy breach, leaked IP, an unfair dismissal claim, or a decision built on a fabricated “fact.” Get it right and AI becomes a safe, genuine productivity gain. We help Australian employers — SME business owners, Queensland local government councils, and community and not-for-profit organisations — turn that risk into confident, proportionate governance.
We can help you:
- Draft a fit-for-purpose AI acceptable-use policy and governance framework.
- Design staff training and clear rules on what data can and cannot be entered.
- Build human oversight into your processes and manage any misuse fairly and lawfully.
Bring shadow AI out of the shadows. Get in touch with our team today — start with an AI use policy and governance framework built for your organisation.
This article provides general information for Australian employers and is not legal advice. Workplace laws change and how they apply depends on your specific circumstances. For advice tailored to your organisation, contact Harrisons.
Claire Harrison is the Founder and Managing Director of Harrisons, a flourishing HR consulting business that sprouted in 2009 from Claire’s passionate belief that inspiring leaders and superstar employees are the key success factor to any business. With over 20 years’ experience, Claire has worked as a HR Director of multi-national organisations, as a Non-Executive Board Director, and a small business owner. Claire’s corporate career includes working with companies such as BHP, Westpac, Fonterra and Mayne Nickless.

