Shadow Legal AI: the legal hand grenade everyone carries in their pocket

Andrew Mellett • 28 September 2026

Shadow Legal AI: the legal hand grenade everyone carries in their pocket

Every person in your business now carries a tool that will draft a contract, take a position and cite a case. Almost none of them can tell when it is wrong.

That is the shift. Shadow IT gave people an unsanctioned place to put files. Shadow legal AI gives them an unsanctioned lawyer: instant, fluent, free, and utterly without doubt. It sits in a browser tab on every desk in the company, including the desks that have never once called legal.

A hand grenade in every pocket. Pull enough pins and one of them goes off.

What is shadow legal AI? It is legal work done through AI tools the organisation has not approved, procured or recorded, whether the person doing it sits in legal or not. Contracts, evidence, advice and personal information pass through systems outside the organisation's records, its privacy controls and its audit trail. Nobody logs it, so nobody can reconstruct it later.

The problem splits two ways

Most of the commentary treats this as one risk: staff putting confidential material into public chatbots. That is half of it, and the smaller half.

1. DIY legal work, and the hyper-confident bush lawyer

Businesses have never been short of bush lawyers. The sales manager certain the indemnity is standard. The marketing lead sure the disclaimer covers it. The procurement officer who has read the clause and formed a view.

They were manageable because they were visibly guessing, and because sooner or later they asked someone qualified.

They do not ask any more. They get an answer in seconds, in the register of a senior associate, with no caveat, no file note and no invoice. The output reads like advice. It is not advice. Nobody reviewed it, nobody recorded it, and legal never finds out a position was taken until the position is being enforced against the company.

The failure mode is not a wrong answer. It is a confident one.

And the bush lawyer is not always outside legal. The person weighing up whether to paste a contract into a public chatbot is frequently senior enough to have written the policy it breaches: the budget owner, the policy signatory, the one who answers to the board. Shadow IT came up from the bottom of the org chart. This does not.

2. AI accelerates the demand for legal work

The second branch runs the other way, which is why it gets missed. The lazy assumption is that AI shrinks legal demand. It expands it.

Legal work is a function of economic activity, and AI raises economic activity. More products shipped, more campaigns run, more suppliers onboarded, more territories entered, more contracts signed. Every one of those throws legal work back over the fence.

Then the second-order effect. As the cost of drafting, reviewing and disputing falls, people draft, review and dispute more. Cheap litigation buys more litigation. Work that was never worth a lawyer's time becomes worth a machine's, and the volume lands in the same place it always did.

So the in-house team is squeezed at both ends. Demand climbs. Headcount does not. The sanctioned path remains the slowest route through the building. That is the pressure that makes the browser tab irresistible, and it is why this looks like a governance problem and behaves like a capacity problem.

Confidence: the direction here is a position, not a measured finding. The demand data to size it does not yet exist. Treat the two survey findings below as evidence and this as argument.

The numbers are worse than most GCs assume

Almost half of employees globally admit to using AI in ways that contravene their organisation's policies, including uploading sensitive company information such as financial, sales or customer data into public AI tools. 57% say they hide their AI use and present AI generated content as their own. Only 2 in 5 say their workplace has any policy guiding generative AI use at all. And 2 in 3 report relying on AI output without evaluating the information it produces.

Those figures come from a study of more than 48,000 people across 47 countries, run by KPMG and the University of Melbourne with fieldwork between November 2024 and January 2025.

The professions are no cleaner. In the Thomson Reuters Future of Professionals Report 2026, based on 1,816 responses across 62 countries with fieldwork in March and April 2026, 34% of professionals said they use AI tools their organisation cannot see. Among those who believe their organisation is moving too slowly on AI, that rises to 41%.

So the honest starting position for most in-house teams is this: you already have an AI policy in practice. Nobody wrote it down, nobody approved it, and it is being set one prompt at a time by whoever is busiest that week.

This is not a survey artefact. It shows up in almost every conversation we have with in-house teams.

One large beverages business has restricted its legal team to a single approved assistant, including where AI is already embedded in software the business licenses. The team's own read is that the restriction will be very hard to hold, because their suppliers keep shipping AI into products they already pay for.

A grocery wholesaler described the failure mode exactly. The guardrails exist. The problem, in their words, is the human angle, where people think: I have just got to get it done, I have run it through the tool, it will be fine.

A vehicle importer is worried about precedent. Approve one AI use for legal, and the rest of the business immediately asks why the rule does not apply to them too.

A healthcare group is doing the arithmetic out loud: if we are not hiring the lawyers we budgeted for, can that money buy a tool that is actually fit for purpose, instead of stretching a general assistant into a job it was not built for.

None of these teams is behaving badly. Every one of them is solving a real capacity problem faster than the sanctioned route allows. That is what makes it shadow AI rather than misconduct, and it is why training and policy memos do not touch it.

When a marketing team pastes a campaign brief into a public chatbot, the exposure is commercial. When the material is a contract, a brief of evidence or an employee complaint, 3 other things happen at once.

Privacy:

The Office of the Australian Information Commissioner's guidance on commercially available AI products, published 21 October 2024 and updated 17 January 2025, is direct. Organisations should not enter personal information, and particularly sensitive information, into publicly available generative AI tools. The same guidance expects your records to show clearly where information is the product of an AI output, and which data and system produced it. If you cannot say which tool touched a matter, you cannot meet that expectation.

The court:

Supreme Court of New South Wales Practice Note SC Gen 23 was issued on 28 January 2025 and has applied since 3 February 2025, replacing the version issued in November 2024. Generative AI must not be used to generate the content of an affidavit, witness statement or character reference. Using it to prepare an expert report requires the court's leave, and where leave is granted the expert must disclose the program, the version, which parts were AI assisted, and keep a record of prompts and variables.

This is not theoretical, and the consequences have already landed on individual practitioners.

  • In Dayal [2024] FedCFamC2F 1166, a solicitor filed a list of authorities generated with AI that contained citations and summaries which did not exist. On 19 August 2025 the Victorian Legal Services Board and Commissioner varied his practising certificate: no principal status, no trust money, no operating his own practice, 2 years of supervised practice, quarterly reporting by both him and his supervisor.

  • In Valu v Minister for Immigration and Multicultural Affairs (No 2) [2025] FedCFamC2G 95, decided 31 January 2025, Judge Skaros referred a legal representative to the NSW Office of the Legal Services Commissioner after fabricated citations and false quotes reached the court.

  • In Murray on behalf of the Wamba Wemba Native Title Claim Group v State of Victoria [2025] FCA 731, the Federal Court ordered indemnity costs against the applicant's solicitors after fabricated document references appeared in a court summary.

An untracked prompt in September becomes a disclosure question in March. Then it becomes a regulator's file.

Privilege:

This is the one most teams have not tested. Legal professional privilege protects confidential communications made for the dominant purpose of legal advice or litigation. Confidentiality is doing the work in that sentence. Whether routing privileged material through a third party tool disturbs it turns on the tool, its terms, what it retains, whether inputs train the model, who can access them and the facts of the matter.

The answer is not automatically bad. The problem is that in most teams nobody can give an answer at all, because no one recorded which tool was used, what went into it, or on whose authority. You cannot argue about a waiver you cannot reconstruct.

What does Shadow AI actually cost?

Consumer AI subscriptions sit at a price point a team lead approves without a business case. That is exactly why the comparison people run is the wrong one. They compare a subscription against a licence.

The comparison that matters is a subscription against a single incident. IBM's 2025 Cost of a Data Breach Report, published 30 July 2025, put the global average breach at USD 4.44 million. Breaches at organisations with high levels of shadow AI cost USD 670,000 more than at organisations with little or none. 1 in 5 breached organisations said an unapproved AI tool was involved. 63% of breached organisations had no AI governance policy, and of those that had suffered an AI related security incident, 97% lacked proper AI access controls.

Read the report properly and there is a second number worth knowing: that global average actually fell from USD 4.88 million in 2024, while the United States average rose to USD 10.22 million. The global figure is not the ceiling. It is the middle.

Either way, the cost does not appear on a monthly invoice. It appears once.

Why banning it does not work

IT spent a decade on shadow IT and did not win with a ban. The unsanctioned file share disappeared when the sanctioned option became the faster one.

That is the bar here too. A policy that adds steps to the fastest route through a contract review will be routed around, politely, by capable people trying to clear a backlog. Thomson Reuters found 35% of professionals whose organisation has a stated AI strategy say that strategy is not visible in their day to day work, and 17% say their organisation has no strategic direction on AI at all.

A rule nobody meets while doing the work is not governance. It is a document.

The Shadow AI Stocktake: 4 checks to run this month

  1. Ask at the top, then ask outside legal. Start with the GC, the legal ops lead and the 2 busiest lawyers on the team, not with a survey of juniors. Then ask sales, marketing and procurement what legal questions they have stopped bringing to you. Frame it as a stocktake, not a breach investigation, or you will get an answer that is clean and useless.

  2. Reconstruct one live matter. Pick a contract that moved through the team last quarter and build the record: who approved what, on which version, when, and which steps involved an AI tool. If you cannot assemble that record today with a week's notice, you will not assemble it under pressure.

  3. Test your obligations against actual practice, not against your policy. Court practice notes, privacy obligations, customer and supplier contract terms, sector regulators. Compare each one to what the team actually did last month.

  4. Name the sanctioned path, then time it. If the approved route is slower than the browser tab for routine work, the route is the problem. Reissuing the policy will not fix it.

Where this leaves you

None of this starts with a new policy. It starts with 2 things: knowing what is already in use, and being able to produce a record. Every other decision, including which tools to ban, buy or build around, gets easier once those exist and stays guesswork until they do.

Plexus builds the workflow, approval and record layer in-house legal teams use, so the sanctioned path is also the fastest one. If the stocktake is the more useful next step, the 4 checks above are the whole of it.

You cannot take the grenades out of people's pockets. You can make sure the pins are somewhere you can see.

Talk to us about running the Shadow AI Stocktake in your team

Sources:

  1. KPMG International and University of Melbourne, Trust, attitudes and use of artificial intelligence: a global study 2025, published April 2025. 48,000+ respondents, 47 countries, fieldwork November 2024 to January 2025.

  2. Thomson Reuters Institute, Future of Professionals Report 2026, 1,816 respondents, 62 countries, fieldwork March to April 2026.

  3. IBM, 2025 Cost of a Data Breach Report, published 30 July 2025.

  4. OAIC, Guidance on privacy and the use of commercially available AI products, 21 October 2024, updated 17 January 2025.

  5. Supreme Court of New South Wales, Practice Note SC Gen 23, issued 28 January 2025, commenced 3 February 2025.

  6. Dayal [2024] FedCFamC2F 1166; Victorian Legal Services Board and Commissioner, statement on the Mr Dayal matter, 19 August 2025.

  7. Valu v Minister for Immigration and Multicultural Affairs (No 2) [2025] FedCFamC2G 95, 31 January 2025.

  8. Murray on behalf of the Wamba Wemba Native Title Claim Group v State of Victoria [2025] FCA 731.

Regulatory position current as at 24 September 2026. Practice Note SC Gen 23 is under periodic review by the Supreme Court of New South Wales; verify the current version before relying on this summary.

Frequently asked questions

What is shadow AI?

Shadow AI is the use of AI tools that an organisation has not approved, procured or recorded. It is the AI equivalent of shadow IT, and in legal teams it typically means work passing through public generative AI tools that sit outside the organisation's records and controls.

What is shadow legal AI?

Shadow legal AI is the same problem applied to legal work, wherever it happens. It covers lawyers using unapproved tools, and it covers business teams doing their own legal work with AI and never telling legal.

Does AI reduce the amount of legal work a business generates?

We do not think so. AI raises the volume of commercial activity, and legal work tracks commercial activity. Falling cost also makes drafting, reviewing and disputing worth doing more often. The likely outcome is more legal work, not less, arriving faster and from more directions.

Is it illegal for an in-house lawyer to use ChatGPT?

No. Using generative AI is not itself unlawful or a breach of professional duty. What creates exposure is entering personal or sensitive information into public tools contrary to privacy obligations, filing AI generated material with a court in breach of practice notes, and failing to verify output. Australian practitioners have already had practising certificates restricted and costs orders made against them for unverified AI output.

Can using AI waive legal professional privilege?

It depends on the tool, its terms, what it retains, who can access the inputs and the facts of the matter. Privilege protects confidential communications, so anything that undermines confidentiality is the risk. The practical problem for most teams is not the legal answer, it is that they have no record of which tool was used or what was put into it.

How do I find out what AI tools my legal team is actually using?

Ask the most senior and busiest people first, frame it as a stocktake rather than an investigation, and test the answer by trying to reconstruct the full approval record for one live matter.

What is the difference between shadow AI and shadow IT?

Shadow IT was largely a bottom-up phenomenon driven by junior and mid-level staff. Shadow AI frequently starts at the top, because senior people have the most work, the most autonomy and the least oversight, and it now also starts outside legal entirely.