4.1 AI for Defence · Module 4 · Shadow AI & Case Studies

What Shadow AI Is — and How Common It Is

The unsanctioned AI use already happening in your team — and the numbers behind it.

Shadow AI~12 min

The big idea

Shadow AI is the unsanctioned use of AI tools — via personal accounts, personal devices or browser plug-ins — without IT approval, security assessment or governance visibility. It's the dominant operational risk for this audience, because it's already happening: Australian surveys show roughly a quarter of public servants using unauthorised AI tools, most use self-initiated, and the overwhelming majority having had no training.

Key insight: The biggest risk usually isn't a sophisticated attack — it's a well-meaning staff member quietly pasting work into a consumer AI tool, with no policy, training or visibility around it.

What you'll see

The Australian prevalence data on shadow AI in the public sector.

The prevalence data

What the Australian research shows. Tap to expand.

Key points to remember

Shadow AI = unsanctioned AI use with no approval, assessment or visibility.
Roughly a quarter of APS staff already use unauthorised tools.
Most use is self-initiated and untrained.
The fix is a sanctioned tool + policy + training, not just a ban.