Back to Home
Business Automation

Shadow AI: Your Staff Are Using ChatGPT at Work Right Now (Here's How to Make It Safe)

Shadow AI is staff quietly using personal ChatGPT accounts for work because there is no sanctioned path. Learn the audit checklist, the real risks, and the channel-it fix for Australian businesses.

13Labs Team25 July 20269 min read
shadow AIAI policyChatGPT at workdata securityAI adoptionbuildAutomation

Contents

What shadow AI is, and why it is already in your business

Shadow AI is what happens when your staff use personal AI accounts like ChatGPT or Claude for work tasks because the business has given them no approved way to do it. It is almost certainly already in your business. Three quarters of knowledge workers say they use AI at work (Microsoft and LinkedIn Work Trend Index, 2024), and 78 percent of those users brought the tools in themselves, a figure that rises to about 80 percent in small and medium businesses (Microsoft and LinkedIn, 2024). In a team of twenty, that usually means a dozen people quietly drafting, summarising and problem solving with accounts you have never seen. Almost none of it is defiance. Your office manager pastes an enquiry into ChatGPT because replying properly takes twenty minutes. Your estimator feeds it scope notes because formatting variations is dull. The intent is good. The problem is that all of it happens on personal accounts, outside any policy, with data you are responsible for.

Why banning it fails

Banning shadow AI fails because the ban pushes usage further underground, destroys the signal that your staff want automation, and alienates exactly the people who were most keen to learn. The technical block is leaky by design. Staff reach personal ChatGPT on their own phones in thirty seconds, or finish the work on a home laptop. What changes after a ban is not the behaviour. It is your visibility of the behaviour. You have traded a manageable risk for an invisible one. There is also a talent cost. Two thirds of leaders say they would not hire someone without AI skills (Microsoft and LinkedIn, 2024), which tells you where the job market prices AI fluency. Your keenest self-taught users are the people most likely to become your automation champions, and a ban tells them their initiative is a disciplinary issue. Meanwhile use of generative AI at work nearly doubled in six months during 2024 (Microsoft and LinkedIn, 2024). That tide does not turn because you wrote a policy.

The four real risks of shadow AI

The real risks of shadow AI are specific and boring: client data sitting in personal accounts, no audit trail, inconsistent output quality, and quiet dependence on one keen person. None of these need malice. They need only a busy Tuesday and a well-meaning employee with a deadline: - Client data in personal accounts. Prompts pasted into personal ChatGPT or Gemini accounts sit outside your control and may be retained or reviewed by the vendor. 11 percent of what employees paste into ChatGPT is confidential company data (Cyberhaven, 2023), and under the Privacy Act you are still responsible for that client data wherever it ends up. - No audit trail. You cannot see what was asked, what came back, or what was sent to a client. When something goes wrong there is nothing to review and nothing to learn from. - Inconsistent quality. Nobody checks the output, so a hallucinated figure lands in a quote or a care note, and it reads so polished that nobody questions it. - Key person risk. The one keen employee holds the prompts, the logins and the know-how. When they go on leave or resign, the unwritten workflows go with them. "Most companies are a complete mess... most of their employees are secretly using a bunch of AI tools to get parts of their work done without them telling the company. And that's creating huge risks of data leaks... it's organised chaos at best." That is Liam Ottley, an AI agency founder, describing what he finds inside client businesses (Liam Ottley, How to Automate Any Business With AI in 3 Steps, 2026).

The usage is the signal: your staff want automation

Shadow AI is evidence, not defiance. It tells you exactly which staff want automation and which tasks hurt enough that they went looking for help on their own. Read it as a live map of your admin burden. If three people privately use AI to draft enquiry replies, enquiry replies are painful. If the bookkeeper uses it to reformat bank data, that export is broken. Every secret use case is a task nomination for your first sanctioned automation, pre-validated by the person who actually does the work. Enterprise experience backs the reframing. A Google Cloud Consulting executive describing an internal rollout at Boston Consulting Group put it bluntly: "A year and a half ago, we tried something top down. It failed miserably. Technology is easy. The change journey is much harder... the catalyst has been the bottom-up part of the journey" (Boston Consulting Group, 2026). When BCG switched to bottom-up adoption, staff submitted over a hundred automation ideas every week in the first few weeks (Boston Consulting Group, 2026). Your shadow users are your bottom-up. They have already started without you.

The shadow AI audit: what to ask and what to look for

A shadow AI audit is a thirty-minute, blame-free pass through your business that answers four questions: who is using AI, which tools, with what data, on which accounts. Set the frame first. Announce it as an amnesty, not a witch-hunt, and say out loud that honest answers lead to better tools, not discipline. If people think honesty gets punished, your audit finds nothing and the risk stays exactly where it was. Then work the checklist: - Ask each person directly which AI tools they use, even occasionally, for any work task. - Ask which tasks: drafting, summarising, research, reformatting, data entry, translation, coding. - Ask which accounts: personal or business, free or paid, and who else can see the login. - Ask what data goes in: client names, health or financial details, prices, contracts, passwords. - Look for subscriptions: ChatGPT, Claude, Gemini or Copilot charges on personal cards or expense claims. - Look at work machines: browser extensions, pinned tabs and bookmarks tell the story quickly. - Look at outputs: any email or document that arrived suspiciously polished is worth a friendly how-did-you-do-this. - Write it down: one page per person, kept private, used only to design the sanctioned setup.

Channel it: sanctioned tools, training and ownership

The fix for shadow AI is to channel it: give your keenest staff sanctioned, business-grade tools, proper training, and named ownership of the automations they build. Three moves do most of the work: - Sanctioned tools. Move users onto business-tier accounts such as ChatGPT Team, Claude for Work or Microsoft 365 Copilot, where your data is excluded from training, an admin can see usage, and the account belongs to the business rather than the person. - Training. Teach prompt basics, output checking, and the one hard rule about what data never goes in. Two half-days of guided practice beats a year of policy documents. - Ownership. Every automation gets a named owner who maintains it, and every prompt and workflow lives in a business-owned vault. Key person risk dies the moment a second person can run it. This is the model behind buildAutomation, a 6 to 12 week program from 13Labs that trains two or three of your own staff to diagnose, build and own automations on your real systems (13labs.au/buildAutomation). The structure matters because missing ownership is what kills most AI efforts: 95 percent of generative AI pilots produced no measurable return in MIT's 2025 analysis (MIT Project NANDA, 2025). Ottley puts the two-sided requirement plainly: "you have to have that employee buy-in or the tools won't get used. And without the leadership buy-in, you're not going to get the budget" (Liam Ottley, 2026). Channelling gives you both. Keen staff get the tools and training they already wanted, and leadership gets governance, visibility, and a capability that stays when someone resigns.

What a governed setup looks like in a small business

A governed AI setup in a small business is simple: paid business accounts, a one-page acceptable use policy, a shared prompt library, and a named owner for every automation. Picture a 30-person trades business in Melbourne. The office manager and one estimator are the trained owners. Enquiry replies are drafted by AI under a business account, then checked by a human. Quote follow-ups and invoice reminders run on automations the owners built and documented. The policy fits on one page: what can go into AI tools, what never can, and who checks output before it leaves. The differences from shadow AI are visibility and resilience. Client data stays inside governed accounts. Output quality is checked by someone trained to check it. And when the office manager takes three weeks off, the automations keep running because they are documented and owned, not parked in a personal login. Alex Hormozi frames the end state well: "your business doesn't have to become an AI business, but you do need to use AI in your business" (Alex Hormozi, 2026). One practical note: businesses that brought in outside help with their AI rollout succeeded roughly twice as often as those that built alone (MIT, 2025). Guided beats go-it-alone, which is the entire premise of the train-to-own model.

Frequently Asked Questions

**Is shadow AI really happening in small businesses, or is it a big-company problem?** It is more common in small businesses, not less. 78 percent of people who use AI at work brought the tools in themselves, and that figure rises to about 80 percent in small and medium businesses (Microsoft and LinkedIn, 2024). Small teams rarely have an IT policy, so personal usage quietly becomes the default. **Could my business be liable for what staff paste into ChatGPT?** Yes. Under the Australian Privacy Act your business stays responsible for personal information it holds, wherever an employee puts it. If client details pasted into a personal AI account leak, that is your breach to manage. 11 percent of what employees paste into ChatGPT is confidential company data (Cyberhaven, 2023). **Should I just block AI tools on the work network?** Blocking alone fails because usage moves to personal phones and home laptops, and you lose the visibility you need. A block can work as a short stopgap while you stand up sanctioned accounts and a written policy. Without the sanctioned path, the behaviour does not stop. It hides. **What is the difference between a personal and a business AI account?** Business plans such as ChatGPT Team, Claude for Work or Microsoft 365 Copilot typically exclude your data from model training, give admins visibility over users, and keep everything under business-owned logins. Personal accounts offer none of that, and the account, the history and the prompts all leave with the employee. **Who should own AI inside a small business?** Your keenest existing staff, properly trained. Pick the two or three people already experimenting, give them sanctioned tools and real weekly hours, and make each the named owner of specific automations. Missing internal ownership is the factor most often blamed for failed AI pilots (MIT Project NANDA, 2025).

Turn your shadow users into automation owners

buildAutomation is a 6 to 12 week program that trains two or three of your keenest staff to diagnose, build and own automations on your real systems. Sanctioned tools, proper training, named ownership. When we leave, the capability stays.

Explore buildAutomation