The phrase “shadow AI” barely existed a couple of years ago. Now it has become one of the most talked about problems in corporate security, and it took its place at the head of the table when technology and security leaders gathered for a roundtable lunch in Brisbane hosted by industry group VITG.
The event, captured in a photo gallery published by iTnews, brought together a room of Queensland decision makers at Alchemy restaurant on the city’s riverfront to work through a problem that many of them are only beginning to get a proper handle on. The theme, security in the age of shadow AI, speaks to a shift that has caught plenty of Australian organisations off guard.
What shadow AI actually means
Shadow AI is the artificial intelligence equivalent of the old “shadow IT” problem, where employees quietly adopted their own software and cloud services because the sanctioned tools were too slow, too clunky or simply not available. The difference this time is scale and speed. Free and low-cost generative AI assistants are a browser tab away, and staff across marketing, finance, legal and operations have embraced them to draft documents, summarise meetings, write code and crunch spreadsheets, often without ever asking permission or telling anyone.
That enthusiasm is easy to understand. The productivity gains are real, and for many workers these tools have quickly become indispensable. The trouble is that every prompt typed into an unsanctioned system can carry sensitive information out the door: customer records, contract terms, source code, board papers, patient details. Once that data lands in a third-party model, an organisation has effectively lost sight of where it went and how it might be used. For security teams, it is the governance blind spot that keeps growing while nobody is watching.
The news from the table
Roundtables like the one in Brisbane are where a lot of this thinking gets thrashed out away from the vendor pitch. The value is in candid conversation between people who are wrestling with the same issue from different angles, and the shadow AI discussion tends to split fairly quickly into two camps.
One view holds that the answer is tighter control. If staff are pouring company data into consumer AI tools, the response should be to lock those tools down at the network level, block the obvious offenders and route everyone towards a vetted, enterprise-grade platform where data handling can be governed and logged. It is the instinct that has served security teams well for decades, and there is a strong case for it when the information at stake is regulated or commercially sensitive.
The competing view is that heavy-handed blocking simply drives the behaviour further underground. Staff who find their preferred assistant blocked will reach for a personal phone, a home laptop or the next tool that has not yet been added to the banned list. On this reading, the smarter play is to give people a sanctioned option that is genuinely good enough to use, pair it with clear guidance on what can and cannot be shared, and treat the whole thing as a culture and training challenge rather than a purely technical one. Visibility, in other words, beats prohibition.
Most seasoned practitioners land somewhere in between. You cannot govern what you cannot see, so the first job is discovery: working out which AI tools are already in use across the business before writing any policy at all. From there the sensible path tends to combine a small number of firm rules around the most sensitive data with a much broader effort to educate staff and offer approved alternatives that people actually want to use.
Why this matters for Australia
The Brisbane setting is a reminder that this is not just a Sydney or Melbourne headquarters problem. Queensland’s economy leans heavily on sectors where sensitive data is the whole game, including mining and resources, agriculture, health services, tourism operators and a growing state government digital footprint. Each of those brings its own compliance obligations, and each has staff experimenting with AI right now.
The regulatory backdrop sharpens the stakes. Australia’s Privacy Act reforms have lifted the bar on how organisations must handle personal information, and the mandatory data breach notification scheme means a leak that flows through an unsanctioned AI tool can turn into a reportable incident with real financial and reputational consequences. For businesses bound by APRA’s prudential standards, or those handling health records under state and federal rules, the idea of customer data quietly moving into an offshore model is exactly the kind of exposure regulators have been warning about.
There is also a sovereignty dimension that resonates locally. Much of the national conversation this year has centred on where Australian data lives and who controls the infrastructure behind it, from data centre investment to debates over AI sovereignty. Shadow AI is that same question playing out one employee at a time, usually without anyone noticing until something goes wrong.
What comes next
The direction of travel is reasonably clear. Organisations that have not yet mapped their AI usage will need to, and the market for tools that detect and manage shadow AI is expanding fast to meet that demand. Expect more Australian boards to ask for an AI usage policy in plain language, more security teams to be handed responsibility for governing tools they did not choose, and more training programs aimed at helping ordinary staff understand where the lines sit.
Roundtables such as the VITG lunch in Brisbane are a small but useful part of that shift, giving leaders a chance to compare notes and normalise the idea that shadow AI is a management problem to be shaped rather than a threat to be stamped out. The uncomfortable truth for most Australian organisations is that their people are already using these tools, whether the policy allows it or not. The question that remains is whether leadership gets ahead of it, or waits for a breach to force the issue.
Sources: iTnews



















































