Walk into almost any Australian business today and the same thing is happening quietly at hundreds of desks: an employee pastes meeting notes into ChatGPT, asks Microsoft Copilot to summarise a contract, runs a client list through Google Gemini, or trials whatever new AI tool turned up on LinkedIn that week. Most of it is well-intentioned. Almost none of it is governed.

This is the new reality of AI in the workplace, and right now it looks a lot like the Wild West. Adoption has sprinted ahead of policy, controls and oversight, leaving organisations exposed in ways many leaders do not yet appreciate.
A patchwork of platforms, no one holding the reins
The problem is not that staff are using AI. It is that they are using many different AI platforms, on their own initiative, with no agreed framework for what is acceptable. The numbers are sobering. Gartner reported in 2025 that 69% of organisations suspect or have evidence that employees are using prohibited public generative AI tools. Microsoft research in 2025 found that 71% of employees admitted to using unapproved AI at work, more than half of them every week, while only a third were worried about the company data they were feeding into it.
This phenomenon now has a name: shadow AI, the unsanctioned, unmonitored use of AI tools outside any corporate policy. Industry research suggests the average enterprise harbours well over a thousand unauthorised applications, while the overwhelming majority of organisations have little to no visibility of how their data flows into and out of these tools.
Why ungoverned AI is really a data-loss problem
This is where it stops being a productivity story and becomes a security one. Every prompt is a potential data-loss event. When an employee pastes customer records, source code, pricing, board papers or health information into a public model, that data leaves your control. Depending on the platform and its settings, it may be stored, processed offshore, reviewed by people, or used to train future models, with no realistic way to claw it back.
Traditional data loss prevention (DLP) controls were never designed for this. DLP has historically watched email, USB drives and file sharing, the channels data used to leak through. AI prompts are an entirely new exfiltration channel, and most DLP tooling is simply blind to it. Cisco’s 2025 Data Privacy Benchmark Study found that 46% of organisations admit their people have fed employee or personal information into public generative AI tools, even as nearly two-thirds worry that data could leak. The risk is rarely a future attacker; it is an ordinary prompt, today.
The governance gap makes it worse. IBM’s 2025 Cost of a Data Breach research found that breaches involving shadow AI cost US$670,000 more than the average, and that 97% of organisations which suffered an AI-related security incident had no AI access controls in place, while 63% had no AI governance policy at all. In short: most businesses cannot see the problem, have no rules around it, and end up paying for it when something goes wrong.
It is not only what your staff put in. It is what walks in
Shadow AI is usually framed as data going out: your people feeding information into tools you never approved. But the same governance gap works in reverse. AI notetakers now join meetings automatically on behalf of whoever is invited, including (if an invitation goes astray) people who were never meant to be there at all. The result is an hour of unguarded conversation transcribed into a third party’s system, with nobody in the room any the wiser. See why you should never let bots auto-join your meetings, and the Microsoft Teams setting that prevents it.
Governance is the missing control layer
The answer is not to ban AI outright. That only pushes it further into the shadows and forfeits the genuine productivity gains on offer. The answer is governance: a deliberate framework that lets your people use AI safely, with the right guardrails. That means knowing which tools are approved, what data can and cannot go into them, how usage is monitored, and who is accountable when it is not.
Two international standards now give Australian businesses a ready-made structure for exactly this:
- ISO 42001 is the world’s first AI management system standard. It provides a framework for governing AI responsibly: risk assessment, acceptable-use policies, human oversight and continual improvement.
- ISO 27001 is the information security management standard. It underpins the data classification, access controls and DLP requirements that keep sensitive information out of the wrong prompts in the first place.
Together they close the loop: ISO 27001 governs your information and the controls protecting it, while ISO 42001 governs how AI is used on top of that information. Layer in foundational controls such as the Essential Eight and broader cyber and information security advisory, and ungoverned shadow AI becomes managed, monitored, sanctioned AI.
How to find the shadow AI already in your business
Governance starts with visibility, and the good news is that most Microsoft 365 businesses already own a tool that can provide it. Microsoft Defender for Cloud Apps, part of the security tooling that comes with the Microsoft 365 E5 suites and is available for Business Premium, quietly builds a picture of which cloud apps your staff actually reach. When your devices are managed through Microsoft Defender for Endpoint, it sees that traffic on and off the corporate network, with nothing extra to install.
The part that matters here is the Generative AI app category. Microsoft has catalogued more than a thousand generative AI tools, so instead of guessing you can filter your discovered apps to that category and see the real list: ChatGPT, Copilot, Gemini, Claude and the long tail of niche tools your people have found for themselves. For each one you get the numbers that turn a vague worry into a decision: how many users, how many devices, and how much data has been uploaded to it. Every app also carries a built-in risk score drawn from dozens of security and compliance factors, so you can tell at a glance which tools are reasonable and which should never have touched your data.
From there it becomes a workflow rather than a fire drill. You sanction the tools you are happy to support, block the ones you are not, and set policies that keep surfacing new generative AI apps as they appear, flagged by risk score or by how many people are using them. That is precisely the ongoing monitoring ISO 42001 asks for: not a one-off cleanup, but a standing view of how AI is really being used, reviewed on a regular cycle rather than after an incident.
Microsoft is now taking this a step further with a dedicated Shadow AI view in the Microsoft 365 admin centre, currently in preview. Where Cloud Discovery is built around web and SaaS AI tools, this newer view targets the fast-emerging risk of standalone AI agents: desktop apps and autonomous agents that run directly on a user’s machine rather than in a browser tab. It shows which agents are running, on how many devices and for how many users, and the traffic they generate, and it lets administrators block the riskiest of them on managed Windows devices. The fullest picture leans on Microsoft 365 E5, Intune-enrolled devices and Global Secure Access, so it sits a little further up the licensing ladder, but it is a clear signal of where this is heading: AI use is becoming something you are expected to see and control, not something you can later claim you never knew about.
Both of these approaches mainly see managed, enrolled devices, and that limitation is worth naming because it shapes everything else. An employee using ChatGPT from a personal laptop or phone, on their own account, stays invisible to them. That blind spot is exactly why detection alone is never enough: you still need an acceptable-use policy, data loss prevention that understands AI prompts, and people who know what good looks like. The tooling tells you where you stand today. The management system is what keeps you there.
Where to start
Discovery tells you what is happening; governance decides what to do about it. A practical next step is a gap analysis that maps which AI tools are actually in use, what data is at risk, and where your current controls fall short of standards like ISO 42001 and ISO 27001. From there you can build an acceptable-use policy, approve a safe toolset, extend your DLP coverage to include AI prompts, and train your people on what good looks like. Both standards make this a formal requirement, and our guide to cyber security awareness training and clause 7.3 shows how to meet it with free resources.
The Wild West did not stay wild forever. It was tamed by rules, structure and accountability. The same is now happening with AI in the workplace. The businesses that get ahead of it will capture the upside of AI without handing their most sensitive data to a platform they have never assessed.
Worried about shadow AI in your business? Streamline helps Australian organisations bring AI use under control through information security and AI governance aligned to ISO 27001 and ISO 42001, working with businesses in Brisbane, Sydney, Melbourne and right across Australia. Get in touch for a conversation about where your risks sit and how to close the gaps.
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











