Shadow AI and the Invisible Workforce in NZ

Shadow AI Governance

Shadow AI: managing unapproved AI use in New Zealand organisations

Shadow AI emerges when employees use artificial intelligence tools outside approved business processes. The right response is not panic or a blanket ban. It is to understand the underlying work pressure, reduce avoidable risk and provide governed alternatives that people will actually use.

Topic: AI governance Risk: Unapproved tools and data handling Response: Discover, assess and govern Market: New Zealand organisations

What is shadow AI?

Shadow AI is the use of artificial intelligence tools, accounts, extensions, applications or automated services without formal approval, visibility or governance from the organisation.

It may involve a staff member using a personal AI account to summarise a document, drafting client communications through an unapproved browser tool, connecting an AI extension to email or uploading business information into a service that has not been assessed.

Not every instance creates the same level of risk. The consequences depend on the information involved, the tool’s settings and terms, the task being completed, the organisation’s obligations and whether the output influences an important decision.

The practical issue: shadow AI is usually a symptom of unmet demand. Staff are trying to reduce work, find information or improve service faster than approved systems allow.

Why shadow AI develops inside organisations

Employees often adopt unapproved tools because they face a genuine operational problem. Workloads increase, information is difficult to find, systems remain disconnected and formal technology change takes time.

Consumer AI products are accessible and easy to test. A person can generate a summary, restructure a spreadsheet, draft a response or analyse a document within minutes. When that experience is significantly easier than the approved process, informal adoption spreads.

Administrative pressure Staff need a faster way to process documents, emails, reports and recurring requests.
Slow approved pathways Existing systems or procurement processes cannot respond quickly to emerging needs.
Limited AI guidance Employees do not know which tools, information or use cases are permitted.
Individual experimentation People begin with low-risk tasks and gradually use the tool for more sensitive work.
Disconnected workflows Manual copying between systems makes external tools feel like the simplest option.
Unclear ownership No team is responsible for evaluating and enabling practical AI use.

What risks can shadow AI create?

The central risk is loss of organisational control. The business may not know which tools are being used, what information is submitted, how outputs are checked or whether records of important work are retained.

Risk should be assessed by use case rather than assuming every tool or activity is identical. A staff member using an approved tool to rephrase public text is different from uploading personal information, confidential advice, source code or commercially sensitive records.

Privacy risk Personal information may be collected, used, stored or disclosed without appropriate assessment or safeguards.
Confidentiality risk Client, commercial, legal or employee information may enter a service outside approved contractual controls.
Accuracy risk Generated content may contain omissions, unsupported conclusions or misleading interpretations.
Decision risk Unverified outputs may influence financial, employment, service or regulatory decisions.
Recordkeeping risk Prompts, source documents, outputs and approval decisions may not be retained appropriately.
Technology risk Extensions or integrations may receive broader access to email, files or systems than staff realise.

Shadow AI and the Privacy Act 2020

The Privacy Act does not make every use of an offshore or public AI service automatically unlawful. The organisation needs to understand what personal information is involved, why it is being used, how it is protected and whether any disclosure outside New Zealand is occurring.

Privacy Principle 5 requires organisations to use safeguards that are reasonable in the circumstances to prevent loss, misuse or disclosure of personal information. Privacy Principle 12 sets rules for relevant disclosures of personal information to organisations or people outside New Zealand.

This means the correct response is an informed assessment of the tool, settings, contractual terms, data flow, access controls and use case. Local hosting may be useful for some requirements, but location alone does not establish security or compliance.

Do not assume: every public AI interaction is a reportable breach.

Do establish: what information entered the tool, what happened to it, who had authority and whether the organisation’s privacy and security requirements were met.

Relevant references include the Office of the Privacy Commissioner’s guidance on Privacy Principle 5 and Privacy Principle 12.

Why a blanket shadow AI ban often fails

A prohibition may be necessary for specific tools, information or high-risk activities. However, a general ban without a practical alternative does not address why staff adopted AI in the first place.

Employees may continue through personal devices or accounts, avoid discussing useful experiments or lose confidence that the organisation understands their workload. This can reduce visibility rather than improve control.

A stronger approach combines clear restrictions with approved tools, practical training and a pathway for evaluating new use cases. Staff need to know what is prohibited, what is permitted and where to take a legitimate operational problem.

Weak response

  • Issue a broad ban without investigating existing use.
  • Assume staff understand tool settings and data risks.
  • Provide no approved alternative for high-friction work.
  • Treat every experiment as deliberate misconduct.
  • Focus only on tools instead of the underlying workflow.

Stronger response

  • Discover current use without creating unnecessary fear.
  • Classify use cases by information, impact and access.
  • Define approved tools and prohibited activities clearly.
  • Provide a fast pathway for legitimate business needs.
  • Improve the processes driving informal adoption.

A practical shadow AI governance framework

The goal is to bring useful AI activity into a visible, controlled operating model. This requires more than publishing a policy.

01

Discover existing use

Use interviews, surveys, access reviews and workflow analysis to identify tools, tasks, information and integrations already in use.

02

Classify the risk

Assess the sensitivity of the information, the impact of the output, system permissions, human oversight and legal or contractual obligations.

03

Prioritise the underlying use cases

Identify which activities create genuine value and which should be stopped, redesigned or moved into an approved environment.

04

Set approved boundaries

Define approved tools, accounts, information classes, prohibited uses, review requirements and escalation pathways.

05

Provide governed alternatives

Introduce approved AI tools, internal knowledge systems, document workflows or purpose-built software for validated use cases.

06

Monitor and improve

Review adoption, incidents, exceptions, value and emerging tools as technology and organisational needs change.

From shadow AI to approved business capability

Some unapproved uses reveal valuable opportunities. Repeated document summarisation may signal a need for an internal knowledge system. Manual spreadsheet analysis may indicate a reporting or data-model problem. Drafting repetitive client messages may reveal a workflow that can be standardised.

The organisation should separate the useful business requirement from the unapproved implementation. The answer may be an enterprise AI licence, a secure document intelligence workflow, an internal knowledge base, an AI agent or straightforward workflow automation.

Changeable starts with the process, information, users, risks and measurable outcome. This creates an approved solution that addresses the demand behind shadow AI rather than merely suppressing it.

Shadow AI is not only a technology problem. It is evidence that employees have found a faster route through work the organisation has not yet improved.

Controls for approved AI use

Controls should be proportionate to the use case. Low-risk drafting with public information does not require the same governance as analysing personal information or preparing a high-impact decision.

Organisation-managed accounts and access controls
Approved information classifications for each tool
Documented use cases and accountable owners
Human verification for material outputs
Vendor, privacy and security assessment
Logging and recordkeeping where appropriate
Training based on realistic staff workflows
Incident and exception reporting pathways

New Zealand’s Responsible AI Guidance for the Public Service promotes generative AI use that is safe, transparent and responsible. Its principles provide a useful reference point for other organisations developing their own governance approach.

Frequently asked questions about shadow AI

What is an example of shadow AI?

An employee using a personal AI account to summarise an internal document, analyse a spreadsheet or draft client material without organisational approval is a common example.

Is all shadow AI illegal?

No. Shadow AI describes unapproved or unmanaged use, not a specific legal conclusion. The actual risk depends on the information, tool, data flow, purpose, output and applicable obligations.

Should we ban public AI tools?

Specific restrictions may be appropriate, especially for sensitive information or high-impact uses. A wider governance response should also provide approved alternatives and address the workload driving adoption.

How can we find shadow AI use?

Use staff interviews, anonymous surveys, process workshops, software and access reviews, expense records and discussions about recurring administrative work.

Does offshore AI processing breach the Privacy Act?

Not automatically. Organisations need to understand whether personal information is being disclosed, which privacy principles apply and whether appropriate safeguards and authority are in place.

How do we move staff onto approved AI tools?

Provide clear guidance, practical training, organisation-managed accounts and approved workflows that solve the real task at least as effectively as the informal tool.

Can Changeable help manage shadow AI?

Yes. Changeable can assess current use, identify risks and valuable use cases, develop governance, improve the underlying processes and build approved AI tools or workflows.

About Changeable: Changeable is a New Zealand AI and automation consultancy. We help organisations understand current AI use, improve processes, establish practical governance and build approved systems that create measurable value.

Bring shadow AI into a visible, governed operating model.

Understand what staff are using, why they are using it and which activities should be stopped, approved or replaced with a better organisational solution.