AI Insights · AI Security & Risk · 5 min read

Shadow AI: Managing Unsanctioned AI Use in NZ Organisations

Last updated 17 July 2026

Shadow AI is staff using AI tools that haven't been approved or governed by the organisation — typically pasting work data into personal ChatGPT accounts or free tools. It's a growing risk for New Zealand organisations because it moves sensitive data outside your control and Privacy Act safeguards. The fix is rarely a ban; it's providing a sanctioned, governed alternative and a clear policy.

Why does shadow AI happen?

It happens because staff find AI genuinely useful and no approved option exists. People aren't trying to create risk — they're trying to get work done. That's actually a positive signal of demand. But when the only available tools are personal accounts, useful behaviour turns into a data-exposure problem.

What are the risks?

  • Sensitive or personal data leaving your control and Privacy Act safeguards.
  • No visibility of what data is shared, by whom, or with which tool.
  • Inconsistent, unreviewed AI output feeding into real decisions.
  • Compliance exposure if regulated data is sent offshore.

How do you manage shadow AI?

Meet the demand safely rather than fighting it. Provide an approved, governed AI tool (an enterprise plan or a private instance), publish a short policy on what data is and isn't allowed, and give staff basic training. Banning AI outright usually just pushes usage further underground; giving people a good sanctioned option is what actually reduces risk.

How common is shadow AI in New Zealand?

It is already the norm rather than the exception. With most staff using AI and only a small minority of employers having a policy, the practical reality is that unsanctioned use is happening in nearly every organisation with knowledge workers — usually invisibly. New Zealand security leaders have noticed: staff misuse of AI is climbing the list of cyber-security concerns, which means shadow AI is no longer just a governance tidiness issue but a recognised risk to the organisation.

What does a good sanctioned alternative look like?

The alternative has to be genuinely good, or staff will keep using their personal accounts. That usually means an enterprise AI plan or a private AI instance that is at least as capable as the free tools people reach for, available to everyone who needs it, and clearly safe to use on work content. If the approved tool is slower, locked behind approvals, or worse than free ChatGPT, a policy alone will not move behaviour. The organisations that shrink shadow AI are the ones that make the safe option the easy option.

How do we write a shadow-AI policy staff will actually follow?

Keep it short, concrete and positive. Say plainly which tools are approved, what data can and cannot go into them, and where to go with a question — in a page, not a manual. Frame it around enabling safe use rather than prohibition, because a policy that reads as "no" gets ignored. Pair it with a few minutes of practical training on the difference between safe and unsafe use, and revisit it as your approved tools change. A living one-pager beats a comprehensive policy nobody reads.

Frequently asked questions

Rarely effective. Bans tend to drive usage into personal accounts you can’t see. Providing a sanctioned, governed alternative reduces risk far more than prohibition.

Assume you do — most organisations with knowledge workers do. A readiness assessment and a simple staff survey quickly reveal how widespread it is and where the risk sits.

Ready to talk it through?

Book a free discovery call. No preparation required — just tell us what you’re trying to solve.