Find the AI your staff already use, and put controls on it that hold.

APRA has told regulated entities that staff use enterprise AI tools outside approved control frameworks, and that many entities rely mainly on policy direction or after-the-fact detection, with few enforceable technical restrictions.

This page is the method for closing that gap in five stages. At the end you hold an AI inventory with an accountable owner, a recorded decision on every tool in use, and technical controls a regulator can test.

Start with stage 1

Shadow AI is any AI tool, model, service or agent that staff use without formal approval or oversight. A prompt sent to one leaves no enterprise audit trail and carries no contractual protection, and the data in it is hard to get back.

For this exercise, count approved tools used outside their approved scope as well. An organisation can run one sanctioned tool with a network block on the rest and still have staff drafting work in that tool against policy. Stage 3 covers the case.

Stage 1 of 5

Discover what staff are using.

You finish with a raw list of every AI app, personal account and agent seen on your network and devices in the last 90 days, with a user count against each. Plan on 2 to 4 weeks for this stage and the classification in stage 2 together.

Checklist

Filter the CASB app catalogue to the generative AI category and export every app seen in the last 90 days, with user counts. In Microsoft Defender for Cloud Apps the category is called Generative AI.
Turn on browser-level detection of sensitive content in prompts, and endpoint DLP for content pasted or uploaded to AI sites. Network inspection alone misses many interactions.
Audit SaaS APIs and identity logs for personal-account logins to AI services from corporate devices.
Add insider risk signals for visits to AI sites. Include browser extensions and AI agents that hold credentials in the sweep.
Run an anonymous staff survey alongside the telemetry. Staff hide AI use from a manager who might scrutinise it, so a named survey undercounts.

Reading the export

A CASB export tells you how many staff reached an AI site and how often.

It says nothing about what they put into it. Client data pasted into a public tool shows up only through the content inspection in the second checklist item.

APRA expects an inventory of AI tooling and AI use cases. ASIC REP 798 asks licensees whether they know where AI is used in the organisation.

Stage 2 of 5

Classify each tool and use.

You finish with an inventory. Each row records whether the provider has confirmed no retention, what data the tool has touched, and whether it feeds a decision about a person.

Checklist

For every tool found, record whether a signed document from the provider confirms no retention and no training on inputs. Enterprise tiers can answer yes, and personal accounts cannot.
Map each tool to the data classes it has touched (public, internal, confidential, restricted), using the DLP and browser findings.
Flag any use that makes, or substantially contributes to, a decision about a person. In New Zealand the same flag marks where the Privacy Commissioner expects an impact assessment before use. See Privacy Act 2020 compliance.
Sort every row into one of three categories: unsanctioned tool, sanctioned tool used in scope, sanctioned tool used out of scope. The third needs a different control from the first.
For APRA-regulated entities, mark any tool that touches a critical operation. It goes through the material service provider test in the CPS 230 guide.

The provider column puts the Privacy Commissioner's eighth expectation and the OAIC's expectation for public tools into one test. The decision flag tells you what the APP 1.7 privacy policy disclosure must list from 10 December 2026.

Worked example · Filling the provider column

Tool Provider confirmation What to note in the row
Microsoft 365 Copilot with enterprise data protection Yes. Prompts, responses and Microsoft Graph data are not used to train Microsoft's foundation models and are covered by the Data Protection Addendum, with Microsoft as processor. Web queries go to Bing under separate terms, with Microsoft as controller. Third-party agents carry their own terms.
ChatGPT Enterprise or Team Confirm the exclusion of customer content from training in your own agreement before you mark it yes. Australian data residency is available for storage. Inference residency is listed only for the EU, US and UAE.
Any personal account No. There is no agreement between the provider and your organisation. Record the user count from stage 1. This row goes straight to stage 3.

Stage 3 of 5

Decide what happens to each one.

You finish with a decision log: one outcome per use case with its reason, an accountable owner for the inventory, and a written scope for every tool you keep. Allow 4 to 6 weeks for these decisions and the controls in stage 4.

Checklist

Name an accountable owner for the AI inventory and set a review cadence. ASIC asks licensees whether they are confident the inventory is adequately maintained.
For each use case, choose one outcome and record the reason: provision a sanctioned equivalent, approve with conditions, or block. A block with no sanctioned alternative leaves the demand in place.
Review past submissions involving regulated or customer data for notification obligations under the Privacy Act 1988 or the Privacy Act 2020.
Write the approved scope for each sanctioned tool as the tasks it may be used for, in the language of the job.
Put the decisions into the policy. The AI policy template has an approved tools register and an incident section for this.

Illustrative case · Scope against the job

An agency rolls out one AI assistant on managed devices, blocks every other public AI tool on the network and keeps every prompt auditable. Its written rule says no personal information in the assistant and no drafting of reports that contain it.

The staff it covers spend their day writing reports about people. Some of them draft those reports in the assistant anyway, because the approved scope and the job point in opposite directions. The fourth checklist item asks for scope written as tasks so that the collision shows up on paper before it shows up in the prompt log.

The Privacy Act applies to personal information used through an AI tool, sanctioned or not.

Stage 4 of 5

Put technical controls behind each decision.

You finish with a control plan that maps every decision from stage 3 to a technical control, plus a training record for each person in scope.

Checklist

Block unsanctioned apps through the CASB, restrict by user or group through secure web access, and block installation on managed devices through MDM. Organisation-wide blocking does not reach users on unmanaged devices or personal networks, so write that gap into the plan.
Block personal-account logins to AI services on corporate devices, and apply inline DLP to the sanctioned tools.
Map the data classification matrix to tool permissions, with written approval required for restricted data.
Provision a sanctioned tool for each common use case the discovery found.
Train staff on AI use, misuse, limitations and secure practices, the headings APRA uses, and keep the attendance record as evidence.

Why the policy alone fails

A written ban with nothing on the network or the device to enforce it is a gap a regulator can name, and public agencies have been ordered to block generative AI tools for exactly that reason.

Staff who believe AI use breaks policy still use it, so the restriction has to sit in the technology.

APRA treats technical restrictions and staff training as expectations under CPS 230, CPS 234, CPS 220 and CPG 235, and will take stronger supervisory action where entities fail to identify, manage or control AI risks.

Stage 5 of 5

Monitor every month.

You finish with a monthly discovery run and a quarterly report to the risk committee built from it.

Checklist

Re-run discovery every month, and again after any change to the sanctioned list.
Audit prompts inside sanctioned tools for out-of-scope use. A network block never sees misuse of a tool it allows.
Report the inventory, the violation count and training coverage to the risk committee each quarter.
Feed every tool that survives into the risk assessment. The AI risk assessment template carries the APP 1.7 and provider-confirmation columns forward.

Why the cadence matters

Governments have directed agencies to remove named AI products from their systems and devices at short notice.

An organisation that already runs discovery on a fixed cadence can show where every instance sits on the day the direction lands. One that has never run it starts from nothing while the deadline runs.

APRA expects boards to build enough AI literacy to challenge management on reports like this one.

Questions we get asked.

What is shadow AI?

Shadow AI is any AI tool, model, service or agent that staff use without formal approval or oversight. We also count an approved tool used outside its approved scope, because that case needs a different control.

How is shadow AI different from shadow IT?

Shadow IT is about unapproved software and access to data at rest. Shadow AI is about data leaving the organisation inside prompts and uploads, with no enterprise audit trail and no contractual data protection. It now includes AI agents that hold credentials and open external connections.

Is it illegal for staff to use ChatGPT at work?

No law in Australia or New Zealand bans it. The Privacy Act 1988 and the Privacy Act 2020 apply to any personal information entered. The OAIC expects organisations not to enter personal information into publicly available generative AI tools. The Privacy Commissioner NZ expects no personal or confidential information to go in unless the provider has explicitly confirmed it will not retain or disclose it. The Fair Work Commission has upheld breach of confidentiality as a valid reason for dismissal.

Does Copilot or ChatGPT Enterprise fix shadow AI?

They change the contract. Copilot prompts, responses and Graph data are not used to train Microsoft's foundation models and sit under its Data Protection Addendum. ChatGPT business tiers add single sign-on, SCIM, role-based access, retention controls and audit logs. Neither stops an approved tool being used outside its approved scope, and organisation-wide blocking does not reach unmanaged devices or personal networks.

How do we find shadow AI?

Start with cloud app discovery filtered to the generative AI category. Add browser and endpoint data loss prevention for pasted or uploaded content, insider risk signals for visits to AI sites, and SaaS API audits for personal-account logins. Record what you find in an inventory with an accountable owner. APRA and ASIC both expect that inventory to exist.

Should we just ban AI tools?

APRA treats policy direction and after-the-fact detection as insufficient and expects enforceable technical restrictions plus staff training. Pair each block with a sanctioned tool for the common use cases, since a block on its own leaves the demand for the tool in place.

What does the 10 December 2026 privacy change mean for shadow AI?

From 10 December 2026, Australian APP entities must describe in their privacy policy the automated decision-making that uses personal information and could significantly affect an individual. Nobody can disclose a tool the organisation does not know about, so an undiscovered tool that influences a significant decision makes the privacy policy inaccurate.

Where does this lead?

Into an AI inventory, which is the first artefact of every governance programme we run. Discovery produces the list. The AI audit in Australia or New Zealand classifies it and tests the controls. Tools from outside vendors go through third-party AI risk review (NZ version), and the models you keep go into model governance (NZ version).

Find out what is already running before the regulator asks.

An AI inventory engagement runs the five stages above with your security and privacy teams. It hands back the inventory with its provider-confirmation column and APP 1.7 flags, and a control plan the board can read.

Get in Touch