Skip to main content

“I’m Shadow AI, and I’m coming for your business.”

Right now someone in your business is up against a deadline. They have a free AI tool open in a browser tab and they will close it before anyone walks past the desk. They are not trying to cause a problem. They just want the job finished. But whatever they paste into that box, a client name, your pricing, a contract, someone’s employment details, ends up somewhere you do not control and cannot get it back from.

That is Shadow AI. The video alongside runs for about 90 seconds.

Over 30 years in business








Rated 5 on Google

100% Australian Owned and Operated
Talk to us

What it looks like in practice

We come across this in client environments most weeks. It is almost never dramatic. More often it is one of these:

Someone drops a client contract into a free chatbot and asks it to pull out the key terms.
A sales spreadsheet gets uploaded because the tool will build the chart faster than Excel will.
An awkward HR email is drafted in a product nobody in the business has heard of.
A browser extension goes on in about thirty seconds. It has permission to read every page that user opens, including your finance system.
The answer comes back reading well and being wrong, and it goes out to a client before anyone checks it.

None of this turns up in a monthly report or sets off an alert. The staff doing it usually have no idea there is a problem, because from where they are sitting there isn’t one.

Blocking it does not fix it

Most owners want to block the lot at the firewall and move on. We understand why, and we have tried it. It does not hold up.

Block the products everyone has heard of and people move to the ones you have not, which are generally worse. Little in the way of security, nothing useful about where your data is stored, and often no way of making money other than the data itself. Or they will do it on their phone instead, or at home on the family laptop. The behaviour carries on. You have just lost sight of it.

The clients we see handling this well did not get there by banning things. They gave staff an approved tool that was good enough to actually use, and were clear about what can and cannot go into it.

Five steps

Where to start

01

Find out what is already being used

Start with visibility rather than paperwork. Entra ID sign-in logs, Defender for Cloud Apps, an inventory of browser extensions and your network reporting will show which AI services the business is already touching and who is using them. Most owners we do this for are surprised by the list.

02

Write a policy people will read

One page, in plain English. Which tools are approved, what must never be pasted into them, what to do when an answer looks off, and who to ask. Forty pages of legal wording gets filed away and ignored, and you end up no better off than before you wrote it.

03

Give people something approved

Microsoft 365 Copilot, or something equivalent that runs inside your own tenant, honours the permissions you already have and does not train on your data. If the approved option does the job well enough, most of the reason to go looking elsewhere disappears.

04

Put controls behind it

Conditional Access, data loss prevention rules over your sensitive material, tenant restrictions, extension allow-listing, and logging that somebody actually reads. A policy on its own depends on everyone doing the right thing every time. The controls are there to catch the rest.

05

Train people on what actually goes wrong

Staff need to know that an answer can read beautifully and still be made up, that asking a chatbot is not the same as checking, and that if they would not email something to a stranger it should not go into a prompt. We usually run about fifteen minutes on it. Longer sessions do not stick.

Not sure where you sit on any of this?

Step one is the only one you need to book. The rest follows from what it finds.

Book a review

Where Sterling IT fits

We have been doing IT since 1995, and we have seen this shape before. USB drives went the same way. So did Dropbox, and BYOD after that. A tool turns up, it solves a genuine problem for someone, staff start using it, and the business hears about it later. AI is moving quicker than any of those did, and there is a lot more sensitive material going out the door with it.

AI exposure review

What is in use across your tenant right now, and which of it is worth worrying about.

AI usage policy

One page, written around your business and your obligations rather than off a template.

Copilot readiness

Permissions tidied up first, so Copilot does not surface files people were never meant to see.

Controls and monitoring

Conditional Access, DLP, extension management, and reporting that carries on after the project finishes.

Staff training

Short sessions run around your team’s hours, on site or over Teams.

Video summary

The video is a 90-second animation in which Shadow AI speaks for itself. It describes the unapproved AI tools staff open in a hidden tab when they are under pressure, and the confidential business information it gets fed in return, which it keeps. It points out that it turns up in more than one form: sometimes a compromised app quietly taking data, sometimes an answer that is completely made up and gets passed straight on to a client. It also makes the case that banning it outright only teaches people to hide it better. The closing section covers what to do instead, including giving staff approved tools, putting an AI acceptable use policy in place, and limiting what these tools can reach.

Not sure what your team is already using?

Most of our clients were not either. Book an AI exposure review and we will show you what is actually happening in your environment, then give you a list of what to deal with first. There is no obligation to use us for the work afterwards.

Book a review
Or call us on 1300 763 699 during business hours.