Customer abuse data belongs in the WHS risk picture, but a model must not become a customer blacklist or an employee surveillance system. Use AI to surface channel-level exposure patterns, have people verify them, then redesign work, service and recovery controls.
Customer abuse is not only a conduct problem to be managed one interaction at a time. Repeated threats, insults, harassment and hostile contact are evidence about how work exposes people to aggression, especially in branches, complaints teams and contact centres. Aggression or violence is a named psychosocial hazard, not a customer-service metric.
AI can help screen appropriately governed contact and complaint data for candidate patterns that manual sampling misses. The useful unit is the channel, journey stage or time window. It is not a score attached to a customer or worker.
People must validate every pattern, consult affected workers and decide the controls. The screening step belongs inside the AI-assisted psychosocial risk assessment you already run, not beside it. The model does not judge intent, sanction a customer, assess a worker's health or decide whether an incident is notifiable.
What should AI screen for, and what must it never decide?
For Commonwealth jurisdiction employers, the current Work Health and Safety Act 2011 compilation, dated 1 July 2024, places the primary duty on the PCBU. Section 47 requires the PCBU, so far as is reasonably practicable, to consult with workers who are, or are likely to be, directly affected by a matter relating to work health or safety. Section 49 requires that consultation when identifying hazards and assessing risks, when making decisions about ways to eliminate or minimise those risks, and when proposing changes that may affect the health or safety of workers.
The current Commonwealth WHS Regulations compilation, dated 25 March 2025, define a psychosocial hazard as one arising from, or relating to, the design or management of work, a work environment, plant at a workplace, or workplace interactions or behaviours, and that may cause psychological harm. Regulation 55C imposes the duty to manage psychosocial risks and to implement the control measures required by regulation 55D. Regulation 55D(2) then lists the matters a person must have regard to in determining those control measures, including the duration, frequency and severity of exposure, how the hazards may interact or combine, the systems of work including how work is managed, organised and supported, and the information, training, instruction and supervision provided to workers.
A single abusive call can be serious, while repeated lower-level hostility may create a cumulative exposure. Queue pressure, rigid handle-time targets, transfers and poor support can combine with aggression rather than sit in separate risk-register rows.
Safe Work Australia's model Code of Practice has legal effect only where a jurisdiction approves it. Its violence and aggression guidance lists what you should do to identify the hazard, including observing contact with the public, looking for long customer queues and wait times, observing lower level but more frequent behaviours, surveying clients to find problems with service delivery, surveying workers about incidents or behaviours, and checking hazard and incident reports and workers compensation claims. That is broader than formally reported incidents.
Under the current Work Health and Safety Regulation 2025, section 55C requires a person conducting a business or undertaking to manage psychosocial risks in accordance with Part 3.1, which contains the section 36 hierarchy of control measures, and to implement the control measures required by section 55D. The approved SafeWork NSW psychosocial Code states that a PCBU's goal to produce a product, provide a particular model of patient care, achieve particular educational outcomes, or focus on customer service, cannot override the duty the WHS Act places on the PCBU to ensure, so far as is reasonably practicable, the work health and safety of their workers and others.
Victoria has a separate regime. The OHS Act is in force in version 045, and the Psychological Health Regulations are in force in version 001 from 1 December 2025. They give aggression or violence as the first example of a psychosocial hazard, and require the employer to eliminate the risk so far as is reasonably practicable and, failing that, to reduce it by altering the management of work, the plant, the systems of work, the work design or the workplace environment. Information, instruction or training may be used exclusively only where none of those alterations is reasonably practicable.
Three regimes sit behind the same contact centre, and they do not use identical language:
Build a contact-friction exposure map. Ask the model to propose candidate signals across four dimensions:
- exposure form, such as direct threats, sexual or discriminatory abuse, coercion, repeated hostile contact and lower-level but frequent aggression
- process location, such as identity checks, hardship, claim decline, complaint escalation, service outage or branch closing time
- exposure conditions, such as channel, time window, contact volume, repeat contact, queue state and available supervisor support
- control response, such as warning, termination, escalation, relief break, handover, follow-up and whether the procedure worked.
Use rates against a suitable contact-volume denominator where possible. Raw counts can make the busiest team look most exposed even when a smaller channel has a higher concentration of abuse. Keep both views because a high rate and a high total load answer different control questions.
This is candidate coding, not truth. A human validation set should include flagged records, low-confidence records and a sample the model marked as having no aggression. That last group tests false negatives, including coded threats, sarcasm and language the model handles poorly. Workers and HSRs then test whether the categories resemble real exposure or merely the wording easiest for software to spot. The questions an HSR should ask about a deployed AI tool apply to this one as much as to any other.
The Privacy Act 1988 is in force in Compilation No. 104, dated 4 June 2026. The OAIC's AI guidance recommends privacy impact assessment, minimising personal information and keeping personal or sensitive information out of public generative AI tools.
Confirm the APP 6 basis before reusing complaint or contact data. The OAIC guidance says a new use or disclosure of personal information must comply with APP 6. An approved tool, a WHS purpose label and removing direct identifiers do not themselves authorise the secondary use.
Use an approved environment, remove identifiers where the purpose permits, restrict access and set retention. Separate WHS trends from customer decisions and employee performance. Never infer dangerousness, rank resilience or create hidden individual measures.
Use this prompt to draft a channel-level signal map from approved, minimised data. A WHS practitioner, privacy specialist and worker or HSR representatives must review the taxonomy, sample the source records and verify every retained pattern before use.
How do patterns become better controls?

The exposure map earns its place only when it changes the system of work. A red cluster labelled "abusive language" is not a control, and it is not a risk-register trigger until a person has validated it. It is a prompt for workers, HSRs, operations, customer teams and WHS specialists to ask what created the exposure and what can reduce it.
Service friction never excuses abuse. It can still be a preventable exposure driver. If aggression spikes after a confusing decline letter, an avoidable transfer loop or an outage with no status information, fixing that process may remove contacts before a worker has to absorb them.
Safe Work Australia states that to manage the risks you must provide a safe physical and online work environment, implement safe work systems and procedures, have clear workplace policies, and provide workers with information, training and supervision. Comcare's contact-centre guidance adds a call termination procedure that lets workers warn clients and escalate calls to more senior personnel, access to counselling services, break areas away from the phones, and rostering that covers peak times while allowing periods of relief through breaks.
The strongest response is usually a control bundle. Start upstream with service redesign and authority for complex complaints. Add clear warning, termination and escalation rules; staffing that preserves relief; protected recovery after difficult interactions; supervisor response standards; and support routes. Training helps people use the system. It should not become the organisation's answer to a system that keeps exposing them.
WorkSafe Victoria's current employer guide asks whether incident, employee assistance and claims data have been analysed to identify trends or patterns of psychosocial hazards including aggression or violence. Separately, under work design, it lists refining complaints processes so complex or difficult complaints can be escalated to more senior employees empowered to resolve them. Its call-centre case study places aggression or violence beside low job control, high job demands, poor support and poor organisational justice, with an average handle time target as the mechanism. Controls include demand analysis, peak staffing, breaks, escalation and fair target exceptions.
Do not import every example feature without assessment. This workflow never places model-generated aggression labels on customer profiles or automatically routes, restricts or penalises anyone. Those actions raise separate legal, privacy, conduct and fairness questions. The WHS map stays aggregated; authorised people handle particular interactions under approved procedures.
Fictional worked example: [BANK_NAME] screens a de-identified sample of complaint notes and chat transcripts from [CONTACT_CENTRE]. The model suggests a concentration of hostile contacts at [PROCESS_STAGE] between [TIME_WINDOW], but people reviewing the records find that half the flags are ordinary expressions of frustration. They also find missed indirect threats in the no-signal sample.
The team corrects the taxonomy and recalculates the pattern. Workers and the HSR explain that repeated transfers, limited hardship authority and a visible queue create pressure to keep abusive contacts going. After consultation, accountable leaders approve a service handoff fix, a human escalation route, protected relief after defined exposures and a performance-target exception. No customer or worker score is created.
Use this prompt to turn a human-validated pattern into options, not decisions. Operations and WHS leaders must review feasibility and risk, then consult affected workers and HSRs before choosing, approving or implementing any control.
Keep ordinary reporting and emergency routes open. Screening historical data is not live threat detection, an emergency response, an incident investigation or a notifiability decision. A person receiving an immediate threat follows the approved human escalation and emergency procedure.
Do this Monday
- Choose one bounded channel. Select a complaints queue, contact-centre team or branch process with worker-reported aggression. Write the WHS purpose, work-group scope and decisions the analysis is prohibited from influencing.
- Consult before extracting. Ask affected workers and HSRs where aggression occurs, what lower-level conduct goes unreported, which interacting demands matter and what a useful aggregated output would look like.
- Set the data boundary. Involve privacy, security and records owners. Use the minimum approved fields, de-identify where the purpose permits, separate the dataset from performance systems and prohibit public AI tools.
- Build and test the map. Have people review flagged, low-confidence and no-signal samples. Correct false positives and false negatives before calculating channel and process-stage patterns.
- Convert one pattern into controls. Take one validated cluster through service redesign, escalation, staffing, target, break, supervisor and support options. Consult, assign a human owner and set an effectiveness measure and review trigger.
- Keep individuals out of the output. Confirm that no customer or worker score, sanction recommendation, health inference, notifiability decision or automated adverse action can leave the workflow.
Bottom line
Customer abuse data can reveal a work-design problem before an incident register does. AI is useful for finding candidate channel-level patterns, provided people validate the records and individuals are not scored. The real control decision belongs with accountable leaders in consultation with workers and HSRs. If the output does not change service design, authority, staffing, recovery or support, it is analytics theatre.
This article is general information and education only. It is not legal, compliance, financial or professional advice. Obligations vary by organisation and circumstance. Verify current requirements against the primary sources cited and seek advice specific to your situation.
References
- Federal Register of Legislation, Work Health and Safety Act 2011, current text: https://www.legislation.gov.au/C2011A00137/latest/text
- Federal Register of Legislation, Work Health and Safety Regulations 2011, current text: https://www.legislation.gov.au/F2011L02664/latest/text
- Safe Work Australia, Model Code of Practice: Managing psychosocial hazards at work: https://www.safeworkaustralia.gov.au/doc/model-code-practice-managing-psychosocial-hazards-work
- Safe Work Australia, Workplace violence and aggression - Managing risks: https://www.safeworkaustralia.gov.au/safety-topic/hazards/workplace-violence-and-aggression/managing-risks
- NSW legislation, Work Health and Safety Regulation 2025, current text: https://legislation.nsw.gov.au/view/whole/html/inforce/current/sl-2025-0440
- SafeWork NSW, Code of Practice: Managing psychosocial hazards at work: https://www.safework.nsw.gov.au/resource-library/codes-of-practice/codes-of-practice/managing-psychosocial-hazards-at-work
- Victorian legislation, Occupational Health and Safety Act 2004, in-force version 045: https://www.legislation.vic.gov.au/in-force/acts/occupational-health-and-safety-act-2004/045
- Victorian legislation, Occupational Health and Safety (Psychological Health) Regulations 2025, in-force version 001: https://www.legislation.vic.gov.au/in-force/statutory-rules/occupational-health-and-safety-psychological-health-regulations-2025/001
- Federal Register of Legislation, Privacy Act 1988, current text: https://www.legislation.gov.au/C2004A03712/latest/text
- Office of the Australian Information Commissioner, Guidance on privacy and the use of commercially available AI products: https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-the-use-of-commercially-available-ai-products
- Comcare, Contact centre worker: https://www.comcare.gov.au/office-safety-tool/roles/contact-centre-worker
- WorkSafe Victoria, Aggression or violence: A guide for employers, January 2026: https://content-v2.api.worksafe.vic.gov.au/sites/default/files/2026-01/Aggression-or-violence-guide-employers-2026-01.pdf
- WorkSafe Victoria, Preventing and managing aggression or violence - case studies: https://www.worksafe.vic.gov.au/preventing-and-managing-aggression-or-violence-case-studies
TheAICommand. Intelligence, At Your Command.


