Shadow AI: your team is already using AI. The question is how.

Team exploring AI tools together at a laptop

Here is a prediction we make confidently in almost every leadership meeting: your team is already using AI. The only question is whether anyone in charge knows which tools, with which data, under which accounts.

The New Zealand picture

Datacom’s 2025 State of AI Index found 87% of NZ organisations now use AI in some form — but only 12% have scaled it beyond pilots, and over half of leaders worry about unapproved “shadow AI” use. That gap between usage and governance is where the risk lives.

Why shadow AI happens (and why banning fails)

People use unapproved AI for a very ordinary reason: it helps them get through their day. Staff paste a customer email into a free chatbot to draft a reply, summarise a contract on a personal account, or transcribe a meeting through an app nobody vetted. Ban it outright and it does not stop — it just moves to personal phones, where you have zero visibility. Prohibition converts a manageable risk into an invisible one.

What actually leaks

The exposure is rarely dramatic hacking. It is client details, financials, HR matters and commercially sensitive text flowing into consumer tools with unclear retention — outside your backups, your access controls and your Privacy Act obligations. Each instance feels trivial to the person doing it. In aggregate, it is your organisation’s information, unmanaged.

The fix: a paved road

The organisations getting this right do three simple things. They provide a sanctioned tool that is genuinely good — for Microsoft 365 businesses, Copilot Chat is included at no extra cost with eligible plans and keeps data inside your tenancy, which removes most of the excuse. They write a one-page AI policy in plain English: what is fine, what is never fine, which tool to use. And they spend a couple of hours training people — not on fear, but on getting better results from the approved tool than the shadow one ever gave them.

Wondering where your organisation actually stands? Our free AI Readiness Check covers data, permissions, policy and people in eight questions — or see how we approach AI enablement done safely.

Want this handled properly? Talk to us about AI & Copilot Enablement.

Keep reading

Related insights

Technology that just works, for organisations that matter

Managed IT, cybersecurity, Microsoft 365 and AI enablement — from a Wellington team that answers the phone.

Or call 0800 448 967.