AI Assurance

Shadow AI: Just One More Piece of the Puzzle

What if your employees are not merely uploading documents to an AI service but contributing fragments that help a foreign intelligence service map your people, projects, suppliers, vulnerabilities, capabilities and Defence role—without your organisation knowing what has escaped, where it now resides, or how it contributes to a picture being assembled?

Cartoon: an employee uploads an asset register to an AI tool, captioned "Just a quick check with AI... so much easier!", while behind him a shadowy figure pins the fragments onto a board headed "Someone else's intelligence picture".

A senior cyber security executive at a large financial institution described an incident that should concern boards, risk committees and leaders across the Defence industry supply chain.

A staff member reportedly transferred about 1.3 gigabytes of company data to DeepSeek, used its artificial intelligence tools to analyse the material, and then moved the results back into the organisation.

The employee may simply have been trying to work more efficiently.

This is shadow AI: employees using artificial intelligence services outside the organisation’s approved systems, contracts and security controls.

The immediate risk

Once information is uploaded to an external artificial intelligence service, the organisation may lose exclusive custody and control over it.

It may no longer be able to confirm:

  • where copies are stored;
  • how long the information is retained;
  • whether it is combined with other material;
  • who can access it;
  • whether it is reviewed by people; or
  • whether deletion can be verified.

The provider’s legal jurisdiction is also important. Local laws may require the provider to preserve information, assist government authorities or disclose data without notifying the organisation that supplied it.

The reported incident does not prove that DeepSeek or any state authority accessed or used the information. The failure is more basic: the organisation can no longer confidently establish where the information is, who may gain access to it or how it may be used.

The Australian Government treated this type of risk seriously. In February 2025, it directed government entities to prevent the access, use or installation of DeepSeek products on government systems and devices. Australian Signals Directorate guidance also warns that foreign providers may be subject to laws or directions that conflict with an Australian organisation’s interests.

The larger intelligence concern

The national-security risk becomes clearer when we look beyond a single disclosure.

One organisation may reveal only a fragment. Similar disclosures from many organisations and individuals may expose people, projects, technologies, locations, commercial relationships, operational problems and strategic dependencies.

The disclosures do not need to be large or obviously connected.

A name may identify someone with access to a sensitive project. A project reference may reveal a strategic priority. Travel records may indicate where work is occurring. Supplier information may expose dependencies. Financial information may reveal commercial pressure. Technical questions may disclose capability gaps or recurring failures.

Individually, these details may appear harmless but together, they can form a useful intelligence picture.

Artificial intelligence makes this easier. Large volumes of documents, prompts and conversations can be searched, grouped and compared quickly. Relationships and patterns that once required substantial human effort can now be identified at far lower cost and much greater speed.

Professional intelligence organisations rarely seek isolated facts. They seek to understand relationships, influence, dependencies, vulnerabilities and opportunities. Thousands of apparently ordinary disclosures may help build that understanding.

Scenario: the intelligence value of an insured asset register

Consider an insurance broker preparing a renewal for a manufacturer that supplies components into the Defence industry.

The broker uploads an insured asset register to an external artificial intelligence service for analysis.

At first glance, the register appears to be no more than a list of machinery and equipment.

However, it may identify high-value autoclaves, five-axis CNC machining centres, carbon-fibre manufacturing equipment, ultrasonic or radiographic inspection systems, clean rooms and other specialised production assets.

Individually, those assets may reveal little.

Collectively, they may indicate:

  • the types of products being manufactured;
  • the materials being processed;
  • likely production methods;
  • manufacturing tolerances;
  • production capacity;
  • technical maturity;
  • investment priorities; and
  • the organisation’s possible role in Australia’s industrial capability.

When combined with job advertisements, planning applications, procurement information, satellite imagery, supplier records or public announcements, the confidence of those assessments may increase.

The intelligence value does not sit in one document. It comes from the relationships that emerge when routine information is accumulated and analysed together.

Is this a plausible scenario and how would an organisation know if its information had already contributed to a broader intelligence assessment?

What Defence suppliers should do

Unmanaged artificial intelligence use should be treated as both an information-security risk and a supply-chain assurance risk.

1. Find out where artificial intelligence is being used

Organisations often underestimate employee use of external services. Identify which tools are being used, by whom, for what purpose and with what information.

2. Set clear information boundaries

Employees need practical guidance about what must never be entered into an unmanaged service.

This should include customer information, Defence-related information, technical data, engineering material, asset registers, supplier information, security documentation, commercially sensitive information and internal material that could contribute to a wider intelligence picture.

3. Provide an approved alternative

Prohibition alone is unlikely to work. Employees use these tools because they are useful.

Organisations should provide an approved service that supports legitimate work while keeping information within agreed contractual, security and legal boundaries.

4. Assess the provider

The provider becomes part of the organisation’s information supply chain.

Before approval, understand where information is processed and stored, which laws apply, whether data is retained, whether it may be used to improve the service, who may access it and whether deletion can be confirmed.

5. Detect and respond

Organisations should monitor for unauthorised services, make accidental disclosure easy to report and investigate incidents promptly.

A seemingly minor disclosure may be more serious when combined with other information already outside the organisation.

6. Make artificial intelligence an executive issue

Boards and executive leaders should receive regular information on approved services, employee use, exceptions, incidents and control effectiveness.

Artificial intelligence governance should form part of normal enterprise risk, cyber security and Defence Industry Security Program reporting. It should not be left solely to information technology staff.

A practical conclusion

Artificial intelligence is now a useful business tool. Attempting to prohibit it completely is unlikely to succeed.

The aim should be to keep customer information, organisational knowledge and Defence-related material under effective Australian organisational control while still allowing employees to benefit from the technology.

Before entering organisational information into an external artificial intelligence service, ask:

If this information could help another nation—or even a competitor—better understand your organisation, your customer or Australia’s Defence industrial capability, would you still upload it?

If there is doubt, the information does not belong in an unmanaged service.

SecureSupply assists organisations in Australia’s Defence supply chain to identify shadow artificial intelligence use, assess information risk, strengthen Defence Industry Security Program-aligned governance and establish practical controls for safer adoption.

Found this useful? Share on LinkedIn
Speak with us

Discuss your DISP, IRAP or security obligations.

We move from first conversation to active engagement in two to three weeks.