In partnership with

Free email without sacrificing your privacy

Gmail is free, but you pay with your data. Proton Mail is different.

We don’t scan your messages. We don’t sell your behavior. We don’t follow you across the internet.

Proton Mail gives you full-featured, private email without surveillance or creepy profiling. It’s email that respects your time, your attention, and your boundaries.

Email doesn’t have to cost your privacy.

Here is a question worth sitting with: do you actually know every AI tool your team is using right now, or do you know the ones you approved?

Those are very different lists, and the gap between them is called shadow AI. Not a hypothetical risk. Something that is almost certainly already true at your organization, whether or not anyone has noticed.

This is not a "ban AI" issue. It is a "you cannot protect what you cannot see" issue.

Real attack breakdown: 12,000 rows, one unauthorized upload

Between March 12 and 15, 2025, a former contractor for the New South Wales Reconstruction Authority in Australia uploaded an Excel spreadsheet to ChatGPT. The file contained more than 12,000 rows of data covering up to 3,000 people.

The people in that spreadsheet were applicants to the Northern Rivers Resilient Homes Program, a government program set up after devastating 2022 floods to help residents rebuild, elevate, or sell flood-prone homes. The data included names, addresses, email addresses, phone numbers, and in some cases personal and health information.

The department's own description of what happened is the important part: the AI tool used was not authorised for this purpose. This was not an approved system with a security gap. It was a tool nobody signed off on, used for a task nobody reviewed, holding data nobody meant to send there.

The breach was not disclosed publicly until October 2025, about six months after it happened. The Reconstruction Authority has since notified the NSW Privacy Commissioner and put new internal protocols in place for AI tool use.

Nothing about this required a hacker. It required a contractor with a task to finish and a tool that made it faster.

Why this matters right now

If this feels like an edge case, the data says otherwise.

Microsoft's Work Trend Index found that 78 percent of people using AI at work bring their own AI tools rather than using anything their organization approved or provided. At small and medium-sized companies, that number climbs to 80 percent. This is not a small business immune to the trend. If anything, it is more exposed.

Cisco's 2025 Cybersecurity Readiness Index, based on a survey of 8,000 business leaders with cybersecurity responsibilities across 30 markets, found that 60 percent of companies do not know what their employees are actually asking AI tools, and 60 percent lack confidence they could even identify unapproved AI tool use if it were happening. Twenty-two percent of companies have no restrictions at all on employee access to public AI tools.

Gartner estimates that 69 percent of organizations already suspect their employees are using prohibited AI tools, and predicts that more than 40 percent of enterprises will face a security or compliance incident tied directly to unauthorized AI use by 2030.

The pattern across all of this: shadow AI is not rare, and most organizations have limited to no visibility into it. That combination is exactly what turned a routine spreadsheet task into a privacy breach for 3,000 flood victims.

Practical fixes you can apply this week

For everyone

1. If you are using an AI tool your company did not approve, that is worth mentioning, not hiding. Most shadow AI use is not malicious. People are trying to get work done faster. Flagging it gets you a sanctioned option instead of a policy violation nobody knew about.

2. Treat any data you would not post publicly as off-limits for unapproved tools. Same instinct as our earlier issue on this: if you would not put it in a public channel, do not paste it into a tool your company has not reviewed.

3. Ask before you upload, not after. A thirty-second question to a manager or IT is cheaper than explaining a breach notification later.

For admins and IT managers

4. Give people an approved option before you write a policy against shadow AI. Prohibition without an alternative just pushes usage further out of sight. A sanctioned tool people actually want to use is the real fix.

5. Check what is already connected, not just what you approved. Microsoft 365's Enterprise Applications view (under Entra ID) and Google Workspace's API Controls both show third-party apps, AI tools included, that already have some level of access to company data. Most admins have never looked.

6. Make reporting shadow AI use low-stakes. If discovering unauthorized AI use turns into discipline, people stop telling you about it, and you lose the visibility you actually need.

This Week in "Please Don't Do That"

Someone, somewhere, is about to upload a spreadsheet full of real names, addresses, and case notes into an AI tool because it will format the columns faster than doing it by hand.

Please do not let "it will save me twenty minutes" be the whole risk assessment for other people's personal information.

If the data involves real people who did not consent to it landing in an AI tool, the twenty minutes saved is not worth what it can cost them.

Tool worth knowing: the app visibility settings you already have

You likely do not need a new product for this. You need to look at one you already pay for.

If your organization uses Microsoft 365, the Enterprise Applications view inside Entra ID (formerly Azure AD) shows third-party apps that have been granted access to company data through user sign-in, which includes a growing number of AI tools connected via OAuth. If you use Google Workspace, API Controls under Security settings does the same job.

Neither requires a purchase. Both are usually sitting unused. Spend ten minutes this week looking at what is actually connected.

Checklist tie-in

This issue is about visibility: knowing what has access to your data, even the access nobody explicitly granted. That is the same instinct behind the SecureByDefault 25-Point Security Checklist.

One question for you

If you checked your admin console today, are you confident you would recognize every app with access to your company's data?

Hit reply and tell me honestly. If the answer is no, that ten-minute check is worth doing before you read next week's issue. I read every one.

Talk soon,
Ron
Cloud and Cybersecurity Engineer, SecureByDefault

Sources

ABC News (Australia) and corroborating reporting (Cyber Daily, iTnews, Insurance Business Australia, ACS Information Age) on the NSW Reconstruction Authority ChatGPT data breach (disclosed October 2025) · Microsoft Work Trend Index, BYOAI statistics · Cisco 2025 Cybersecurity Readiness Index · Gartner research on shadow AI prevalence and projected incidents · SecureByDefault 25-Point Security Checklist

Reply

Avatar

or to participate

Recommended for you

View all
caret-right