About CDU
We design, develop, test, maintain, and grow high-performance applications across web, mobile, and wearable platforms, harnessing technology to enhance quality of life.
READ MORE ABOUT CDUSomebody in your finance team is probably pasting client numbers into ChatGPT right now. Somebody in marketing turned on Copilot inside Outlook without telling IT. Nobody filed a project. Nobody wrote a policy. And technically, nobody did anything wrong — the tools were just there.
This is shadow AI, and if you run a business in Australia, it’s almost certainly already inside yours.
Here’s the thing: this isn’t a future risk to plan for. It’s a present-tense problem with a hard government deadline attached to it. On 10 December 2026, new transparency rules under the Privacy Act come into force, and most Australian businesses using AI haven’t mapped what they’d even need to disclose.
Not sure what’s already running in your tenant? We’ve put together a free Shadow AI Exposure Checklist — the exact eight things we check first in a Microsoft 365 environment. Get the checklist →
What “Shadow AI” Actually Means
Shadow AI is what happens when staff adopt AI tools — chat assistants, browser plug-ins, AI features baked into software you already pay for — without IT, security, or compliance ever signing off. It’s the direct descendant of “shadow IT,” the old problem of employees spinning up cloud apps the IT department never approved. Only this version is harder to see and does more damage, because the tools don’t just store your data. They read it, summarise it, and sometimes act on it.
It rarely looks like rebellion. Someone accepts a pop-up offering to “summarise this thread.” A sales rep drafts a proposal in a free AI tool because it’s faster than waiting on a template. A developer pastes a code snippet into an assistant to debug it. None of it feels like deploying artificial intelligence. It feels like using the software that’s already on the desktop.
That’s exactly why it spreads so fast — and why most leadership teams underestimate how much of it is already happening.
Why This Is Exploding in Australia Right Now
The numbers from 2026 tell a fairly stark story. Local research shows the large majority of Australian security leaders now treat generative AI itself as a security risk, and enabling safe AI use has become a top priority for most of them over the next two years. At the same time, the majority of Australian organisations have already pushed AI assistants past the pilot stage and into everyday use — while over half admit their own AI security posture is inconsistent or still catching up to what staff are already doing.
Separate research into enterprise IT architecture adds another layer: a majority of Australian companies say their systems are too rigid to properly support AI at all, which means the AI that is running is often bolted on rather than governed.
Put those together and you get adoption that’s broad, shallow, and largely unaccounted for — not because Australian businesses are reckless, but because AI arrived through the side door of software they already trusted.
The Deadline Most Businesses Haven’t Clocked: 10 December 2026
This is the part that turns shadow AI from an IT headache into a board-level compliance issue.
Under the Privacy and Other Legislation Amendment Act 2024, new clauses inserted into Australian Privacy Principle 1 (APP 1.7 to 1.9) come into effect on 10 December 2026. From that date, any APP entity that uses a computer program — including AI tools, but also simpler rule-based or automated systems — to make or substantially assist a decision that could reasonably affect someone’s rights or interests must say so in its privacy policy. That covers things like automated assessments of credit, insurance, employment, tenancy, or access to services.
The Office of the Australian Information Commissioner has been consulting on formal guidance and is expected to release it shortly before the deadline, which leaves a tight window between guidance and compliance. The OAIC is also already running privacy policy compliance sweeps in 2026, which is a fair signal about where its enforcement attention is heading next.
Here’s the catch that makes shadow AI directly relevant to this law: you can’t disclose what you don’t know is happening. If an unapproved AI tool inside your business is quietly influencing a decision about a customer, a job applicant, or a tenant, your privacy policy is already incomplete — and you may not find out until an audit or a complaint forces the question.
Where Shadow AI Hides Inside a Typical Microsoft Environment
This is the bit most generic “shadow AI” articles skip, and it’s the part that actually matters if your business runs on Microsoft 365, Dynamics, or Salesforce — which most Australian mid-market and enterprise organisations do.
- Copilot switched on tenant-wide by default. Microsoft 365 Copilot inherits whatever permissions a user already has across Teams, Outlook, SharePoint, and OneDrive. If your file permissions have been loose for years — and most organisations’ have — Copilot doesn’t create new access risk so much as it makes old access risk instantly searchable and summarisable.
- Power Platform’s AI Builder and Copilot Studio. Business users can build automated workflows and decision-assisting agents in Power Automate and Power Apps with almost no code. These count as automated decision-making under the new APP rules if they touch customer or staff data — and they’re built by people who’ve never heard of APP 1.7.
- Personal AI accounts bypassing the tenant entirely. Staff who find sanctioned Copilot too slow, too limited, or simply unavailable to their license tier fall back on free consumer AI tools in a personal browser tab — outside any Microsoft Purview audit trail.
- AI features inside connected platforms. Salesforce’s Einstein AI, embedded AI in accounting or HR platforms, and third-party plug-ins on SharePoint or Dynamics all quietly process personal data, usually without a documented risk assessment.
- Big data and reporting pipelines with AI layered on top. Once predictive scoring or automated flags get added to a data warehouse or BI dashboard, that pipeline can meet the legal definition of automated decision-making even if nobody thought of it as “AI” at all.
None of this requires a rogue employee. It requires a normal Microsoft rollout, a normal Power Platform license, and twelve months of nobody circling back to check what got switched on.
A Practical Five-Step Audit You Can Run This Quarter
You don’t need a six-month governance program to get ahead of the December deadline. You need a clear-eyed audit, in this order:
- Inventory what’s actually running. Pull Microsoft Purview and Copilot usage reports, check Power Platform’s admin centre for AI Builder and Copilot Studio apps, and review Salesforce’s AI feature settings. Most businesses are surprised by what’s already switched on.
- Map each tool against the APP 1.7 test. For every AI or automated tool touching personal information, ask: does it make, or substantially assist, a decision that could reasonably affect someone’s rights or interests? If yes, it needs disclosure.
- Fix the access problem before the AI problem. Tightening SharePoint and Teams permissions does more to reduce Copilot’s blast radius than almost any AI-specific control.
- Give staff a sanctioned, fast alternative. Shadow AI thrives when the approved option is slower or more restricted than the free public tool. A properly licensed and governed Copilot rollout usually reduces shadow use rather than increases it.
- Update the privacy policy and assign an owner. Someone specific — not “IT” as a department — needs to own the AI inventory going forward, because governance that nobody owns quietly decays within a quarter.
Reading that list and mentally counting the hours it’ll eat out of your IT team’s quarter? That’s normal — steps 1 and 2 alone usually take a Microsoft-certified team a day or two to do properly. Talk to us about running the audit for you and you’ll have the inventory and the APP 1.7 mapping without pulling anyone off their day job.
What Good AI Governance Looks Like for a Microsoft Shop
For organisations already invested in the Microsoft ecosystem, governance doesn’t mean bolting on a separate AI security product. It means using what’s already licensable — Microsoft Purview for data classification and audit trails, Entra ID for access control, and Copilot’s built-in admin controls for usage visibility — configured properly and reviewed on a set schedule, not as a one-off project.
Aligning that internal program loosely to a recognised standard such as ISO/IEC 42001 gives it structure without turning it into a compliance exercise nobody follows. The goal isn’t to ban AI. Businesses that combine sensible governance with continued AI investment are the ones capturing the productivity gains without carrying the exposure — and that balance is exactly where a Microsoft Solutions Partner earns its keep.
Where Cloud Downunder Fits In
We’re a Microsoft Solutions Partner working across cloud infrastructure, Salesforce, big data and reporting, and DevOps for Australian businesses, which puts us in the exact stack where shadow AI hides. If you’d rather not run the five-step audit above solo, we can run a Microsoft 365 and Power Platform AI audit alongside your team, map the results against the December deadline, and — if you’re short-staffed for the follow-up work — plug in specialists through our team augmentation services rather than making you hire for a six-month project.
We’ve done this kind of compliance-sensitive work before. When City Fertility needed a patient-facing app built around sensitive health data, their National IT Manager singled out how well our team handled shifting scope without losing sight of the compliance requirements underneath it — see the My Fertility Portal case study. That’s the same discipline a shadow AI audit needs: fast-moving tech work that still holds up under regulatory scrutiny.
Book Your Free Shadow AI Exposure Check
30 minutes, no sales pitch. Tell us what’s running in your Microsoft 365 tenant and we’ll tell you — honestly — whether you’ve got real exposure under the December deadline or a quick fix. Even if you decide not to go further, you’ll walk away with a clear picture of where you stand.
Book your free 30-minute consultation →
Prefer to talk it through first? Call 1300 699 571 or email hello@clouddownunder.com.au — same team, no call centre.
Frequently Asked Questions
Does the Privacy Act’s automated decision-making rule apply to small businesses?
It applies to APP entities, which generally means businesses with turnover over $3 million — but a number of smaller businesses are covered regardless of size, including health service providers and businesses that trade in personal information. If you’re unsure, it’s worth checking rather than assuming you’re exempt.
Is shadow AI illegal on its own?
No. Using an AI tool isn’t illegal by itself. The risk comes from what happens next — entering personal information into a public AI tool without a data processing agreement, or letting an unapproved tool influence a decision about a customer or employee, can put you in breach of the Privacy Act regardless of intent.
What’s the difference between shadow AI and shadow IT?
Shadow IT is staff using unapproved software. Shadow AI is a more active version of the same problem — the tool doesn’t just store data, it reads, summarises, and sometimes decides based on it, which is why it carries more compliance weight.
Does turning on Microsoft 365 Copilot count as automated decision-making?
Not automatically. Copilot summarising an email thread isn’t a decision about anyone’s rights or interests. But a Power Automate flow built on top of Copilot that scores job applicants or flags customer accounts almost certainly is — which is why the audit needs to look at what’s built on top of the platform, not just whether Copilot is switched on.
How long do we have before the deadline?
The transparency obligations commence 10 December 2026. Given the OAIC’s guidance is expected shortly before that date, businesses that wait for the guidance before starting their internal audit will have very little runway left to act on it.
Still reading? You’ve probably already spotted something you need to check.
That’s normal — most leaders can name at least one AI tool in their business nobody’s formally signed off. Get in touch and we’ll help you find the rest before 10 December does it for you.
