Glossary · Security
Shadow AI
The use of AI tools by staff without IT or management knowledge or approval, often involving personal data sent to consumer AI products.
Browse all definitionsIn detail
Shadow AI is the organisational equivalent of shadow IT, where employees adopt AI tools independently of sanctioned processes. Typical examples include staff pasting customer data, financial information or confidential documents into ChatGPT, using personal Copilot accounts for work tasks, or building automation workflows in consumer AI tools that connect to company systems. Shadow AI creates data exposure risk (personal data sent to third party training pipelines), compliance gaps (no APP 8 cross-border assessment), security gaps (no credential management, no audit trail) and operational risk (business critical workflows built on unsanctioned tools that staff leave when they resign).
Sources & further reading
Check the source, not just the summary
- OAIC Privacy and AI guidanceoaic.gov.au
Apply the definition
Want to talk through how this applies to your business?
Start with the decision in front of you. We will help map the fit.