Even if your business has approved AI tools, employees may still be connecting personal AI accounts to work systems, and giving those tools far more access and authority than you realise

Larissa Hamilton
Director
AI
/

Some employees may not want to use the approved AI tools, so they use their own AI tool, like Claude or ChatGPT. Whether they access the tool through a web browser or on their phone, this usage is commonly referred to as "shadow AI" because the organisation has no visibility of it, or how it is being used.
Some employees may also go further than simply using personal or consumer AI accounts for work, by connecting them to workplace systems.
That becomes more important as AI tools are able to do more than generate content.
AI tools can now carry out tasks, access information and take actions on a user's behalf. That might include sending emails, changing files or connecting to other systems. Some connections continue running until someone turns them off.
If an employee gives an AI tool access to work information or tells it to act on that information, there is an obvious question: does that employee actually have authority to give the AI tool that access or allow it to take those actions? If the employer is not aware, the answer is very likely to be no.
So what is the real issue?
The risk changes when an AI tool can act inside your systems, rather than simply answer a question.
For example, if an employee connects a personal AI account to your organisation's CRM, the AI tool may be able to read client records, update notes, log activity or send follow-up emails.
Many organisations are focused on the AI tools they have officially approved. They may have much less visibility over the consumer AI tools employees are also using for work.
That can create legal and commercial risk. Depending on the circumstances, it may affect confidentiality obligations, intellectual property rights, internal policies, customer contracts and the organisation's obligations under the NZ Privacy Act 2020 to protect personal information.
What does your AI use policy say about personal AI accounts, connected apps and AI tools accessing work systems?
If the answer is unclear, it may be time to update both the policy and the training that goes with it.


