IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
Shadow AI becomes security headache as workers outpace governance

Shadow AI becomes security headache as workers outpace governance

Thu, 27th Aug 2026 (Today)
David Shilovsky
DAVID SHILOVSKY Interview Editor

The rapid adoption of artificial intelligence by employees is creating a growing 'shadow AI' problem for enterprises, with organisations struggling to keep governance and security controls aligned with the pace at which workers are adopting consumer AI tools.

The gap between employee demand for AI and the ability of enterprises to govern its use is becoming a significant challenge for businesses.

That has created a rise in employees using AI applications that have not been approved or governed by their superiors, potentially exposing sensitive corporate information to public or inadequately controlled models.

The issue is particularly problematic because of AI models becoming ubiquitous on millions of devices. 

Employees can access applications such as ChatGPT, Claude or Gemini from their personal smartphones and other devices, making attempts to completely restrict their use difficult for employers, said Regional VP JAPAC at Staffbase, Ramak Salamat.

"Consumers want to use AI at a speed that enterprise governance has struggled to match," Salamat said.

Instead of making futile attempts to suppress shadow AI, Salamat argues organisations that are handling the issue effectively are first acknowledging that it exists and seeking to understand how employees are using AI.

The next step is to provide sanctioned alternatives that allow workers to perform the same tasks, while simultaneously giving organisations greater control over data, security and compliance.

"Businesses understand that it's happening," she said. "They can't deny it."

The most effective organisations are identifying which AI applications employees are already using and then providing technology that can support those use cases in a governed environment.

This approach allows businesses to maintain control without preventing employees from using technologies that may improve productivity.

However, many organisations are still trying to determine how to implement that model effectively, with CIOs, CISOs and other technology leaders under pressure to establish governance at the same speed as AI adoption.

Staffers remain major source of risk

A significant concern is whether employees fully understand the risks associated with entering company information into publicly available AI models.

Salamat suggests there is still considerable naivety among workers, particularly because AI systems can operate as something of a 'black box' in terms of how information is processed and where data ultimately goes.

"There is this black box with AI and the models and where that data goes and how it's processed," she said.

High-profile incidents involving employees entering sensitive information into public AI services have highlighted the potential consequences, but Salamat said the underlying problem was not necessarily malicious behaviour.

Instead, it was often a behavioural security issue.

"Their intentions are good," she said. "They want to use it because they want to do their job."

That distinction is particularly important in industries such as healthcare, where frontline employees can have access to personally identifiable information and highly confidential patient data.

For those workers, entering information into an unmanaged public AI service creates serious privacy, compliance and data leakage risks.

Organisations need to understand what their team members are trying to achieve with AI and then provide tools that allow them to perform those tasks safely.

AI governance not just an IT department problem

The growth of AI is also challenging the traditional model in which technology departments have primary responsibility for IT security and systems management.

Governance needs to extend beyond the IT department because these AI tools are being adopted across almost every part of a company, including sales, marketing and people management teams.

Traditional IT governance was often focused on controlling systems and infrastructure. AI introduces a broader challenge because data itself becomes central to how those systems operate.

"It's a collaboration of these departments," Salamat said. "It's a collaboration of the risk, the responsibilities, the governance."

Boards and executives must take a more active role in establishing enterprise-wide AI policies instead of delegating responsibility to CIOs and IT teams.

Pressure to invest adds another layuer of complication

At the same time, companies are facing significant pressure to invest in AI as competitors adopt new technologies and vendors promote more ambitious use cases.

Businesses could feel that they're falling behind if not investing aggressively, creating a risk that they deploy AI without first establishing a clear business case.

"There's this pressure of implementing AI without understanding the real value of it," Salamat said.

As economic scrutiny increases, companies are asking whether AI investments will improve productivity, reduce costs or otherwise deliver a measurable return.

For technology leaders, this means the business case for AI needs to go beyond the novelty of deploying the latest tool.

Shadow AI represents dangerous evolution of shadow IT

Salamat also argues that shadow AI represents a broader risk than the shadow IT problem that enterprises have dealt with for years.

While employees have traditionally installed or used unauthorised software, AI involves the movement of sensitive business information into external public models and services.

"The broader element gives it a lot more risk for any business," she said.

Potential consequences extend beyond traditional IT security into data governance, regulatory compliance, reputational damage and audit risk.

Organisations can also have formal AI policies that employees either do not understand or consider too restrictive, encouraging them to find alternative ways to access the tools they want.

Ultimately, Salamat insists businesses should stop treating AI adoption as something that can simply be prohibited.

It is not an issue that is going away anytime soon, and organisations need to accept that employees will continue to use it, particularly as AI becomes increasingly embedded in their personal lives.

The challenge for enterprise leaders is therefore to establish guardrails that allow workers to benefit from AI without exposing sensitive information.

"We have to lean into it and understand it," Salamat said.