Find the AI your staff already use, and put controls on it that hold.
APRA has told regulated entities that staff use enterprise AI tools outside approved control frameworks, and that many entities rely mainly on policy direction or after-the-fact detection, with few enforceable technical restrictions.
This page is the method for closing that gap in five stages. At the end you hold an AI inventory with an accountable owner, a recorded decision on every tool in use, and technical controls a regulator can test.
Shadow AI is any AI tool, model, service or agent that staff use without formal approval or oversight. A prompt sent to one leaves no enterprise audit trail and carries no contractual protection, and the data in it is hard to get back.
For this exercise, count approved tools used outside their approved scope as well. An organisation can run one sanctioned tool with a network block on the rest and still have staff drafting work in that tool against policy. Stage 3 covers the case.
Stage 1 of 5
Discover what staff are using.
You finish with a raw list of every AI app, personal account and agent seen on your network and devices in the last 90 days, with a user count against each. Plan on 2 to 4 weeks for this stage and the classification in stage 2 together.
Checklist
Reading the export
A CASB export tells you how many staff reached an AI site and how often.
It says nothing about what they put into it. Client data pasted into a public tool shows up only through the content inspection in the second checklist item.
APRA expects an inventory of AI tooling and AI use cases. ASIC REP 798 asks licensees whether they know where AI is used in the organisation.
Stage 2 of 5
Classify each tool and use.
You finish with an inventory. Each row records whether the provider has confirmed no retention, what data the tool has touched, and whether it feeds a decision about a person.
Checklist
The provider column puts the Privacy Commissioner's eighth expectation and the OAIC's expectation for public tools into one test. The decision flag tells you what the APP 1.7 privacy policy disclosure must list from 10 December 2026.
Worked example · Filling the provider column
| Tool | Provider confirmation | What to note in the row |
|---|---|---|
| Microsoft 365 Copilot with enterprise data protection | Yes. Prompts, responses and Microsoft Graph data are not used to train Microsoft's foundation models and are covered by the Data Protection Addendum, with Microsoft as processor. | Web queries go to Bing under separate terms, with Microsoft as controller. Third-party agents carry their own terms. |
| ChatGPT Enterprise or Team | Confirm the exclusion of customer content from training in your own agreement before you mark it yes. | Australian data residency is available for storage. Inference residency is listed only for the EU, US and UAE. |
| Any personal account | No. There is no agreement between the provider and your organisation. | Record the user count from stage 1. This row goes straight to stage 3. |
Stage 3 of 5
Decide what happens to each one.
You finish with a decision log: one outcome per use case with its reason, an accountable owner for the inventory, and a written scope for every tool you keep. Allow 4 to 6 weeks for these decisions and the controls in stage 4.
Checklist
Illustrative case · Scope against the job
An agency rolls out one AI assistant on managed devices, blocks every other public AI tool on the network and keeps every prompt auditable. Its written rule says no personal information in the assistant and no drafting of reports that contain it.
The staff it covers spend their day writing reports about people. Some of them draft those reports in the assistant anyway, because the approved scope and the job point in opposite directions. The fourth checklist item asks for scope written as tasks so that the collision shows up on paper before it shows up in the prompt log.
The Privacy Act applies to personal information used through an AI tool, sanctioned or not.
Stage 4 of 5
Put technical controls behind each decision.
You finish with a control plan that maps every decision from stage 3 to a technical control, plus a training record for each person in scope.
Checklist
Why the policy alone fails
A written ban with nothing on the network or the device to enforce it is a gap a regulator can name, and public agencies have been ordered to block generative AI tools for exactly that reason.
Staff who believe AI use breaks policy still use it, so the restriction has to sit in the technology.
APRA treats technical restrictions and staff training as expectations under CPS 230, CPS 234, CPS 220 and CPG 235, and will take stronger supervisory action where entities fail to identify, manage or control AI risks.
Stage 5 of 5
Monitor every month.
You finish with a monthly discovery run and a quarterly report to the risk committee built from it.
Checklist
Why the cadence matters
Governments have directed agencies to remove named AI products from their systems and devices at short notice.
An organisation that already runs discovery on a fixed cadence can show where every instance sits on the day the direction lands. One that has never run it starts from nothing while the deadline runs.
APRA expects boards to build enough AI literacy to challenge management on reports like this one.
Questions we get asked.
What is shadow AI?
Shadow AI is any AI tool, model, service or agent that staff use without formal approval or oversight. We also count an approved tool used outside its approved scope, because that case needs a different control.
How is shadow AI different from shadow IT?
Shadow IT is about unapproved software and access to data at rest. Shadow AI is about data leaving the organisation inside prompts and uploads, with no enterprise audit trail and no contractual data protection. It now includes AI agents that hold credentials and open external connections.
Is it illegal for staff to use ChatGPT at work?
No law in Australia or New Zealand bans it. The Privacy Act 1988 and the Privacy Act 2020 apply to any personal information entered. The OAIC expects organisations not to enter personal information into publicly available generative AI tools. The Privacy Commissioner NZ expects no personal or confidential information to go in unless the provider has explicitly confirmed it will not retain or disclose it. The Fair Work Commission has upheld breach of confidentiality as a valid reason for dismissal.
Does Copilot or ChatGPT Enterprise fix shadow AI?
They change the contract. Copilot prompts, responses and Graph data are not used to train Microsoft's foundation models and sit under its Data Protection Addendum. ChatGPT business tiers add single sign-on, SCIM, role-based access, retention controls and audit logs. Neither stops an approved tool being used outside its approved scope, and organisation-wide blocking does not reach unmanaged devices or personal networks.
How do we find shadow AI?
Start with cloud app discovery filtered to the generative AI category. Add browser and endpoint data loss prevention for pasted or uploaded content, insider risk signals for visits to AI sites, and SaaS API audits for personal-account logins. Record what you find in an inventory with an accountable owner. APRA and ASIC both expect that inventory to exist.
Should we just ban AI tools?
APRA treats policy direction and after-the-fact detection as insufficient and expects enforceable technical restrictions plus staff training. Pair each block with a sanctioned tool for the common use cases, since a block on its own leaves the demand for the tool in place.
What does the 10 December 2026 privacy change mean for shadow AI?
From 10 December 2026, Australian APP entities must describe in their privacy policy the automated decision-making that uses personal information and could significantly affect an individual. Nobody can disclose a tool the organisation does not know about, so an undiscovered tool that influences a significant decision makes the privacy policy inaccurate.
Where does this lead?
Into an AI inventory, which is the first artefact of every governance programme we run. Discovery produces the list. The AI audit in Australia or New Zealand classifies it and tests the controls. Tools from outside vendors go through third-party AI risk review (NZ version), and the models you keep go into model governance (NZ version).
Find out what is already running before the regulator asks.
An AI inventory engagement runs the five stages above with your security and privacy teams. It hands back the inventory with its provider-confirmation column and APP 1.7 flags, and a control plan the board can read.