The unsanctioning is done. The application has been tagged, the block indicator has propagated to the endpoint fleet, and the enforcement is live. Within a fortnight the discovery dashboard, which had been showing several hundred distinct users reaching a consumer AI service, drops to almost nothing.
The programme reports success, and the graph supports it.
There are two readings of that graph and they are indistinguishable from the graph. Either the behaviour stopped, or the measurement stopped. Everything in Part Four about where instruments live suggests the second is at least as likely as the first, because the block was applied to the population the organisation could already see, and the obvious response to a block on a work laptop is a phone.
Chapters 28 to 30 covered what the law requires and what proportionality asks. This chapter covers a third question that is separate from both: whether the control achieves the outcome. It is also the chapter that has to be most careful with its evidence, because the claim it is going to make is the claim most heavily asserted by people selling alternatives to blocking.
Shadow security, and the finding that matters
The relevant research is older than generative AI and better evidenced than anything written about it.
The core finding comes from a 2014 study based on 118 in-depth interviews with employees. Security-conscious staff who cannot comply effectively with a security control devise workarounds, and those workarounds represent the best compromise the staff member can find between getting the job done and managing the risk as they understand it (high). The authors named the phenomenon shadow security, and the design recommendation that follows is the useful part: study the workaround as the starting point for a workable control, rather than treating it as a discipline problem.
The methodological point matters as much as the finding. This is interview research with real employees describing real behaviour, not telemetry from a product measuring the customers of that product. It is one of the few things in this area with a published sampling approach.
Sitting under it is an earlier idea from the same research tradition, the compliance budget. Employees weigh the actual and anticipated costs and benefits of compliance, and the budget available for that weighing is finite (high). The implication for a shadow AI programme is uncomfortable and useful. A control that is disproportionate does not merely fail on its own terms; it spends compliance capital that is then unavailable for controls that matter more. An organisation with ten rules that staff mostly follow is in a stronger position than one with forty that they mostly do not.
How unsanctioned use becomes invisible rather than absent
The systematic literature on shadow IT gives a taxonomy that transfers directly. Causing factors are grouped as enablers, motivators and missing barriers, and unsanctioned use is distinguished from business-managed use by whether it is covert or overt (high).
Apply the taxonomy to a block. Blocking removes an enabler on the managed device. It leaves the motivator entirely untouched, because the motivator is the work the staff member is trying to do. And the enabler is trivially replaced, because everyone in the building has a device the organisation does not manage. What the block reliably changes is the covert-or-overt dimension: use that was visible becomes use that is not.
Peer effects compound it. Research on how employees justify unapproved IT use finds that existing users influence colleagues, and that non-users can be recruited when they perceive an operational advantage (high). Justifications circulate faster than policies do, and a justification that begins 'they blocked it so I use my phone' is a complete and socially acceptable account of the behaviour.
What is not evidenced
It is worth being direct about the limits of the argument, because this manual has spent thirty chapters insisting on it.
There is no peer-reviewed study measuring migration to personal devices caused specifically by blocking a generative AI tool (high, as a negative finding from targeted searching). The general mechanism is well evidenced. The AI-specific step is an inference from it, and a reasonable one, and it is an inference.
The alternative to saying so would be to cite vendor telemetry as though it were research. A large amount of the material circulating on this topic consists of percentages drawn from a vendor's own customer base, measured through that vendor's own product, published by that vendor's marketing function, with no sampling frame, no response rate and no questionnaire. Those numbers can be indicative. They are not evidence of the proposition they are usually cited for, and repeating them with a footnote launders them.
The Australian numbers, with their denominators
A defender will be asked how widespread this is in Australia. The honest answer has three parts.
For businesses, there is an official figure. The Australian Bureau of Statistics reports that twelve per cent of Australian businesses adopted artificial intelligence in the 2024 to 25 financial year, from the biennial Business Characteristics Survey of around seven thousand businesses, with fieldwork from October 2025 to February 2026. Adoption was thirty-five per cent among large businesses, twenty-two per cent among medium, and eleven per cent among small and micro businesses (high). Note that this measures business adoption, meaning the organisation using AI, not staff using consumer tools.
For individual workers, there is no official Australian statistic. The best available is a nationally representative multi-country survey conducted from November 2024 to mid-January 2025, with over forty-eight thousand respondents across forty-seven countries and a published methodology (high on the study). Its Australian workplace figures circulate in two versions with different denominators, one apparently based on all Australian employees and one on Australian employees who use AI at work, and they should not be mixed or quoted without stating which is which (medium). A national capacity study puts Australian worker use of generative AI in the low to mid twenties as a percentage, reported second-hand (medium).
For the university sector specifically, a figure of seventy-one per cent of Australian university staff using generative AI circulates widely, attributed to a survey of over three thousand staff across around seventeen institutions. The primary report could not be located during this build, and the figure is therefore resting on a secondary account (low). It is the most useful number for this manual's audience and it is the least well sourced, which is a common combination and worth flagging rather than concealing.
The teaching point is not any of these numbers. It is that they measure different constructs on different populations, and that a figure of twelve per cent and a figure of sixty-eight per cent can both be accurate about Australian AI adoption because they are not measuring the same thing. Ask for the denominator and the sampling frame before putting any of them on a slide.
The visibility economics
Restate the finding of Part Four in one paragraph, because it is what makes the argument of this chapter more than a preference.
Every instrument in this manual depends on one of three things. The device is in the managed fleet, so an agent can report. The traffic crosses a network the organisation controls, so it can be observed or intercepted. Or a contract exists with the service, so a log can be requested. Where none of the three holds, there is nothing, and Chapter 27 traced that residue from four directions.
Blocking removes none of those dependencies. It changes where the activity happens, and the destination it changes it to is precisely the place where none of the three holds. That is not an argument that blocking never works. It is an argument that a block's effect on the dashboard is not evidence of its effect on the behaviour, and that the two are systematically confused.
The sanctioned alternative as a control
The strongest available intervention for most Australian organisations is not a control in the usual sense. It is making a governed tool easier to reach than an ungoverned one.
The concrete instance in a Microsoft estate is the free work-account chat service with enterprise data protection, available at no additional cost to users signed in with a work identity. Under that protection the vendor acts as data processor under the data protection addendum, prompts and responses are not used to train foundation models, and the interaction is logged and available for retention, discovery and compliance where the subscription supports it (high).
Eligibility is worth checking rather than assuming. The chat experience is included at no extra cost for work or school account users on a listed subscription, and the list includes the academic A1, A3 and A5 plans as well as the enterprise E3 and E5 plans (high).
Two caveats belong in any communication about it, because getting them wrong damages the credibility of the whole message. The included experience is the web-grounded one. The chat that reasons over the organisation's own content through the graph requires the paid add-on licence, so an organisation promoting the free option should not describe it as knowing anything about the organisation's documents unless the user attaches them (high). And web search within it is handled under a different regime, with the vendor acting as an independent data controller for the search queries rather than as a processor, and the European data boundary commitments do not extend to those queries (high). An organisation that promotes 'Copilot is your sanctioned alternative' without saying which one is setting up a support problem and a trust problem at the same time.
The shadow AI lens
Discover, then decide. The sequence that follows is not a project plan and the week numbers in the internal report should not be treated as one. It is a logic, and each step earns the next.
Discover before deciding, because a decision made about an unmeasured population is a guess. Turn on cloud application discovery through the endpoint agent on the managed fleet, filter to the generative AI category, and establish a baseline of which applications are in use, by how many staff, at what volume. Chapter 24 established that this measurement errs low in a knowable direction, which is a useful property: the real number is higher than the one on the screen, and by roughly the amount the estate is unmanaged.
Classify what was discovered. Tag applications as sanctioned, monitored or unsanctioned, on the basis of risk and of whether a governed equivalent exists. This is where a defender earns their keep, because the classification is a judgement about the organisation's work, not about the product's risk score.
Communicate and consult before enforcing. Because the consultation obligation in Chapter 29 exists, and because an unexplained block is the specific stimulus that produces the workaround this chapter is about.
Warn before blocking. Run sensitive information policies in audit, then in warn, and read what they produce. A warn policy is also a training intervention delivered at the moment of the behaviour, which is the only moment anyone is paying attention.
Block narrowly, where the risk is worst and the alternative is clearest, and keep discovering, because the application catalogue changes monthly and a block list is a snapshot.
What makes a block explainable. A block list of three named applications, with a stated reason for each and a named alternative, is a policy. A block list of two hundred categories inherited from a vendor template is a wall. Staff route around walls, and they do it without feeling that they have done anything wrong, because a wall communicates nothing that could be disagreed with. The difference between the two is not technological and costs nothing.
Making the sanctioned tool the path of least resistance. Concretely, and none of this is a communications activity. It is on the browser toolbar by policy. It is on the intranet front page rather than three levels down. It is in the induction. It is in training that names the data classes that must not leave, rather than the tool names that will change. And there is a procurement path, with a known owner and a known timeframe, for the research or teaching workflow that genuinely needs a different product.
If the sanctioned tool is materially worse at the task, none of that helps. Staff will grade it accurately within a week and the promotion becomes a message rather than a control. An organisation that cannot honestly say its sanctioned tool is good enough for the common cases should fix that before it spends effort on enforcement, because enforcement without a workable alternative is the configuration this chapter is warning about.
When blocking is right. The chapter should not be read as an argument against enforcement, and there is a clear Australian counter-example. Following an investigation into a child protection worker's use of a consumer AI service to draft a court report, the Victorian regulator issued a compliance notice requiring the department to direct staff not to use web-based generative AI text tools, to technically block fifteen named platforms by a specified date, to run an ongoing monitoring programme for emerging tools, and to report to the regulator through to September 2026 (high).
That is blocking, ordered by a regulator, as the proportionate response to a specific harm in a specific unit. The argument in this chapter is not against that. It is against blocking as the opening step across an entire estate, with no alternative in place, no consultation, and a dashboard treated as the measure of success.
The evidence base for the AI-specific claim is thinner than the confidence with which it is usually asserted, including by sources cited in this chapter. The general mechanism is well supported. The extrapolation to generative AI is not, and a defender who overstates it will be corrected by someone who has read the literature.
A sanctioned alternative that is worse at the task does not substitute for the ungoverned one. This is the argument's largest dependency and it is outside the security team's control.
Blocking that does work still relocates the activity to a device where nothing reaches. Success and failure look the same from the dashboard, which is the chapter's opening problem restated and not solved.
Vendor telemetry is a measurement of a vendor's customers through a vendor's product. It can be indicative, it is not research, and citing it does not make it so.
The compliance budget argument can be misused to justify inaction. It is an argument for spending the budget on the controls that matter, not for leaving it unspent, and it will be quoted back by people who would prefer no controls at all.
Universities have a complication the corporate literature does not address. Research and teaching workflows can legitimately require a specific tool, and academic staff have a defensible claim to autonomy in choosing the instruments of their own scholarship. A governance model that treats that claim as non-compliance will produce a great deal of concealment and very little safety.
- A discovery dashboard drops to near zero in the fortnight after a block. Write the two sentences you add to the report.
- State which part of this chapter's argument is supported by peer-reviewed research and which part is inference, in one sentence each.
- A vendor cites a percentage of employees pasting confidential data into chatbots. List the three questions you ask before the figure goes into a governance paper.
- Explain why an unexplained block is more likely to produce a workaround than an explained one, using the enabler and motivator distinction.
- Describe what would have to be true of your organisation's sanctioned alternative before it could be described as a control rather than a message.
Glossary terms used in this chapter
adaptive protection · cloud discovery · compliance budget · device onboarding · enterprise data protection · intelligent enablement · sanctioned alternative · sensitive information type · shadow IT · shadow security · unsanctioned application
Sources
- Kirlappos, I, Parkin, S and Sasse, M A, 'Learning from "Shadow Security": Why understanding non-compliance provides the basis for effective security', Proceedings of the Workshop on Usable Security (USEC 2014), San Diego, February 2014, DOI 10.14722/usec.2014.23007. discovery.ucl.ac.uk Based on 118 in-depth interviews. The source for the shadow security construct and for the finding that workarounds represent the best compromise staff can find between getting the job done and managing risk. Last checked 9 August 2026; (high).
- Beautement, A, Sasse, M A and Wonham, M, 'The compliance budget: managing security behaviour in organisations', Proceedings of the 2008 New Security Paradigms Workshop, pp 47 to 58, DOI 10.1145/1595676.1595684. nspw.org Interviews with seventeen staff across two firms. The source for the compliance budget concept. Last checked 9 August 2026; (high).
- Klotz, S, Kopper, A, Westner, M and Strahringer, S, 'Causing factors, outcomes, and governance of Shadow IT and business-managed IT: a systematic literature review', International Journal of Information Systems and Project Management, 7(1), 2019, pp 15 to 43. aisel.aisnet.org The source for the enablers, motivators and missing barriers taxonomy and for the covert against overt distinction. Last checked 9 August 2026; (high).
- Haag, S, Eckhardt, A and Schwarz, A, 'The Acceptance of Justifications among Shadow IT Users and Nonusers: An Empirical Analysis', Information & Management, 56(5), 2019, pp 731 to 741, DOI 10.1016/j.im.2018.11.006. repository.lsu.edu The source for the peer influence and justification findings. Last checked 9 August 2026; (high).
- Australian Bureau of Statistics, 'Business adoption of Artificial Intelligence accelerates in 2024 to 25', media release, 25 June 2026, and Characteristics of Australian Business, 2024-25 financial year. abs.gov.au Business Characteristics Survey, approximately 7,000 businesses, fieldwork October 2025 to February 2026. The source for the twelve per cent adoption figure and the breakdown by business size. Note that the older Business Use of Information Technology collection is discontinued and contains no AI data. Last checked 9 August 2026; (high).
- Gillespie, N, Lockey, S, Ward, T, Macdade, A and Hassed, G, Trust, attitudes and use of artificial intelligence: A global study 2025, The University of Melbourne and KPMG, DOI 10.26188/28822919. figshare.unimelb.edu.au 48,340 respondents across 47 countries, fieldwork November 2024 to mid-January 2025, minimum 1,000 per country, workplace items based on an employee subsample of 32,352. Cited here for the methodology and for the caution about the two Australian denominators. Last checked 9 August 2026; (medium).
- Microsoft Learn, 'Enterprise data protection in Microsoft 365 Copilot and Microsoft 365 Copilot Chat'. learn.microsoft.com The source for the enterprise data protection position: Microsoft acting as data processor under the Data Protection Addendum and Product Terms, prompts and responses not used to train foundation models, sensitivity labels and retention policies applying, audit of interactions supported, and the separate handling of web search queries where Microsoft acts as an independent data controller and the European data boundary does not apply. Verified against the Microsoft Learn documentation service on 9 August 2026; (high).
- Microsoft Learn, 'Manage Microsoft 365 Copilot Chat', eligibility section, and 'License options for Microsoft 365 Copilot'. learn.microsoft.com The source for the statement that the chat experience is included at no extra cost for work or school account users on listed subscriptions including the academic A1, A3 and A5 plans, and that work-grounded chat requires the add-on licence while web-grounded chat does not. Verified against the Microsoft Learn documentation service on 9 August 2026; (high).
- Office of the Victorian Information Commissioner, Investigation into the use of ChatGPT by a Child Protection worker, report dated 24 September 2024. ovic.vic.gov.au The source for the compliance notice requiring technical blocking of fifteen named platforms and reporting to the regulator through to September 2026. Last checked 9 August 2026; (high).
- Office of the Australian Information Commissioner, 'GenAI tools in the workplace: balancing protection of personal information and business efficiency', 4 December 2025. oaic.gov.au Supports the graduated position taken here: policy, training and technical measures on a scale, with prohibition reserved for cases where the risk is too high. Last checked 9 August 2026; (high).
- Telemetry and Control Options for Shadow AI in an Australian University (this project's internal source report), sections 7.1 and 7.2. The origin of the discover-then-decide sequence and of the shadow IT migration argument, rendered here as prose with the evidence base examined rather than assumed.
Open questions
No peer-reviewed study measuring migration to personal devices caused specifically by blocking a generative AI tool was found. The claim in this chapter is an inference from the general shadow IT and shadow security literature and is presented as one (medium).
The primary report behind the widely quoted figure of seventy-one per cent of Australian university staff using generative AI could not be located. Author names, publisher and a stable URL were not found, and the figure rests on a secondary account. Do not quote it without tracking the report down (low).
The Australian workplace figures from the global trust study appear in two versions with different denominators, and the discrepancy could not be resolved. State the denominator explicitly or do not use the figures (medium).
Full citation details for two of the shadow IT papers cited here, including volume, issue, pages and DOI strings, could not be verified because the publisher pages block automated retrieval. Verify before formal citation (medium).
Last updated 9 August 2026