The shadow AI risks to check first
Shadow AI risk depends on the workflow, data, and consequence. Start with the places where mistakes could affect customers, staff, money, public trust, or business records.
Customer and staff information
Check whether AI tools are being used with customer records, support emails, call transcripts, staff information, complaints, employment matters, or private contact data. Business.govt.nz has useful safe and smart AI guidance, but daily controls still need to be written inside the business.
Confidential business documents
Proposals, contracts, supplier agreements, pricing strategy, unpublished IP, financial information, and internal plans should not drift into unmanaged tools.
CRM, inbox, proposal, and finance context
Risk rises when AI reads or prepares work from live systems. A draft follow-up is different from an automatic send. A CRM note is different from changing a deal stage. Use the AI Agent Permissions Checklist to separate read, draft, update, send, publish, delete, and blocked permissions.
Unsupported claims and public content
Shadow AI can create confident copy that sounds accurate but invents proof, overstates capability, changes an offer, or misses source context. Public outputs should stay human-approved until the source rules are clear.