Blog | Understanding Cyber Security · 5 min read | Practice Management | Cyber Security | Compliance | AI Governance
Quick answer: Shadow AI is staff using their own personal AI accounts, like ChatGPT, Claude or Gemini, to do firm work. It usually starts with good intentions: someone finds a tool that saves them hours and puts it straight to work. The gap is that the account is in their name rather than the firm’s, so anything they enter sits outside your systems and leaves with them if they move on. October is Cyber Security Action Month in Australia, which makes it a good time to find out what your team is using and bring those tools inside the firm’s rules.
Key Takeaways
- Shadow AI means staff using personal AI accounts for client work. It’s usually a sign your team is looking for ways to work faster, which is worth knowing about rather than shutting down.
- Traditional cyber security keeps people out of your systems. These tools raise a different question: what information is going out, and into accounts the firm doesn’t hold.
- It tends to come to light at a resignation, or when a client spots another client’s information in their own advice.
- TPB(GS) 55/2026, issued 22 July 2026, confirms that AI use sits under the existing Code of Professional Conduct. You remain accountable for the output.
- Every firm has AI in it in some form, much of it now built into software you already pay for. The opportunity is to get ahead of how it’s used.
Most software reaches a firm through the front door. Someone reviews it, checks what it does with client data, and it gets added to the stack.
AI didn’t arrive that way. It came in through individual staff finding tools that turned a three-hour job into twenty minutes, one person at a time, usually without anyone needing to ask. That’s why it sits outside the processes firms already run well and why it’s become an emerging threat category of its own for accountants.
So here’s a question worth sitting with. If a senior accountant resigned this Friday, which AI tools would you want to know she’d been using, and what would you want to be able to check?
This is already widespread. A global IDC survey sponsored by Caseware, reported by Accounting Times in May 2026, found that 68% of Australian accounting firms had embedded or piloted AI, slightly ahead of the global average of 66%. The same survey put regulatory uncertainty among the top three barriers firms named, behind a lack of technical talent and the cost of implementation.
Why is this different to the cyber security you already have in place?
Direct answer: your existing controls are built to keep people out, and this is a question about what goes out.
Traditional cyber security protects a perimeter. Client data sits in the middle, controls sit around the edge, and the job is keeping the wrong people out. Your MFA, your email filtering and your access controls all do that job well — the fundamentals every firm should have in place.
AI asks something different. When a staff member pastes a client’s figures into a personal account, nothing is breached and no control has failed. The information has simply gone somewhere the firm doesn’t hold the keys to.
When does it tend to come to light?
Direct answer: at a staff departure, or when a client notices another client’s information in their own advice.
Both of these arrive without warning, which is what makes them worth getting ahead of.
The first is a resignation. Someone who spent a year working out how to handle a particular type of engagement, inside their own AI account, has built something genuinely valuable. The firm just has no copy of it. It leaves with them, along with whatever client data went into it, and their replacement starts from the beginning. It’s the same gap that makes a thorough offboarding process worth getting right — and the reason one-click offboarding exists in the first place.
The second is the one firms most want to avoid. Because the work sits in one personal account rather than in separate client files, information from one engagement can carry into another. It’s the kind of thing a client notices, and it’s entirely preventable with the right tools in place.
What does the TPB expect from firms using AI?
Direct answer: that you stay accountable for the output, understand what the tool does, and review its work.
TPB(GS) 55/2026, finalised on 22 July 2026, sets out how existing Code of Professional Conduct obligations apply when AI is used in delivering tax agent services. The TPB is supportive of firms adopting these tools, which is worth noting. It’s also clear that using one doesn’t transfer responsibility. Competency, confidentiality, reasonable care and record-keeping all still apply.
For most firms this is reassuring rather than onerous, because it’s the standard you already hold your work to. The practical change is being able to show it.
There’s a second date worth knowing. From 10 December 2026, Privacy Act changes require firms that use personal information in automated decision-making affecting a person’s rights or interests to describe that in their privacy policy. Whether it applies turns on how a tool is used rather than whether the firm uses AI at all, and the OAIC’s guidance on it is still being finalised. Our 2026 Regulatory Compliance Map sets out how this sits alongside your TPB, ATO, AML/CTF and Essential Eight obligations.
What does getting ahead of it look like?
Direct answer: decide which tools are approved, write the rules down, and keep a record of what your people can reach.
The instinct to restrict these tools is understandable, and some firms start there. In practice it tends to push usage out of sight, because someone who’s found a tool that saves them an afternoon will keep using it quietly. It also means the firm misses the ground other practices are gaining. The firms doing best with this are the ones that picked the tools, set the rules, and let their teams get good at them.
Three things make it work. Approved tools your team can use openly. Rules the firm has talked through, so people know what client information can and can’t go in. And a record of what was accessed and by whom, which is what turns a policy into something you can stand behind. It’s the same distinction that separates a password manager from a compliance platform: storing credentials solves a convenience problem, while evidencing access solves a regulatory one.
That last part is where Practice Protect Core™ does the heavy lifting: single sign-on across the firm’s connected applications, an access log showing who opened which application, when and from where, and removal of a departing staff member’s access to those applications in a single step. Where AI tools are reached through the platform, they sit in that same record. The Cyber Security Compliance Hub™ includes ready-to-use policy templates, an AI Usage Policy among them, that your firm applies its own details to.
Frequently Asked Questions
What is shadow AI?
+
How do we find out which AI tools our team is using?
+
Should an accounting firm ban AI tools?
+
What does TPB(GS) 55/2026 actually require?
+
How often should a firm review its AI policy?
+
We’ve got a policy signed by the team. Is that enough?
+
A good month to get the full picture
October is Cyber Security Action Month, with a call to ‘Take a second. Stay secure”, which makes it a good time to ask your team which AI tools they’re using for client work, and to get a clear view of what you’d be able to evidence.
A complimentary security consultation covers both. What your people can currently access, and what you’d be able to show if someone asked. It runs under 60 minutes, often shorter, with a specialist who only works with accounting and bookkeeping firms.
Practice Protect is the cyber security platform built exclusively for accounting and bookkeeping firms, trusted by 28,000+ accounting and bookkeeping professionals.