In March 2025, a contractor working on the NSW Reconstruction Authority’s Resilient Homes Program uploaded a spreadsheet with more than 12,000 rows of flood victims’ personal and health data into ChatGPT. No one approved it. No one knew until months later.
That is shadow AI in a single sentence: capable people, under time pressure, reaching for a tool that was never assessed, never sanctioned, and never visible until the damage was already done.
The 30-second take
Shadow AI is AI used without governance, approval, or risk assessment — and it is now the norm, not the exception.
New 2026 survey data puts unsanctioned AI use among staff at well over 60%, while most organisations still have no formal AI security policy. The fix is not a ban; bans just push the behaviour further out of sight. It is visibility, ownership, and a policy staff can actually follow. Boards that treat this as an IT problem will keep discovering it the way NSW Reconstruction Authority did — after the fact.
Three signals boards can’t ignore
Samsung, 2023 — the wake-up call that didn’t stick. Within 20 days of allowing staff to use ChatGPT, Samsung semiconductor engineers pasted proprietary source code, test sequences and internal meeting notes into the tool three separate times. Samsung banned generative AI outright, retrained staff, and began building an internal alternative. Two years on, the same pattern — sensitive material pasted into a public model by someone trying to move faster — is still the leading cause of shadow AI incidents industry-wide.
NSW Reconstruction Authority, 2025 — when it happens in your own backyard. A former contractor on the $920 million Resilient Homes Program uploaded a spreadsheet containing names, addresses, contact details and health information for people affected by the 2022 floods to an unauthorised AI platform. The breach wasn’t disclosed until roughly six months after it occurred. It is now the subject of scrutiny from the NSW Information and Privacy Commission — a reminder that shadow AI incidents don’t stay internal; they become regulatory and reputational events for the organisations that fail to catch them early.
The 2026 numbers — this is now baseline behaviour, not an edge case. WatchGuard’s 2026 Global Cybersecurity Hygiene Report found unsanctioned AI tool use has become one of the fastest-growing sources of workplace cyber risk, with a large majority of staff admitting to using AI tools their employer hasn’t approved. Separately, PagerDuty’s 2026 Shadow AI Workplace Survey found two-thirds of office professionals had used AI tools at work that they believed were against company policy — and most said they’d keep using them regardless, because the tools make them faster at their job. Policy alone doesn’t change behaviour when the incentive to use the tool is stronger than the deterrent against it.
Questions your board should be asking
- Do we actually know which AI tools our people are using, or are we assuming our approved-tools list reflects reality?
- If a contractor or employee pasted client, patient, or citizen data into a public AI tool tomorrow, how long would it take us to find out — and would we find out ourselves, or from someone else?
- Is our current AI policy realistic enough that staff will actually follow it, or does it create the same gap that pushed Samsung’s engineers and the NSW contractor toward unsanctioned tools in the first place?
- Who owns shadow AI risk in our organisation today — IT, legal, risk, or no one specifically?
- Do we have any technical visibility (DLP, network monitoring, browser controls) over what data leaves the organisation via AI tools, or are we relying entirely on staff disclosure?
- When did we last test whether our incident response plan actually covers an AI-related data exposure, end to end?
Where to start
Shadow AI isn’t a technology problem to be switched off — it’s a signal that governance hasn’t kept pace with how people actually work.
The organisations getting ahead of it aren’t the ones with the strictest bans; they’re the ones with the clearest visibility, the most realistic policies, and a genuine understanding of where their own exposure sits today.
If you’re not sure where yours sits, that’s exactly what the Innovation of Risk has built to help you work through — practical tools to assess your AI risk maturity before it becomes someone else’s headline.
“Shadow AI isn’t a problem to be stamped out; it’s a signal that governance needs to catch up with how people actually work.”

