Shadow AI policy NZ

Shadow AI in NZ Businesses: How to Find and Govern Unapproved AI Use

Find hidden AI use before it becomes hidden business risk

Shadow AI is the use of AI tools, personal accounts, browser extensions, meeting assistants, or automations outside the business's approved rules.

For a New Zealand business, the practical response is visibility: find where staff already use AI, classify the data involved, approve safe uses, restrict sensitive work, and turn high-value recurring tasks into governed workflows with human approval gates.

Shadow AI often appears because people are trying to move faster. Some of that use may be helpful. The risk is that no one has decided what information can be used, what output must be checked, or who owns the consequences.

What is shadow AI?

Shadow AI is workplace AI use that happens outside approved tools, accounts, policies, permissions, or review processes. It includes public chatbots, personal AI subscriptions, browser extensions, meeting bots, CRM plugins, inbox assistants, spreadsheet add-ons, and automations that staff connect without a business decision.

Plain-English definition for NZ businesses

In plain English, shadow AI is AI work the business cannot see or govern. The tool may be useful, but the business does not know what data entered it, what output came back, which customer or staff context was included, or whether a person checked the result before it affected someone.

Examples staff may not recognise as AI governance issues

Common examples include using a personal ChatGPT account for proposals, turning on an AI meeting note-taker for client calls, analysing exported CRM records, or generating public copy without source checks. They become risky when sensitive data, public claims, pricing, customer commitments, or live system access are involved without review.

Why shadow AI appears in small businesses

Shadow AI appears before policy because tools arrive faster than operating rules.

Staff are trying to solve real friction

Most shadow AI starts with a practical problem: too many emails, slow proposal drafting, messy notes, repeated customer questions, or inconsistent CRM updates. Treat that as a signal.

AI features are now built into everyday tools

Staff now encounter AI in search, email, documents, design tools, CRMs, meeting software, accounting add-ons, and website platforms.

The policy gap creates private judgement

Without a short AI policy for small business NZ, each staff member decides what feels safe. A better system gives everyone the same rules.

The shadow AI risks to check first

Shadow AI risk depends on the workflow, data, and consequence. Start with the places where mistakes could affect customers, staff, money, public trust, or business records.

Customer and staff information

Check whether AI tools are being used with customer records, support emails, call transcripts, staff information, complaints, employment matters, or private contact data. Business.govt.nz has useful safe and smart AI guidance, but daily controls still need to be written inside the business.

Confidential business documents

Proposals, contracts, supplier agreements, pricing strategy, unpublished IP, financial information, and internal plans should not drift into unmanaged tools.

CRM, inbox, proposal, and finance context

Risk rises when AI reads or prepares work from live systems. A draft follow-up is different from an automatic send. A CRM note is different from changing a deal stage. Use the AI Agent Permissions Checklist to separate read, draft, update, send, publish, delete, and blocked permissions.

Unsupported claims and public content

Shadow AI can create confident copy that sounds accurate but invents proof, overstates capability, changes an offer, or misses source context. Public outputs should stay human-approved until the source rules are clear.

Bounded access

A practical shadow AI discovery checklist

Do this as a visibility exercise, not a witch hunt.

1. Ask what AI tools staff already use

Ask each role: what AI tools, built-in assistants, extensions, automations, or personal accounts do you use for work? Include drafting, summaries, research, CRM help, website updates, and customer support.

2. Identify what information is being pasted, uploaded, or connected

For each tool, record the data involved. Mark it green, amber, or red. Green might be public information. Amber might need approval. Red might include customer records, credentials, financial data, HR matters, or confidential client information.

3. Separate low-risk drafting from sensitive workflow access

Low-risk AI drafting can often continue with review rules. Anything connected to CRM, inbox, finance, website publishing, customer commitments, or staff decisions should be assessed before broader use.

4. Record approved, restricted, and blocked uses

Create a short register: approved tools, acceptable use cases, restricted data, blocked actions, approval points, and workflow owners. Add recurring or consequential uses to an AI risk register for NZ businesses.

5. Look for repeated use cases worth governing

If staff use AI for the same task every week, do not leave it as private judgement. CRM cleanup, lead follow-up, inbox triage, reporting, website checks, and proposal preparation may be candidates for a controlled agent workflow.

How to turn shadow AI into governed AI adoption

The best outcome is not less useful AI. It is better-governed AI.

Keep a short approved-tool list

List the tools staff may use for business work, who owns each account, what data may enter each tool, and which use cases are allowed.

Create approval gates for customer-facing or high-risk work

Use the rule: AI can prepare, people approve consequences. Customer messages, public copy, pricing, proposals, privacy wording, finance actions, sensitive CRM updates, and staff decisions should have named human approval. The AI Governance Framework NZ shows how policy, risk, permissions, and review fit together.

Start with one workflow instead of a company-wide rollout

A small business does not need to govern every possible AI use before improving one useful workflow. Choose one repeated task, map the source data, define permissions, set the approval point, and test draft-and-review.

If the next decision is whether to buy a tool, agent platform, or consultant support, use the AI Procurement Checklist NZ before giving AI access to live systems.

Decide build, prepare, wait, or avoid

Some shadow AI use can become approved low-risk drafting. Some needs better data or policy first. Some should wait. Some should be avoided.

How the AI Agent Assessment helps

The AI Agent Assessment is designed for the moment when informal AI use is becoming operational.

Map one real workflow

The assessment identifies the workflow, owner, trigger, sources, tools, permissions, outputs, and risk points. It turns vague AI use into a clear operating map.

Define data sources, permissions, and approval gates

The assessment separates what AI may read, draft, recommend, update, send, publish, or never touch. It also names the human approval point before outputs affect customers, systems, finance, or staff.

Replace hidden tool use with a practical roadmap

The result is not a generic AI strategy. It is a decision for one workflow: build now, prepare first, wait, or do not automate.

Frequently asked questions

What is shadow AI?

Shadow AI is workplace AI use that happens outside approved business tools, accounts, policies, permissions, or review processes. It includes chatbots, personal accounts, browser extensions, meeting tools, CRM plugins, inbox assistants, and unofficial automations.

Is shadow AI illegal in New Zealand?

Shadow AI is not automatically illegal, but it can create privacy, confidentiality, security, employment, customer-trust, or commercial risks if staff use sensitive information or rely on unchecked outputs. This is not legal advice.

Should a small business ban staff from using ChatGPT?

Usually, a blanket ban is less useful than clear rules. Define approved tools, prohibited information, low-risk use cases, and human approval points. For recurring or sensitive ChatGPT use, read the ChatGPT for Business NZ AI Policy Checklist.

What should an AI policy say about unapproved AI tools?

It should say how staff request a new tool, what information must not be entered, which tasks need approval, who owns exceptions, and what happens when a tool is already being used.

How do we find shadow AI use without blaming staff?

Ask staff what tools help them work faster, what tasks they use AI for, and where they feel unsure about rules. Treat the answers as workflow evidence. The aim is visibility and safer operating rules, not punishment.

Next step

Do not let helpful AI use become an invisible operating model. Find the tools, classify the data, approve safe uses, block unsafe actions, and choose one workflow to govern properly.

Book the $1,000 AI Agent Assessment to turn hidden AI use into a controlled workflow map: what staff may use, what data stays protected, where human approval is required, and which workflow is worth building first.