When Employees Use AI Privately, How Does It Become a Shadow Workflow?

After AI Enters the Workflow · Season Two: “From Personal Tool to Organisational Capability” · Article 3

An employee receives a large volume of customer material every day. The company provides no approved AI service, so he uses a personal account to turn emails into summaries and copies the results back into the work system. At first, the tool merely reduces reading time. Later he creates a stable set of instructions that asks AI to assign priority, draft replies and recommend the next action. New colleagues see the improvement and copy his method.

Within months, the department has an AI workflow in substance. Customer material leaves the official environment, an external service participates in classification, AI suggestions affect the order of work, and employees paste results into formal records. Yet the workflow appears nowhere in the organisation’s process maps, risk register, training or audit trail.

This is a shadow workflow. It is more than unapproved software. Real work has formed an alternative operating path outside formal governance.

Why a prohibition does not remove the shadow workflow

Employees rarely adopt AI in order to undermine controls. They face practical friction: too much material, too little time, awkward systems, repetitive work and unrealistic output targets. A public AI tool can reduce that pressure immediately, while procurement and process reform may take months.

A rule stating “do not use unapproved AI” may therefore change visibility rather than behaviour. Employees may stop discussing use but continue it. They may remove obvious identifiers and assume the remaining material is safe. The organisation loses not the risk, but the opportunity to understand it.

Effective governance has to answer two questions at once. Which uses must stop immediately? And how can employees expose a legitimate need and obtain a safe alternative? A prohibition without the second path pushes both innovation and error underground.

What formal facts does a shadow workflow change?

If AI helps one person rewrite private notes containing no sensitive material, the risk may be limited. Once the output influences customer priority, payment, recruitment, compliance or official communication, it enters the organisation’s decision chain.

Four things have changed.

First, the data flow has changed. Information enters a processing environment the organisation has not assessed.

Second, the judgement flow has changed. Employees may rely on model classifications and omissions without recognising that reliance.

Third, the record flow has changed. The official system retains only the pasted result, not the AI input, output or human alteration.

Fourth, the responsibility flow has changed. Managers believe staff are following the established process, while staff regard AI as “only assistance”, leaving the new workflow without an owner.

The most dangerous feature is not total invisibility. It is that the formal record still looks complete.

Privacy risk is not solved by removing a name

The Office of the Australian Information Commissioner recommends, as a matter of best practice, that organisations not enter personal information—especially sensitive information—into publicly available generative AI tools. It also emphasises that the Privacy Act and Australian Privacy Principles apply to AI uses involving personal information. OAIC, “Guidance on privacy and commercially available AI products”

Deleting a name does not necessarily anonymise a case. Unusual facts, partial addresses, rare experiences or combinations of attributes may identify a person. Even where a provider promises not to use content for training, the organisation must still understand retention, access, processing locations, logs and deletion.

In 2025 workplace guidance, the OAIC recommended measures including privacy impact assessment, policies, active management of enterprise privacy settings and employee education. OAIC, “GenAI tools in the workplace”

The issue is not whether an employee trusts the product. It is whether the institution understands and accepts the complete data-processing relationship.

Shadow workflows can also acquire excessive authority

When personal tools connect to browser extensions, email, cloud drives or automation services, they no longer receive only copied text. They may read broad collections of information, send messages or modify files.

OWASP’s risk list for large-language-model applications includes sensitive information disclosure, excessive agency and overreliance. Excessive functions, permissions or autonomy can turn an error or malicious input into a larger consequence. OWASP, “Top 10 for Large Language Model Applications”

Formal systems can apply least privilege, approval gates and logging. A personally assembled workflow may use one account with broad rights and provide no dependable method of reversal.

Build a map of actual AI use

The first response should be discovery, not punishment. Anonymous surveys, team interviews, data-flow reviews, expense records and a safe help channel can reveal which tools employees use, for which tasks, with which data, and how outputs enter formal decisions. The organisation should also ask why existing systems failed to meet the need.

Australia’s government AI policy requires covered agencies to maintain internal use-case registers and establish training, impact assessment and use-case accountability. The value of this approach is that dispersed activity becomes a governable object. Digital Transformation Agency, “Policy for the responsible use of AI in government”

The register should not list only centrally procured products. AI should be identified by use. The same public chatbot may polish public text in one team and participate in a sensitive determination in another; those are not equivalent risks.

Preserve the useful discovery inside the shadow process

Shadow use often reveals the genuine point of friction in a formal process. It should be treated as evidence of need as well as evidence of non-compliance.

Common uses can be divided into three groups: low-risk assistance that may be allowed within clear boundaries; uses that require an enterprise service, permissions and evaluation before formalisation; and uses inappropriate because of law, privacy or consequence.

For the second group, the original users should participate in design. They know which steps save time and where AI fails. But the resulting system must not continue to depend on a personal account and personal memory. Instructions, sources, tests, approvals and exceptions must become organisational records.

The UK National Cyber Security Centre’s secure-AI guidance calls for organisations to identify, track and protect assets including models, data, prompts and logs, and to manage data access and supply-chain risks. NCSC, “Secure development” These are precisely the elements that must be added when a shadow process becomes a formal capability.

Discovering shadow workflows also requires a credible reporting channel. If disclosure leads only to punishment, employees will hide records and the organisation will lose the chance to learn where real risk has emerged. A better response distinguishes good-faith disclosure, carelessness and deliberate evasion: allow staff to register tools and purposes, provide a safe alternative quickly, and apply firmer boundaries where sensitive information or consequential decisions are involved. Governance should not manufacture silence. It should bring an existing change in work into a visible institutional space where it can be evaluated and corrected.

Conclusion: the real risk is not knowing that work has changed

Private AI use is not automatically a severe breach, nor is it automatically acceptable innovation. The question is whether it changes data, judgement, records and responsibility while remaining outside governance.

The organisational rule should be:

Do not manage only which AI products are permitted. Manage the work decisions into which AI has actually entered. When a shadow workflow is discovered, stop the high-risk parts, protect the data, preserve the legitimate need and rebuild acceptable uses as formal processes.

If governance can only prohibit, employees hide work. If it can only encourage, the organisation loses control. A mature system creates a usable route between real experimentation and formal responsibility.

Primary sources and further reading

Continue reading: Explore the After AI Enters the Workflow series.


Discover more from Geoffrey Chen

Subscribe to get the latest posts sent to your email.