Can You Name Every AI Tool Your Staff Used This Week?
Name every AI tool your people used this week. Not the ones you bought. All of them.
Almost nobody can. I ask this in meetings, and the answer is usually a pause, then “Copilot, Claude…I think…” then a slightly less certain “and I think a few of them use ChatGPT.” That is an honest answer, and it is nowhere near complete, which is the entire problem.
This isn’t a gotcha. It’s the same blind spot every firm has about its office keys.
The keys nobody kept a list of
Think about how many keys exist to your office.
There’s the set you carry. The practice manager has one. The cleaners were given one about six years ago. A key was cut for the accountant during the fit-out and was never returned. Someone lent one to a contractor over a long weekend in 2023. A former associate handed hers in or said she did.
Every single one of those was issued for a good reason by a sensible person solving a real problem. Nobody kept a list. And if you were asked today how many keys to your office exist and who holds them, you could not say.
That is exactly what has happened with AI inside professional firms, except it took two years instead of twenty, and the keys open your client files rather than your reception.
In May 2026 Salesforce surveyed(opens in new tab) 1,293 Australians and found that more than half, 56 per cent, of Australian workers who use AI at work are using tools that were not provided or approved by their employer. Two-thirds use at least one AI tool regularly. So for most firms, the majority of the AI in the building arrived without a decision, a contract, or a conversation.
The KPMG and University of Melbourne study of trust in AI(opens in new tab) puts the Australian figure for employees who have “used AI in ways that contravene policies and guidelines” at 44 per cent. Not people being reckless. People being efficient, in a firm that never told them where the line was.
Beware: Shadow AI is not a discipline problem. It is what happens when capable people are given a deadline and no guidance.
Five questions I would ask on Monday
None of it is technical, and you can run the first pass yourself over a coffee.
1. What tools are actually installed and signed into?
A good answer: a current list of what’s on the machines, refreshed automatically, including browser extensions and anything staff have signed into with a work email address.
A worrying answer: “our IT provider would know.” They might. Ask them for the list, see how long it takes to arrive, and check whether it covers browser-based tools at all. Most AI use in a professional firm happens in a browser tab, not in an installed application, and much of the monitoring stops at the browser’s edge.
2. What has gone into those tools?
This is the one that matters for your insurer. Client names, draft advice, a spreadsheet of holdings, a file note about a family dispute. The privacy regulator’s own guidance is blunt about why this is hard to undo: once personal information has been put into a generative AI system, it is difficult to track or control how it is used, and potentially impossible to remove. We wrote up what actually happens to the data you paste into a free AI tool a while ago, and the mechanics have not improved since.
3. Does anyone know what they’re allowed to do?
Not “is there a policy.” Whether a second-year analyst, asked on a Tuesday afternoon, could tell you in one sentence what she may and may not put into an AI tool. If the policy exists but lives in a PDF on the intranet, then the answer to this question is no.
4. Are we giving them a sanctioned option that’s actually good enough?
This is the question firms skip, and it’s the one that decides whether any of the rest works. Staff reach for outside tools when the approved ones are worse or absent. If your people have access to something proper inside your own tenant, where the data stays under your agreements, most of the shadow use evaporates on its own. Microsoft 365 Copilot is the obvious candidate for a Microsoft first firm. Banning without replacing just moves the activity somewhere you can’t see.
We’ve written before about what Copilot actually does day to day, and the truth is that it is very good at some things and unremarkable at others. Worth knowing which before you promise your people it will change their lives.
5. Who reviews this, and how often?
Once a year, at minimum, with a named person. This moves at a pace that makes an annual review feel slow.
Two important facts
The Australian evidence is thin. No Australian government body publishes a shadow AI figure. Not the ABS, not the privacy regulator, not the Signals Directorate. Every number above comes from a private survey of people self-reporting behaviour they know they aren’t supposed to have. And people aren’t the best at coming forward with this kind of candour.
The tooling is younger than the marketing. Microsoft has been shipping genuinely useful controls here, but several of the headline AI discovery features are still in preview, some require the higher-tier licences, and a few of them find one specific named agent rather than “all AI on the device.” For an accountant pasting a client file into a browser, the things that actually help are data loss prevention through Microsoft Purview, controls on the browser itself, and visibility over which cloud applications your staff are signing into. Less exciting. Considerably more effective.
I would also be careful about reaching for surveillance as the answer. There’s a real trade-off between visibility and trust, and we’ve set out both sides of the monitoring argument before. Knowing which applications are in use is a different thing from watching your people work, and the first one is what you need.
Pro-Tip: Do the discovery before you write the policy. A policy written without knowing what’s already running is a document about an imaginary firm.
Where we come in
We run an AI and shadow IT audit: what’s installed, what’s being signed into, what data is moving where, and where that sits against your obligations. You get it in writing, in language you can hand to your board, which is how we approach compliance audits generally.
Then we put the controls in. A short, readable AI policy your staff will actually follow. Data loss prevention so client information can’t be pasted into an unapproved tool in the first place. A sanctioned AI option inside your own environment so nobody needs a workaround. And a review cycle, so this doesn’t quietly drift again over the next eighteen months. It sits inside our compliance and governance work, and it is not a large project.
You will not get every key back. Nobody ever does. But you will be able to answer the question when your board asks it, and you will know that the answer is true.
If you’d like to know what’s actually running in your firm, get in touch and we’ll take a look.
About the author
Yener is the founder and Managing Director of Intuitive IT. Prior to running his own business Yener worked for a number of corporate organisations where he gained invaluable experience and skills, as well as an understanding of how IT can complement and improve business outcomes.