The risks of directors using shadow AI

Wednesday, 12 August 2026

Elise Shaw photo
Elise Shaw
Content Specialist
    Current

    Directors are already using artificial intelligence (AI) informally, but boards are not yet governing accordingly.


    In May 2026, NSW Chief Justice Andrew Bell AC used the Harold Ford Memorial Lecture at Melbourne Law School to warn that individual directors are already using AI informally to prepare for meetings, even though board-endorsed, governed use remains “far from entrenched”. 

    His Honour described shadow AI use by directors as “apparently already widespread” and cautioned that prompts, transcripts and AI outputs may be discoverable in future litigation or regulatory inquiries. 

    He made clear what many directors and boards have been reluctant to confront. AI is not a technology issue to be delegated to senior managers, but a governance issue that sits squarely with directors. 

    His message was not that AI should be feared or avoided, but that the legal framework governing directors’ duties already apply to every decision touched by AI and that many boards are not yet governing accordingly in response. 

    AI risks are increasing 

    As AI adoption grows, governance and data security become increasingly interconnected. 

    Gartner predicts 25% of enterprise breaches are expected to be linked to the misuse of AI agents by insiders and outsiders by 2028. 

    Without proper governance and data security, AI systems become easier to exploit, and more costly when things go wrong. 

    Governing the process 

    However, Chirag Joshi, founder and CEO of 7 Rules Cyber and ISACA Sydney Chapter President, says it’s not just about increasing regulations, but more about the governance of decisions. 

    “How are we making decisions we can stand behind, and do we practise for instances where training mechanisms have included AI-enabled outcomes? 

    “AI is not a whole new thing. It’s just much faster and the consequences are more pronounced. That’s why regulation can’t be delegated just to industry. It has to come from the very top.” 

     

    Should boards ban AI use? 

    Lindsey Hershman GAICD, managing director of AI Access, says their work is focused on two key areas – aligning AI use to the enterprise strategy (value) and ensuring deployment is safe (governance). Banning the use of AI in the boardroom is not a safer option. 

    “A ban pushes AI use underground and increases the risk of sensitive information IP and privacy information leaving the organisation,” he says. 

    At board level, the safer option is to create a custom internal knowledge engine that has access to all current and historical board papers, and secure access within the company’s ecosystem, says Hershman. 

    “For the enterprise, having a clear AI policy that sets behavioural expectations, paired with a roadmap showing staff where the organisation will create AI value first, does more for risk and adoption than a prohibition nobody follows.” 

    Who is using what? 

    The first step is knowing who is using what, and for what purpose, says Hershman. Suggestions include one-to-one conversations, face-to-face where possible, with every director and executive. Be non-judgemental, but dive into what is being used, why, when, how and where, he says. 

    “Second, conduct a data loss prevention assessment across unsanctioned public AI tools, but realise that it will not capture use on personal devices, which is precisely why the conversations come first.” 

    Joshi stresses the need for a practical framework, backed by feedback on its effectiveness. 

    “Rehearse an AI incident with the board,” he says. “Ask, see, track. What use cases are there in the organisation? 

    “As a director, what do you need to see as evidence that you’re actually operating within guardrails? How is the board tracking, in an ongoing way, the effectiveness of the measures?” 

    Revealing weaknesses 

    Think broadly about what information is going into AI use and build awareness of issues that might not be apparent to an individual director.

    “It’s not so much about the risk of putting confidential data into models,” says Joshi. 

    “The prompts by themselves can reveal some weaknesses if you’re not really structuring them. Boards need to give directors some awareness of that and the information boundaries – what’s OK, what’s not OK.” 

    Be wary of AI-enabled or model-enabled groupthink and bias and keep a human in the loop. 

    “If directors all talk to the same model, they all come up with very similar ideas, because they’re all generating responses from the same tool,” says Joshi. “That’s where human judgement needs to be preserved.” 

    Accountability and liability 

    AI’s potential is enormous but realising it safely requires intent. Strong governance and enterprise-grade data security are no longer optional. They are foundational to ensuring AI remains an asset, not a liability. 

    Ultimately, directors hold the duty of care, which means being able to trust and verify from the board paper in front of them right through to the code base, says Hershman. 

    “At the individual director level, they only need a paper trail if they’re operating outside the company’s ecosystem, hence the importance of having an internal custom knowledge engine with all historical board papers inside the ecosystem. Inside a sanctioned environment the system is the paper trail,” he says. 

    “At enterprise level, the paper trail requirement is larger and more complex. Existing AI governance frameworks have mushroomed in the past few years and they are written to be comprehensive rather than executed, so they don’t assist the board to discharge its responsibility.” 

    Research from IBM indicates the global average cost of a data breach is US$5 million (A$7 million), reflecting the growing difficulty of protecting sensitive information. In the past year there has been a 56 per cent increase in AI-driven attacks. 

    “Given risk exposure is expanding with agentic AI, every board pack should carry a current AI safety verification report. Can you afford not to?” asks Hershman. 

    Latest news

    This is of of your complimentary pieces of content

    This is exclusive content.

    You have reached your limit for guest contents. The content you are trying to access is exclusive for AICD members. Please become a member for unlimited access.