Shadow IT has always existed. People find tools that do the job, skip the approval queue, and get on with their work. But the scale of unsanctioned software in Australian organisations in 2026 is genuinely different from what IT departments dealt with five years ago. The SaaS market makes it trivially easy for a team of three to spin up a project management tool, an AI writing assistant, a customer data platform, and a no-code workflow automation in an afternoon, paying on a corporate card without triggering a single procurement alert.
The problem isn't always malicious. It's usually well-intentioned. A marketing team gets tired of waiting for IT to evaluate a tool, so they subscribe themselves. A sales manager finds that the approved CRM doesn't do what the new vendor pitch needs, so a second CRM appears. An operations team automates a data export using a free-tier AI tool because the enterprise-approved route involves six weeks of change requests. The intention is productivity. The consequence is a security and compliance problem IT didn't sign off on.
Why shadow IT is growing faster now
Three forces are compounding the traditional shadow IT problem. First, the cost of entry for SaaS tools has collapsed. Many platforms offer functional free tiers that never require a finance approval. Second, AI-powered tools are uniquely attractive because they deliver visible, immediate results, which makes them hard for business units to give up once adopted. Third, procurement cycles at many Australian organisations haven't kept pace with the speed at which new categories emerge. By the time IT has finished evaluating a generative AI tool, the business unit has been using a competitor product for three months.
The data is consistent across industries. Australian technology surveys over the past two years have repeatedly found that IT departments are aware of roughly 30 to 40 per cent of the SaaS subscriptions actually running in their environment. The rest sit outside visibility tools, outside single sign-on, and outside the vendor risk review process.
The real risks: not just security theatre
Security is the obvious concern. An unsanctioned SaaS tool that handles customer data, employee records, or financial information creates exposure under the Privacy Act that the organisation cannot manage if it doesn't know the tool exists. Australia's Notifiable Data Breaches scheme places obligations on organisations regardless of which tool was responsible for the breach. "We didn't know a business unit was using that platform" is not a defence that limits liability.
Beyond privacy, there are three categories of risk that tend to surprise IT leaders when they map shadow IT for the first time.
- Identity risk: Shadow SaaS tools almost always sit outside the organisation's identity provider. That means no MFA enforcement, no conditional access policies, no deprovisioning when an employee leaves. An ex-staff member can retain access to a shadow tool for months.
- Data residency risk: A tool chosen quickly by a business unit may store data on servers outside Australia. For organisations subject to Australian data residency requirements, this is a compliance failure the IT team inherits without knowing it happened.
- Spend duplication: Shadow subscriptions frequently overlap with tools IT has already licensed centrally. SaaS license sprawl is already one of the most common sources of waste in Australian IT budgets, and shadow IT makes the problem significantly worse by funding parallel capabilities that nobody is comparing.
What discovery actually looks like
Most IT teams underestimate how long a thorough shadow IT audit takes. The instinct is to run a query against the expense management system or check browser proxy logs. Those methods surface some tools, but they miss anything paid through a business credit card that routes around accounts payable, and they miss browser extensions entirely.
A more complete approach combines four inputs: expense management data (including card transactions by department), SSO gap analysis (services that exist in the environment but aren't connected to the identity provider), network traffic analysis from DNS and proxy logs, and direct business unit interviews. The last one is the most uncomfortable and the most informative. When you ask a team lead what tools their team uses, you typically hear about 2 or 3 tools not in your asset register within the first five minutes.
Cloud access security brokers (CASBs) can automate much of this discovery for organisations with the budget, identifying sanctioned versus unsanctioned cloud services in near real-time. But CASBs don't replace the business unit conversation. They tell you what's running; they don't tell you why, or what data is flowing through it.
The governance response that doesn't just say no
IT teams that respond to shadow IT purely with prohibition make the problem worse. If the procurement process is the reason people go around IT in the first place, adding more friction to that process accelerates shadow adoption rather than containing it. The organisations that handle this well do something different: they make the approved path faster and more useful than the shadow path.
That means maintaining a curated, current catalogue of approved tools by category, with clear guidance on which use case each covers. It means running a fast-track evaluation process for low-risk tools (a 5-business-day turnaround for tools handling no sensitive data is achievable and changes how business units perceive IT). It means pre-approving categories rather than individual tools, so a project manager can choose from 3 approved options without waiting for a specific platform to be reviewed.
There's a useful parallel in how organisations approach SaaS vendor consolidation: the goal isn't to reduce tool count for its own sake, it's to reduce the number of unmanaged tools. Some shadow IT tools, once discovered, turn out to be genuinely better than the approved alternative. The right response in that case is to evaluate, sanction, and integrate, not to block and mandate a worse experience.
AI tools deserve a specific conversation
Generative AI tools are the fastest-growing category of shadow IT in Australian organisations right now. The risk profile is materially different from a project management subscription. An AI writing assistant may process draft contracts, internal memos, HR correspondence, or customer complaints. Some platforms use submitted content to train future models by default, unless that option is explicitly disabled at the enterprise tier.
Business units adopting AI tools informally rarely read the data processing terms. IT teams discovering these tools after the fact are often in the uncomfortable position of having to assess whether sensitive organisational data has already been sent to a third-party AI model that may be based outside Australia. That's a harder conversation than a routine shadow SaaS discovery.
A practical step many Australian IT teams are taking is issuing a short internal AI tool policy, separate from the general acceptable use policy, that specifically addresses what data categories may not be pasted into any AI tool that isn't enterprise-approved. Simple, specific, and communicated to every business unit directly rather than buried in an intranet document few people read.
Measuring what you've actually fixed
Shadow IT governance is one of those disciplines where it's easy to do the audit, write the report, and move on without changing the underlying dynamic. The metric that matters isn't the number of tools discovered or blocked. It's the percentage of the organisation's SaaS portfolio that sits inside the identity provider, is covered by vendor risk assessment, and has a named owner accountable for the subscription.
That percentage is almost never 100 per cent, and chasing perfect coverage is less useful than getting from 40 per cent to 80 per cent and building the process that keeps new tools from falling through the gap. Quarterly reviews of expense transactions, monthly SSO gap reports, and annual business unit interviews form a repeatable cadence that most IT teams can absorb without dedicated headcount.
Shadow IT won't disappear. The economics of SaaS make it permanent. But the gap between what IT knows about and what's actually running in the organisation is manageable, and closing it is one of the highest-leverage governance investments an Australian IT team can make right now.

