Back to Security

Is Shadow AI a Data Breach? What Australian Businesses Get Wrong

Is Shadow AI a Data Breach? What Australian Businesses Get Wrong

Quick answer: When an employee pastes customer or business data into an AI tool that IT has not approved or configured, that is an unauthorised disclosure of personal information — the same core element that defines a data breach under the Privacy Act 1988. Whether it becomes a notifiable breach depends on whether serious harm is likely. But the disclosure itself has already happened, regardless of whether anyone reports it, notices it, or calls it that.

Most businesses picture a data breach as something that happens to them. A hacker gets in. A laptop goes missing from a car. A database gets hit and makes the news. There is a villain, a moment, and usually a headline.

Shadow AI data breach events do not look like that at all, which is precisely why they keep slipping past people who would otherwise take a breach seriously. Nobody breaks in. Nobody steals anything. An employee, trying to get through their afternoon a little faster, pastes a client's details into a chatbot to draft a follow-up email. Nothing crashes. No alert fires. Everyone moves on.

Under the Privacy Act, none of that matters to the definition. It only matters to how the incident feels.

What "Unauthorised Disclosure" Actually Means

The Notifiable Data Breaches scheme, administered by the Office of the Australian Information Commissioner, defines an eligible data breach around three elements: unauthorised access to, or unauthorised disclosure of, personal information; a likelihood of serious harm to the people involved; and an inability to prevent that harm through remedial action.

Disclosure does not require malicious intent, and it does not require the information to leave the country or end up somewhere dramatic. It simply means personal information has moved somewhere it was not authorised to go, outside the controls your business put in place to protect it.

An unmanaged AI tool, by definition, sits outside those controls. Nobody configured its retention settings. Nobody confirmed whether it trains on submitted data or for how long it is kept. Nobody agreed, on the business's behalf, that this was an acceptable place for a client's phone number, medical note, or financial detail to sit. The moment that information is typed in, an unauthorised disclosure has occurred in the technical sense the Privacy Act cares about, independent of whether the business realises it, documents it, or ever finds out.

Where This Usually Gets Missed

In our experience walking businesses through their AI exposure, the disconnect almost always comes from timing. People are trained to recognise a breach as something urgent and visible, so an AI paste job that took eleven seconds and produced a genuinely useful email does not register as an incident. It registers as normal Tuesday.

That gap between how something feels and what it legally is tends to be where the real exposure sits. A business can have perfectly good instincts about obvious risks, a locked front door, a firewall, staff who know not to click suspicious links, and still have sensitive information flowing into a dozen ungoverned AI tools every week, simply because none of those disclosures felt like the kind of event anyone had been trained to flag.

When It Clears the Notification Bar

Not every instance of shadow AI use meets the higher threshold of an eligible data breach requiring notification to the OAIC and affected individuals. That second test, whether serious harm is likely, is deliberately not automatic. Pasting a colleague's internal meeting notes into a writing assistant is a very different proposition from uploading a spreadsheet of client health records or financial account details.

The honest position is this: the disclosure has already happened the moment ungoverned data enters an unmanaged tool. Whether it escalates into a reportable breach depends on what kind of data it was, how sensitive it is, and whether the business can demonstrate it took reasonable steps to prevent or contain harm. That second part is where most businesses have nothing to point to, because nobody was tracking the disclosure in the first place. You cannot take remedial action on a data flow you never knew existed.

This is also why an AI governance conversation cannot stop at "block the obvious tools." Most shadow AI exposure now comes from AI features embedded inside platforms staff already use, not from someone consciously signing up for a new chatbot. The disclosure risk is the same either way.

Why This Changes the Accountability Conversation

Framing shadow AI as a potential breach rather than a productivity quirk changes what a reasonable business is expected to do about it. Under Australian Privacy Principle 11, entities covered by the Privacy Act are required to take reasonable steps to protect personal information they hold. "We did not know our staff were doing this" is a weaker position than most businesses assume, because ignorance of a data flow is not the same as having controls over it.

This sits alongside the layered controls most businesses already understand from frameworks such as the ACSC Essential Eight, which focuses on limiting where data can move and who can move it. AI governance is not a separate discipline bolted onto cybersecurity. It is the same discipline, applied to a newer category of tool that most access control policies were not written with in mind.

Knowing this is a breach exposure is one thing. Building the process to actually find where it is happening across your business is another, and it is worth doing properly rather than as a one-off scramble. We have written separately about what that audit process looks like in practice, including how to triage risk without turning it into a months-long project.

Frequently Asked Questions

Is using ChatGPT or another AI tool automatically a data breach?
No. Using an AI tool is not inherently a breach. It becomes a problem when personal or sensitive information is disclosed to a tool outside the business's authorised controls, and that disclosure is likely to cause serious harm if something goes wrong.

Does my business have obligations under the Privacy Act if we use AI tools?
If your business is covered by the Privacy Act 1988, generally organisations with turnover above $3 million, along with health service providers and some other categories, then yes. Australian Privacy Principle 11 requires reasonable steps to protect personal information, regardless of which tool it passes through.

What counts as "sensitive" data in this context?
Client contact details, financial information, health records, and anything that could identify an individual all count as personal information under the Act. Health information carries an even higher standard of protection.

How does Affinity MSP help with shadow AI and data breach risk?
We help businesses build a practical picture of where AI tools are actually touching client or staff data, then map that against the access controls and Essential Eight maturity the business already has in place. Rather than treating this as a one-off audit, we fold it into the same ongoing review cycle we use for access rights and vulnerability management, so new AI features that appear inside existing platforms get caught before they become a live disclosure risk.

Where Affinity MSP Fits In

We do not think shadow AI needs a scare campaign. Most staff using these tools are trying to do good work faster, not cut corners. But a business cannot claim reasonable steps under the Privacy Act if it has never asked where its own data is actually going.

Our approach starts with visibility rather than policy, because a policy nobody can enforce against tools nobody can see is not a control, it is a document. We work with clients to build a live register of AI touchpoints across the business, weigh each one against the sensitivity of the data involved, and fold that review into the same cycle we already run for access rights and vulnerability management. That way, a new AI feature that appears inside an existing platform gets flagged before it becomes a disclosure nobody can explain.

If your business has never mapped where staff-driven AI use actually touches client data, that is worth a direct conversation rather than a guess. Contact us and we will walk through what a practical first pass looks like for your environment.

Franchesca Michaela Antonio
Franchesca Michaela Antonio
Back to Security