Deepfake scams use AI-generated voice clones and video to impersonate a real person — usually your CEO, CFO or a supplier — and trick staff into approving a payment or handing over credentials. They are already hitting Australian businesses, and they work because they exploit trust in a familiar voice or face rather than a dodgy link.
What changed: the technology caught up
For years, the weak link in business fraud was the writing. A scam email asking the accounts team to urgently pay a new supplier account often gave itself away — odd phrasing, a misspelt name, a tone the real boss would never use. Staff learned to spot it.
That tell has gone. Modern voice-cloning tools need only a few seconds of clean audio to produce a convincing copy of someone’s voice, saying anything you type. A LinkedIn video, a conference talk on YouTube, a podcast appearance, a voicemail greeting, even a recorded webinar — that is more than enough source material. The output is good enough to fool a colleague who speaks to that person every day, especially over a phone line or a slightly glitchy Teams call where audio quality is already degraded.
Video deepfakes have followed. The widely reported 2024 case in Hong Kong, where a finance worker paid out roughly AUD $39 million after joining a video call with what he believed were several senior colleagues — every one of them a deepfake — is the example everyone cites because it proves the technique scales to live, multi-person video. You no longer need to be a nation-state to run it. The tools are commodity, cheap, and getting easier to use by the month.
How the attack actually plays out
This is not theoretical, and it is not science fiction. It is a refinement of business email compromise (BEC), the fraud that the Australian Cyber Security Centre (ACSC) and ReportCyber already rank among the most costly facing Australian businesses. We wrote about the email side of this in our guide to business email security and BEC. Voice and video are the new front end on the same con.
The pattern is consistent. The attacker has done their homework — they know the names of your finance staff, who reports to whom, and often that a director is travelling or otherwise hard to reach. Then they apply pressure through a channel that feels personal:
- A phone call or voicemail from “the managing director”, voice cloned, instructing accounts to release a payment before close of business because a deal is about to fall over.
- A Teams or WhatsApp voice note from “the CFO” that sounds exactly right, authorising a transfer to a new account and asking the recipient to keep it quiet until it is done.
- A short video call where the face and voice of a senior leader appear on screen, lending authority to an instruction that would normally need paperwork.
- A “supplier” calling to confirm that their bank details have changed, following up an email you were already half-expecting.
Every version leans on the same three levers: authority (it is the boss), urgency (it has to happen now) and secrecy (don’t loop anyone else in). Those three together should be a red flag regardless of how convincing the voice is. Genuine executives almost never combine all three.
Why this supercharges BEC
Classic BEC relied on a spoofed or compromised email account and the victim not picking up the phone to check. The standard advice — “if in doubt, call the person directly” — was the defence. Voice cloning attacks that defence head-on. Now the phone call itself can be the fraud. When the verification channel and the attack channel are the same, the old safety net is gone, and you need a new one.
A Melbourne scenario
Picture a construction firm in Box Hill, mid-afternoon on a Friday. The accounts manager gets a voicemail that sounds unmistakably like the director, who everyone knows is on site at a job in Geelong and notoriously hard to reach. He says a subcontractor needs to be paid today to keep a pour on schedule, the bank details are in a follow-up email, and he is heading into a meeting so just get it done — he will sign off properly Monday. The email arrives moments later from what looks like his address. The voice was right. The story was plausible. The pressure was real.
The only thing that saves that firm is a process that does not depend on recognising the voice — because the voice was perfect. A business we work with in the eastern suburbs had a near-miss almost exactly like this. What stopped it was a boring rule: any change to payment details, or any new payee over a set dollar threshold, gets verified by calling the requester back on the number already in the contact system, never a number supplied in the request. The accounts manager rang the director’s real mobile, got no urgent payment story at all, and the fraud collapsed.
Defences that actually work
You cannot reliably train staff to detect a good deepfake by ear or eye any more — that race is lost, and pretending otherwise sets people up to fail. The defences that hold up are about process and verification, not detection. Technology helps at the edges; controls do the heavy lifting.
Out-of-band verification and callback procedures
This is the single most effective control. Any instruction to move money, change bank details or release sensitive data must be confirmed through a different channel than the one it arrived on — and a channel the attacker does not control. If the request came by call or voice note, verify by a different route: call back on the known number stored in your system, message them on an established internal channel, or confirm in person. Never use contact details supplied in the request itself. The whole point is that a cloned voice cannot also intercept the verification.
Payment controls and dual approval
No single person should be able to release a significant payment or change a payee unilaterally. Dual authorisation — a second, independent person who approves transfers over a threshold — means one fooled employee is not enough to lose the money. Set sensible thresholds, enforce them in your accounting and banking platforms, and make exceptions impossible rather than merely discouraged. Most banks support transaction limits and multi-signatory approval; use them.
A code word for fund transfers
Agree a verbal pass-phrase, known only to the people who authorise payments, that must be stated to confirm any urgent or unusual transfer. A deepfake can clone a voice but it does not know the secret word that was never written down or spoken online. It is low-tech, it costs nothing, and it works precisely because the attacker has no way to obtain it from public footage.
Staff awareness, framed correctly
Train people on the pattern, not the polish. Staff should treat any combination of authority, urgency and secrecy as a trigger to verify, full stop — regardless of how genuine the voice or face seems. Make it explicitly safe, even expected, for a junior staff member to slow down and check an instruction that appears to come from the CEO. The culture has to make verification normal, not insubordinate.
Limit your public voice and video footprint
Cloning needs source audio and video. The more of your executives’ voices and faces sit publicly online, the easier the job. You will never eliminate this — and senior people often need a public profile — but it is worth being deliberate about what gets posted, and aware that anyone with a prominent media presence is a higher-value target who warrants tighter payment controls.
Email security underneath it all
Most of these attacks still pair the voice or video with a supporting email, so the email layer matters. Properly configured SPF, DKIM and DMARC to stop domain spoofing, anti-impersonation rules that flag display-name lookalikes, and conditional access to lock down accounts all reduce the surface. This is core to our cybersecurity services, and we cover the email-specific side in detail in the BEC guide. Strong authentication matters too — if attackers cannot get into the real mailbox, they cannot send the convincing follow-up from the genuine address.
What to do if you have been hit
Speed matters enormously with payment fraud, because the money moves fast and recovery odds fall by the hour. If you suspect a deepfake or voice-clone scam has succeeded, or nearly has:
- Call your bank immediately. Ask them to attempt a recall or freeze on the transfer. The first hour or two is when funds are most likely to be recoverable.
- Report to ReportCyber (cyber.gov.au) and, for the scam itself, to Scamwatch (run by the National Anti-Scam Centre). These reports feed the national picture and can assist tracing.
- Lock down internally. Reset credentials on any account that may have been compromised, check mailbox rules for malicious forwarding, and review what else the attacker may have accessed.
- Tell your people. Warn staff that an attack is in progress so a second or third attempt does not land. These campaigns often target several employees.
- Check your obligations. If personal information was exposed, the Notifiable Data Breaches scheme under the Office of the Australian Information Commissioner (OAIC) may require notification. Get advice quickly.
- Preserve evidence. Keep the voicemail, the call records, the emails and any video. Do not delete anything — it matters for the bank, the police and your insurer.
If you carry cyber insurance, notify your insurer early; social-engineering and fund-transfer fraud cover varies widely between policies and many have strict notification windows.
Frequently asked questions
How little audio is really needed to clone a voice?
A few seconds of clear speech is enough for current consumer tools to produce a usable clone, and a minute or two yields something genuinely convincing. Given that most business leaders have video, podcast or webinar audio publicly available, attackers rarely struggle for source material. Assume any voice with a public footprint can be cloned.
Can we just train staff to spot deepfakes?
No, and relying on that is dangerous. Good deepfakes already fool people who know the real person well, and the quality keeps improving. Train staff to follow verification processes regardless of how authentic something seems. The defence is procedural — callback verification, dual approval, a code word — not human lie-detection.
Is this just a problem for big companies?
No. Small and mid-sized businesses are arguably easier targets because they often lack formal payment controls and have flatter structures where one person can authorise a transfer. Attackers go where the friction is lowest. A 15-person firm with no dual-approval rule is a softer target than a large enterprise with locked-down finance controls.
Does multi-factor authentication stop these scams?
It helps but does not solve it. Strong authentication stops attackers logging into your real accounts to send convincing emails, which is valuable. But a voice-clone scam can work entirely outside your systems — a phone call to your accounts team referencing a legitimate-looking email. You still need the payment-verification controls on top of good authentication.
The short version
Deepfake and voice-clone fraud is BEC with a far more convincing front end, and it is landing on Australian businesses now. You cannot train your way to spotting a perfect clone, so the answer is process: out-of-band callback verification on a known number, dual approval over a threshold, a code word for transfers, and email security underneath. Those controls do not care how good the fake is. As a Melbourne-based MSP founded in 2014, with 13 Australian-employed engineers and a 24/7 NOC in Tecoma, we set these controls up so a convincing voice on the phone is not enough to move your money. If you want a straight assessment of where your payment and email controls stand, get in touch.
AI data governance is how you stop staff pasting confidential, customer or regulated information into public AI tools where it can be retained and reused. The fix is not banning AI. It is steering people onto sanctioned, commercially protected tools and putting technical controls around the data itself.
Every Melbourne SME we work with has the same quiet problem: people are already using ChatGPT, Gemini and Copilot, whether or not anyone approved it. The data has already started moving. Governance is about catching up to that reality before it bites.
The actual risk: your data ends up in someone else’s model
When a staff member pastes a slab of text into a free, consumer AI tool, that text leaves your control. Depending on the product and the account tier, it may be stored on the provider’s servers, reviewed by humans for quality, and used to train future versions of the model. That is the part that catches people out — not a dramatic breach, just an employee trying to work faster.
The realistic scenarios are mundane and that is what makes them common:
- A bookkeeper pastes a payroll export into a free chatbot to “summarise the anomalies” — names, salaries and Tax File Numbers go with it.
- A lawyer drops a draft settlement deed in to “tighten the language” — privileged client material, now sitting on an external service.
- A sales rep uploads the full customer list to “write a follow-up campaign” — personal information of hundreds of people, handed to a third party with no agreement in place.
- A clinic manager pastes patient correspondence in to “make it sound friendlier” — health information, the most sensitive category there is.
None of these people are reckless. They are using a tool that is genuinely useful, on data they handle every day, without realising the back end works differently to Office or their line-of-business app. That is the gap governance closes.
Consumer AI vs commercial AI: the difference that matters
Not all AI tools treat your data the same way, and the difference is entirely about which account you are signed into. This is the single most important thing to get staff to understand.
Consumer tiers — a free ChatGPT account, a personal Gmail’s Gemini, a chatbot someone signed up for with their own email — generally reserve the right to retain prompts and use them to improve the model. The provider’s consumer terms, not a commercial contract, govern what happens to your data.
Enterprise and business tiers — the paid, commercially licensed versions tied to your organisation — come with explicit data-protection commitments. Prompts are not used to train the underlying models, data stays within a contractual boundary, and you get administrative controls. The same brand can sit on either side of that line depending on the plan.
| Tool | Consumer / free tier | Commercial / enterprise tier |
|---|
| ChatGPT | Prompts may be retained and used to improve models | ChatGPT Team / Enterprise — prompts not used for training, data stays in your workspace |
| Microsoft Copilot | Personal Copilot — consumer terms apply | Microsoft 365 Copilot — commercial data protection, prompts and data not used to train foundation models, stays within the Microsoft 365 service boundary |
| Google Gemini | Personal-account Gemini — may be reviewed and retained | Gemini for Google Workspace — enterprise data protection, content not used for training |
The practical instruction for staff is short: if AI work involves anything that is not already public, it goes through the sanctioned, organisation-signed-in tool — never a personal or free account. Microsoft 365 Copilot in particular sits inside the same service boundary as your existing Microsoft 365 data, which is why it is the natural starting point for most Melbourne SMEs already on Business Premium. Our guide to what is included with Microsoft 365 support in Melbourne covers where Copilot fits.
The Australian regulatory angle
This is not just a tidiness issue. Feeding personal information into an uncontrolled AND offshore service can put you on the wrong side of the Privacy Act 1988.
Under the Australian Privacy Principles (APPs), you must take reasonable steps to protect personal information (APP 11) and you carry obligations when personal information crosses borders to an overseas recipient (APP 8). Most consumer AI services process data offshore, which means an employee pasting customer data into a free tool can quietly trigger a cross-border disclosure you never assessed or agreed to.
The privacy reforms passed in late 2024 sharpened the picture. They introduced a statutory tort for serious invasions of privacy, strengthened enforcement powers for the Office of the Australian Information Commissioner (OAIC), and signalled tighter expectations around automated decision-making and transparency. The direction of travel is clear: regulators expect organisations to know where personal information goes and to be able to show they controlled it.
Sensitive information — health, biometric, and similar categories — attracts a higher bar again. A health service that lets staff paste patient details into a consumer chatbot has a genuine problem, not a theoretical one. If you operate in that space, our note on healthcare IT support and OAIC obligations is worth a read. The point for everyone else: regulated and customer data needs governance before it goes anywhere near a model.
The technical controls that actually work
A policy document on its own changes nothing. The control that holds is the one that does not depend on every employee remembering a rule at the moment they are busy. Here is the stack we put in place, roughly in order.
An AU-aligned AI acceptable use policy
You still need the policy — it sets the expectation, names the sanctioned tools, and gives you something to point to. The key is that it must be specific to your tools and your obligations, not a generic template. We have written separately about building an acceptable use policy that staff actually follow; the short version is that it should name which tools are approved, what data must never go into any AI tool, and who to ask when unsure. Treat the policy as the starting line, not the finish.
Sanctioned tools, properly licensed
Give people a good, approved option and most of the problem evaporates. Staff reach for free tools because nothing better was offered. Roll out Microsoft 365 Copilot or Gemini for Workspace on the right licence, sign them in under the organisation account, and the data stays inside the commercial boundary by default. Sanctioning a tool is cheaper than cleaning up after an uncontrolled one.
Microsoft Purview sensitivity labels and DLP
This is where governance gets teeth. Sensitivity labels tag and can encrypt your most sensitive files, and Data Loss Prevention (DLP) inspects content and acts on it. A DLP policy can warn or block when someone tries to send a document full of Tax File Numbers or Medicare numbers to an external destination — including, increasingly, paste actions into a browser-based AI tool via endpoint DLP. Labelling and DLP are also what govern what Copilot itself is allowed to surface internally. We cover the full setup in our piece on Microsoft 365 data governance, but the headline is that labels plus DLP are the data-layer control that does not rely on goodwill.
Conditional access
Identity controls decide who can reach the sanctioned tools and from where. Conditional access policies let you require a managed, compliant device and an MFA-verified identity before someone touches the corporate AI tools, and let you block access from unmanaged personal devices where you have no visibility. This is the difference between “we hope people use the right account” and “the wrong account simply cannot reach our data”.
Staff training
Controls reduce the blast radius; training reduces how often the trigger gets pulled. People need to understand, in plain terms, why a free chatbot is different from the signed-in corporate one, and what counts as data they must not paste. A fifteen-minute briefing that shows the consumer-versus-commercial difference does more than a fifty-page policy nobody reads.
Govern before you adopt
The mistake we see most is enthusiasm-first: a business rolls AI out across the company, then thinks about data governance when something goes wrong. Reverse it. Decide what data is sensitive, label and protect it, set DLP rules, pick and license your sanctioned tools, lock access with conditional access, then turn AI loose. Governance first is not slower — it is the only version that does not generate a clean-up project six months later.
A Box Hill scenario
An accounting firm in Box Hill we work with came to us after a partner noticed staff using personal ChatGPT accounts to draft client letters — pasting in figures, names and TFNs as they went. Nobody had done anything malicious; the firm had simply never offered an approved tool or said where the line was. We rolled out Microsoft 365 Copilot under their existing Business Premium licences, applied Confidential sensitivity labels with encryption to their client folders, set DLP rules on TFNs and Medicare numbers, and used conditional access so the corporate tools only worked from managed devices. We paired it with a short staff session on the consumer-versus-commercial difference. The firm now has a faster, sanctioned tool and a defensible answer if the OAIC or their professional indemnity insurer ever asks how client data is controlled.
TechAssist has run Microsoft 365 for Melbourne SMEs since 2014, with thirteen Australian-employed engineers and a 24/7 NOC in Tecoma. The govern-then-adopt review has quietly become one of the more common pieces of work we do as AI tools spread through workplaces.
Frequently asked questions
Is it safe to use ChatGPT for work?
It depends entirely on the account. A free or personal ChatGPT account may retain your prompts and use them to improve the model, so it is not appropriate for confidential, customer or regulated data. ChatGPT Team or Enterprise, signed in under your organisation, does not use your prompts for training and is a reasonable sanctioned tool. The rule of thumb: anything not already public goes only through the approved, organisation-licensed tool.
Does Microsoft 365 Copilot use our data to train its models?
No. Microsoft 365 Copilot operates under commercial data-protection commitments. Your prompts, responses and organisational data are not used to train the underlying foundation models and stay within the Microsoft 365 service boundary. That is precisely why it is a safer default than a personal AI account for business data.
Can staff pasting data into AI tools breach the Privacy Act?
It can. Pasting personal information into a consumer AI service that processes data offshore can amount to a cross-border disclosure under APP 8 and a failure to take reasonable security steps under APP 11. Sensitive information such as health data raises the bar further. Sanctioned tools, sensitivity labels and DLP are how you keep that data inside controls you can demonstrate to the OAIC.
How do we stop people using free AI tools without banning AI entirely?
You give them a good sanctioned alternative and put controls around the data. License a commercial tool such as Microsoft 365 Copilot or Gemini for Workspace, apply Purview sensitivity labels and DLP, enforce conditional access so the corporate tools only work from managed devices, and back it with a short, specific acceptable use policy and training. Most uncontrolled use stops once a better, approved option exists.
Where to start
You do not need to solve everything at once. Decide which data is genuinely sensitive, license one sanctioned AI tool, switch on a couple of DLP rules in audit mode, and run a fifteen-minute staff briefing. That alone moves you from “people are doing whatever” to a defensible, governed position.
If you would like a hand scoping an AI data governance rollout — sanctioned tools, Purview labels and DLP, conditional access and a policy that fits your obligations — talk to our cyber security team, or get in touch with TechAssist. We will tell you plainly what to lock down first and what you can safely leave alone.
Shadow AI is the unapproved use of artificial intelligence tools by your staff — pasting company data into ChatGPT, running client calls through a free transcription app, installing a browser AI extension — without IT knowing or approving it. It is happening in your business right now, whether you have a policy or not.
The instinct is to ban it. That fails. This post covers what shadow AI actually looks like, the real risks, how to find what is already in use, and how to give staff a safe option instead of a locked door.
What shadow AI actually is
Shadow AI is the AI cousin of shadow IT — staff using software the business never sanctioned. The difference is that AI tools are free, browser-based, genuinely useful, and they ingest whatever you feed them. That makes adoption fast and the data exposure quiet. In a typical Melbourne SME it shows up as:
- Public chatbots — staff pasting contracts, client emails, financials or source code into the free tiers of ChatGPT, Google Gemini or Claude to summarise, rewrite or debug.
- Free transcription tools — meeting bots that join Teams or Zoom calls and quietly record and transcribe board meetings, HR discussions and client briefings to a third-party server.
- Browser AI extensions — Chrome and Edge add-ons that promise to “summarise this page” while reading everything on screen, including data inside your line-of-business apps.
- AI features bolted onto consumer apps — note-takers, design tools and PDF readers that have added an AI feature most users never think twice about.
None of this is malicious. It is a marketing manager hitting a deadline, an accounts clerk speeding up a reconciliation, a salesperson who wants their call notes written for them. The intent is fine. The data trail is the problem.
The real risks
The risks are concrete, and several carry legal weight in Australia.
Confidential and customer data leaving the business
When someone pastes a client list, a draft contract or a spreadsheet of personal details into a public AI tool, that data has left your control. On free and consumer tiers you generally have no contractual data-handling guarantees, no Australian data residency, and limited ability to demand deletion. Once it is out, it is out.
Your data becoming training data
Several consumer AI services reserve the right to use submitted content to improve their models unless you are on a paid plan that explicitly opts out. A confidential prompt today could influence an answer given to a stranger tomorrow. For a law firm, an accountant or anyone handling commercial-in-confidence material, that is a genuine professional problem.
Intellectual property and privacy breaches
Feeding proprietary code, product designs or unpublished strategy into an external tool can weaken your claim over that IP. More seriously, if the data includes personal information — names, contact details, health or financial records — you are likely engaging the Privacy Act 1988 and the Australian Privacy Principles, which require reasonable steps to protect personal information and to control offshore disclosures. A staff member uploading a customer database to a US-hosted chatbot can put you on the wrong side of those obligations, and a serious breach is reportable to the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme.
Inaccurate output, trusted blindly
The risk that gets least attention is the most common in practice. AI tools produce confident, fluent answers that are sometimes wrong — fabricated case citations, invented figures, misremembered policy. When staff paste that output straight into client advice, a board paper or a compliance document without checking it, the error is now yours. The tool does not sign off on the work; your business does.
Why banning it outright fails
The first reaction from a nervous business owner is “block all of it”. It does not work, for three reasons.
First, the tools are too accessible. You can block a domain on the corporate network, but staff will use their phone, home laptop or personal browser profile. You have not removed the risk; you have just lost sight of it.
Second, AI genuinely makes people faster and your competitors are using it. A blanket ban tells your best people the business is behind, and they will route around it.
Third, a ban with no sanctioned alternative guarantees the worst outcome: people still use AI, but only the unmonitored consumer versions, because you gave them nothing else. The goal is not zero AI. It is governed AI — the same logic that underpins sensible cyber security everywhere else.
How to discover what is already in use
You cannot govern what you cannot see, and most businesses have no idea how deep shadow AI already runs. Three practical ways to find out:
- SaaS and cloud app discovery (CASB) — a Cloud Access Security Broker, or the app-discovery capability in Microsoft Defender for Cloud Apps, inventories which cloud services staff sign into and ranks them by risk. The fastest way to see that thirty people are logging into AI tools you never approved.
- Network and DNS logs — your firewall and DNS resolver already record outbound connections. Filtering for known AI domains shows traffic volume and which devices generate it, even before you have a CASB in place.
- Conversations — the most underrated method. Ask teams, without blame, what AI tools they use and why. People are usually happy to tell you, because they do not see it as a security issue. That honesty tells you where to provide a safe option.
A construction firm in Box Hill we work with ran exactly this exercise. A discovery scan plus a few honest conversations turned up four AI transcription tools quietly joining site-coordination meetings, and two project managers pasting subcontractor agreements into a public chatbot to summarise variations. Nobody was acting in bad faith. They simply had no sanctioned tool and no rule telling them where the line sat.
Building a sane AI position
The fix is a short, clear acceptable-use position backed by a real alternative — not a 40-page policy nobody reads.
A short acceptable-use position
Write a one-page AI acceptable-use statement that answers the questions staff actually have: which tools are approved, what data must never go into a public tool (client personal information, financials, contracts, anything under NDA), and that AI output must be checked by a human before it is used in client work. A policy people understand is worth ten they ignore.
Provide a sanctioned, safe option
This is the part most businesses skip, and the part that makes the policy stick. Give staff an enterprise-grade AI tool with proper data protections — most commonly Microsoft 365 Copilot, which operates inside your tenant, respects existing permissions, and does not use your prompts to train public models. When people have a fast, sanctioned tool that works, the pull towards consumer apps drops sharply.
The catch is that Copilot surfaces anything the asking user can already reach, so loose permissions become a liability the moment you switch it on. That is why governance comes first, and why conditional access policies matter for controlling which devices and users can reach these tools at all. The data-governance groundwork sits alongside the rest of your Microsoft 365 setup.
The governance and DLP layer
A policy tells people what to do; technical controls back it up when they forget. This is the AI data governance layer, and for Microsoft 365 businesses it largely lives in Microsoft Purview.
Two Purview capabilities do most of the work:
- Sensitivity labels — tagging documents as Confidential or Highly Confidential, with encryption on the top tier, so the most sensitive data is marked and protected before any AI tool can touch it.
- Data Loss Prevention (DLP) — rules that detect sensitive content (Tax File Numbers, Medicare numbers, credit card numbers, client records) and warn or block when someone pastes or uploads it to an unsanctioned destination. Endpoint DLP extends that to the browser and clipboard, which is precisely where shadow AI lives.
Start DLP rules in audit-only mode for a fortnight, tune out the false positives, then move the high-risk ones to block. Turn everything to block on day one and you will have the finance team locked out of legitimate work by Tuesday.
| Concern | Consumer AI (free tier) | Sanctioned enterprise AI |
|---|
| Data residency / control | Usually offshore, no guarantees | Inside your tenant, contractual terms |
| Used to train public models | Often, unless opted out | No |
| Respects existing permissions | No concept of them | Yes |
| Auditable | No visibility | Logged via Purview audit |
| DLP enforceable | No | Yes |
Staff training closes the loop
Tools and policies fail without the why. A thirty-minute session showing real examples — what happens to a contract pasted into a free chatbot, why the transcription bot in the board meeting is a problem, how to use the sanctioned tool instead — changes behaviour far more than a signed policy ever will. The message is not “AI is dangerous, stop”. It is “AI is useful, here is how we use it safely”. Train people to treat AI output as a draft to verify, never a finished answer.
Frequently asked questions
Is using ChatGPT at work illegal in Australia?
Using it is not illegal. The risk is what you put into it. If staff feed personal information into a public AI tool, you may breach the Australian Privacy Principles, particularly the rules on protecting personal information and disclosing it overseas. A serious breach can trigger reporting obligations to the OAIC. The tool is fine; uncontrolled data going into it is the problem.
Does Microsoft 365 Copilot solve the shadow AI problem?
It removes most of the pull towards consumer tools by giving staff a fast, sanctioned alternative that keeps data inside your tenant. It does not replace governance. You still need sensitivity labels, sensible permissions and DLP, because Copilot surfaces whatever the user can already access. Provide the safe tool and govern the data underneath it.
What is the first thing we should do about shadow AI?
Find out what is actually in use. Run a SaaS discovery scan or check your DNS logs, and have a few honest conversations with staff. You cannot write a sensible policy or pick the right sanctioned tool until you know what problem people are solving and which tools they have reached for.
Where to start
Shadow AI is not a reason to panic, and certainly not a reason to ban a technology your staff find useful. It is a reason to look. Find out what is in use, write a one-page position people will follow, give them a safe enterprise tool, and back it with Purview labelling and DLP. That sequence — discover, sanction, govern, train — turns an invisible risk into a managed one.
TechAssist has run Microsoft 365 and security for Melbourne SMEs since 2014, with thirteen Australian-employed engineers and a 24/7 NOC in Tecoma. If you would like a hand finding what is in use and putting a sane AI position in place, get in touch with TechAssist. We will tell you plainly what is happening, what to allow, and what to lock down.