Customer Abuse Is a WHS Signal, Not Just a Conduct Problem., practitioner guidance from TheAICommand
← WHS & AI
Practical GuideWHS

Customer Abuse Is a WHS Signal, Not Just a Conduct Problem.

Customer abuse data belongs in the WHS risk picture, but a model must not become a customer blacklist or an employee surveillance system. Use AI to surface channel-level exposure patterns, have people verify them, then redesign work, service and recovery controls.

Practitioner content. Written for WHS and safety professionals under the model WHS laws (with Victoria, WA, and the Comcare scheme noted where they differ). General information only. Not legal or WHS advice. A competent person makes every risk and notification decision.

Quick answer

Treat it as exposure evidence, not just conduct. AI can screen appropriately governed contact and complaint data for candidate patterns by channel, journey stage and time window. People must validate the records, consult affected workers and decide the controls. The model never scores a customer or a worker, infers health or decides notifiability.

Customer abuse data belongs in the WHS risk picture, but a model must not become a customer blacklist or an employee surveillance system. Use AI to surface channel-level exposure patterns, have people verify them, then redesign work, service and recovery controls.

Customer abuse is not only a conduct problem to be managed one interaction at a time. Repeated threats, insults, harassment and hostile contact are evidence about how work exposes people to aggression, especially in branches, complaints teams and contact centres. Aggression or violence is a named psychosocial hazard, not a customer-service metric.

AI can help screen appropriately governed contact and complaint data for candidate patterns that manual sampling misses. The useful unit is the channel, journey stage or time window. It is not a score attached to a customer or worker.

People must validate every pattern, consult affected workers and decide the controls. The screening step belongs inside the AI-assisted psychosocial risk assessment you already run, not beside it. The model does not judge intent, sanction a customer, assess a worker's health or decide whether an incident is notifiable.

What should AI screen for, and what must it never decide?

For Commonwealth jurisdiction employers, the current Work Health and Safety Act 2011 compilation, dated 1 July 2024, places the primary duty on the PCBU. Section 47 requires the PCBU, so far as is reasonably practicable, to consult with workers who are, or are likely to be, directly affected by a matter relating to work health or safety. Section 49 requires that consultation when identifying hazards and assessing risks, when making decisions about ways to eliminate or minimise those risks, and when proposing changes that may affect the health or safety of workers.

The current Commonwealth WHS Regulations compilation, dated 25 March 2025, define a psychosocial hazard as one arising from, or relating to, the design or management of work, a work environment, plant at a workplace, or workplace interactions or behaviours, and that may cause psychological harm. Regulation 55C imposes the duty to manage psychosocial risks and to implement the control measures required by regulation 55D. Regulation 55D(2) then lists the matters a person must have regard to in determining those control measures, including the duration, frequency and severity of exposure, how the hazards may interact or combine, the systems of work including how work is managed, organised and supported, and the information, training, instruction and supervision provided to workers.

A single abusive call can be serious, while repeated lower-level hostility may create a cumulative exposure. Queue pressure, rigid handle-time targets, transfers and poor support can combine with aggression rather than sit in separate risk-register rows.

Safe Work Australia's model Code of Practice has legal effect only where a jurisdiction approves it. Its violence and aggression guidance lists what you should do to identify the hazard, including observing contact with the public, looking for long customer queues and wait times, observing lower level but more frequent behaviours, surveying clients to find problems with service delivery, surveying workers about incidents or behaviours, and checking hazard and incident reports and workers compensation claims. That is broader than formally reported incidents.

Under the current Work Health and Safety Regulation 2025, section 55C requires a person conducting a business or undertaking to manage psychosocial risks in accordance with Part 3.1, which contains the section 36 hierarchy of control measures, and to implement the control measures required by section 55D. The approved SafeWork NSW psychosocial Code states that a PCBU's goal to produce a product, provide a particular model of patient care, achieve particular educational outcomes, or focus on customer service, cannot override the duty the WHS Act places on the PCBU to ensure, so far as is reasonably practicable, the work health and safety of their workers and others.

Victoria has a separate regime. The OHS Act is in force in version 045, and the Psychological Health Regulations are in force in version 001 from 1 December 2025. They give aggression or violence as the first example of a psychosocial hazard, and require the employer to eliminate the risk so far as is reasonably practicable and, failing that, to reduce it by altering the management of work, the plant, the systems of work, the work design or the workplace environment. Information, instruction or training may be used exclusively only where none of those alterations is reasonably practicable.

Three regimes sit behind the same contact centre, and they do not use identical language:

JurisdictionDuty provisionControl provisionNote
CommonwealthWHS Act 2011 s 47, consult so far as is reasonably practicable; s 49, when consultation is requiredWHS Regulations reg 55C duty, reg 55D(2) mattersReg 55A defines the hazard across work design or management, work environment, plant, and workplace interactions or behaviours
New South WalesWH&S Regulation 2025 s 55CPart 3.1 s 36 hierarchy, plus s 55D control measures in Part 3.2 Division 11The 2025 remake uses "section", not "clause"
VictoriaOHS Act 2004 version 045Psychological Health Regulations 2025 reg 15, eliminate first, then alter management, plant, systems of work, work design or environmentInformation, instruction or training may be used exclusively only where no alteration is reasonably practicable

Build a contact-friction exposure map. Ask the model to propose candidate signals across four dimensions:

  • exposure form, such as direct threats, sexual or discriminatory abuse, coercion, repeated hostile contact and lower-level but frequent aggression
  • process location, such as identity checks, hardship, claim decline, complaint escalation, service outage or branch closing time
  • exposure conditions, such as channel, time window, contact volume, repeat contact, queue state and available supervisor support
  • control response, such as warning, termination, escalation, relief break, handover, follow-up and whether the procedure worked.

Use rates against a suitable contact-volume denominator where possible. Raw counts can make the busiest team look most exposed even when a smaller channel has a higher concentration of abuse. Keep both views because a high rate and a high total load answer different control questions.

This is candidate coding, not truth. A human validation set should include flagged records, low-confidence records and a sample the model marked as having no aggression. That last group tests false negatives, including coded threats, sarcasm and language the model handles poorly. Workers and HSRs then test whether the categories resemble real exposure or merely the wording easiest for software to spot. The questions an HSR should ask about a deployed AI tool apply to this one as much as to any other.

The Privacy Act 1988 is in force in Compilation No. 104, dated 4 June 2026. The OAIC's AI guidance recommends privacy impact assessment, minimising personal information and keeping personal or sensitive information out of public generative AI tools.

Confirm the APP 6 basis before reusing complaint or contact data. The OAIC guidance says a new use or disclosure of personal information must comply with APP 6. An approved tool, a WHS purpose label and removing direct identifiers do not themselves authorise the secondary use.

Use an approved environment, remove identifiers where the purpose permits, restrict access and set retention. Separate WHS trends from customer decisions and employee performance. Never infer dangerousness, rank resilience or create hidden individual measures.

Use this prompt to draft a channel-level signal map from approved, minimised data. A WHS practitioner, privacy specialist and worker or HSR representatives must review the taxonomy, sample the source records and verify every retained pattern before use.

Prompt
Prepare a candidate contact-friction exposure map for human validation.

Approved minimised dataset: [APPROVED_DATASET]
Permitted purpose: [WHS_TREND_PURPOSE]
Fields and definitions: [FIELD_DICTIONARY]
Contact-volume denominator: [VOLUME_DATA]
Work groups and channels: [AGGREGATED_SCOPE]
Known service changes: [SERVICE_CHANGE_LOG]

Group candidate aggression signals by channel, journey stage and time window.
For each pattern, show the evidence fields, volume and rate, confidence, possible
interacting work factors and records requiring human review. Include separate
samples of flagged, low-confidence and no-signal records for validation.

Do not identify or score a customer or worker, infer intent or health, recommend
sanctions, decide incident notifiability, or assess individual performance. Mark
unsupported explanations as [UNKNOWN] and output no final risk rating.

How do patterns become better controls?

A single halo reading ZERO above a caption about person scores in a channel-level exposure map
The map counts channels, journey stages and time windows. It never scores a customer or a worker.

The exposure map earns its place only when it changes the system of work. A red cluster labelled "abusive language" is not a control, and it is not a risk-register trigger until a person has validated it. It is a prompt for workers, HSRs, operations, customer teams and WHS specialists to ask what created the exposure and what can reduce it.

Service friction never excuses abuse. It can still be a preventable exposure driver. If aggression spikes after a confusing decline letter, an avoidable transfer loop or an outage with no status information, fixing that process may remove contacts before a worker has to absorb them.

Safe Work Australia states that to manage the risks you must provide a safe physical and online work environment, implement safe work systems and procedures, have clear workplace policies, and provide workers with information, training and supervision. Comcare's contact-centre guidance adds a call termination procedure that lets workers warn clients and escalate calls to more senior personnel, access to counselling services, break areas away from the phones, and rostering that covers peak times while allowing periods of relief through breaks.

The strongest response is usually a control bundle. Start upstream with service redesign and authority for complex complaints. Add clear warning, termination and escalation rules; staffing that preserves relief; protected recovery after difficult interactions; supervisor response standards; and support routes. Training helps people use the system. It should not become the organisation's answer to a system that keeps exposing them.

WorkSafe Victoria's current employer guide asks whether incident, employee assistance and claims data have been analysed to identify trends or patterns of psychosocial hazards including aggression or violence. Separately, under work design, it lists refining complaints processes so complex or difficult complaints can be escalated to more senior employees empowered to resolve them. Its call-centre case study places aggression or violence beside low job control, high job demands, poor support and poor organisational justice, with an average handle time target as the mechanism. Controls include demand analysis, peak staffing, breaks, escalation and fair target exceptions.

Do not import every example feature without assessment. This workflow never places model-generated aggression labels on customer profiles or automatically routes, restricts or penalises anyone. Those actions raise separate legal, privacy, conduct and fairness questions. The WHS map stays aggregated; authorised people handle particular interactions under approved procedures.

Fictional worked example: [BANK_NAME] screens a de-identified sample of complaint notes and chat transcripts from [CONTACT_CENTRE]. The model suggests a concentration of hostile contacts at [PROCESS_STAGE] between [TIME_WINDOW], but people reviewing the records find that half the flags are ordinary expressions of frustration. They also find missed indirect threats in the no-signal sample.

The team corrects the taxonomy and recalculates the pattern. Workers and the HSR explain that repeated transfers, limited hardship authority and a visible queue create pressure to keep abusive contacts going. After consultation, accountable leaders approve a service handoff fix, a human escalation route, protected relief after defined exposures and a performance-target exception. No customer or worker score is created.

Use this prompt to turn a human-validated pattern into options, not decisions. Operations and WHS leaders must review feasibility and risk, then consult affected workers and HSRs before choosing, approving or implementing any control.

Prompt
Draft a control-options brief from this human-validated exposure pattern.

Validated pattern: [VALIDATED_AGGREGATED_PATTERN]
Worker and HSR evidence: [CONSULTATION_INPUT]
Current controls and failures: [CONTROL_EVIDENCE]
Service constraints: [SERVICE_CONSTRAINTS]
Applicable jurisdiction: [JURISDICTION]

Present options in this order: remove the exposure driver; redesign the service
or work; improve authority, escalation and termination; change staffing, targets
or relief; improve supervisor response and post-contact support. For each option,
state the exposure addressed, owner, dependency, possible new risk, worker input
still needed and effectiveness measure.

Do not select a control, make a legal finding, assess a person, recommend customer
sanctions or replace consultation. Mark missing evidence as [HUMAN_DECISION].

Keep ordinary reporting and emergency routes open. Screening historical data is not live threat detection, an emergency response, an incident investigation or a notifiability decision. A person receiving an immediate threat follows the approved human escalation and emergency procedure.

Do this Monday

  1. Choose one bounded channel. Select a complaints queue, contact-centre team or branch process with worker-reported aggression. Write the WHS purpose, work-group scope and decisions the analysis is prohibited from influencing.
  2. Consult before extracting. Ask affected workers and HSRs where aggression occurs, what lower-level conduct goes unreported, which interacting demands matter and what a useful aggregated output would look like.
  3. Set the data boundary. Involve privacy, security and records owners. Use the minimum approved fields, de-identify where the purpose permits, separate the dataset from performance systems and prohibit public AI tools.
  4. Build and test the map. Have people review flagged, low-confidence and no-signal samples. Correct false positives and false negatives before calculating channel and process-stage patterns.
  5. Convert one pattern into controls. Take one validated cluster through service redesign, escalation, staffing, target, break, supervisor and support options. Consult, assign a human owner and set an effectiveness measure and review trigger.
  6. Keep individuals out of the output. Confirm that no customer or worker score, sanction recommendation, health inference, notifiability decision or automated adverse action can leave the workflow.

Bottom line

Customer abuse data can reveal a work-design problem before an incident register does. AI is useful for finding candidate channel-level patterns, provided people validate the records and individuals are not scored. The real control decision belongs with accountable leaders in consultation with workers and HSRs. If the output does not change service design, authority, staffing, recovery or support, it is analytics theatre.

This article is general information and education only. It is not legal, compliance, financial or professional advice. Obligations vary by organisation and circumstance. Verify current requirements against the primary sources cited and seek advice specific to your situation.

References

  1. Federal Register of Legislation, Work Health and Safety Act 2011, current text: https://www.legislation.gov.au/C2011A00137/latest/text
  2. Federal Register of Legislation, Work Health and Safety Regulations 2011, current text: https://www.legislation.gov.au/F2011L02664/latest/text
  3. Safe Work Australia, Model Code of Practice: Managing psychosocial hazards at work: https://www.safeworkaustralia.gov.au/doc/model-code-practice-managing-psychosocial-hazards-work
  4. Safe Work Australia, Workplace violence and aggression - Managing risks: https://www.safeworkaustralia.gov.au/safety-topic/hazards/workplace-violence-and-aggression/managing-risks
  5. NSW legislation, Work Health and Safety Regulation 2025, current text: https://legislation.nsw.gov.au/view/whole/html/inforce/current/sl-2025-0440
  6. SafeWork NSW, Code of Practice: Managing psychosocial hazards at work: https://www.safework.nsw.gov.au/resource-library/codes-of-practice/codes-of-practice/managing-psychosocial-hazards-at-work
  7. Victorian legislation, Occupational Health and Safety Act 2004, in-force version 045: https://www.legislation.vic.gov.au/in-force/acts/occupational-health-and-safety-act-2004/045
  8. Victorian legislation, Occupational Health and Safety (Psychological Health) Regulations 2025, in-force version 001: https://www.legislation.vic.gov.au/in-force/statutory-rules/occupational-health-and-safety-psychological-health-regulations-2025/001
  9. Federal Register of Legislation, Privacy Act 1988, current text: https://www.legislation.gov.au/C2004A03712/latest/text
  10. Office of the Australian Information Commissioner, Guidance on privacy and the use of commercially available AI products: https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-the-use-of-commercially-available-ai-products
  11. Comcare, Contact centre worker: https://www.comcare.gov.au/office-safety-tool/roles/contact-centre-worker
  12. WorkSafe Victoria, Aggression or violence: A guide for employers, January 2026: https://content-v2.api.worksafe.vic.gov.au/sites/default/files/2026-01/Aggression-or-violence-guide-employers-2026-01.pdf
  13. WorkSafe Victoria, Preventing and managing aggression or violence - case studies: https://www.worksafe.vic.gov.au/preventing-and-managing-aggression-or-violence-case-studies

TheAICommand. Intelligence, At Your Command.

Frequently asked questions

What is the right unit of analysis?
The channel, journey stage or time window, never the individual. A channel-level pattern points at work design, which is where the control sits. A person-level score points at someone to manage or sanction, which raises separate legal, privacy, conduct and fairness questions and does nothing to reduce the exposure.
Should we use raw counts or rates?
Keep both. Rates against a suitable contact-volume denominator stop the busiest team looking most exposed when a smaller channel has a higher concentration of abuse. Raw totals still matter because a high rate and a high total load answer different control questions.
Why sample records the model marked as having no aggression?
To test false negatives. A validation set of flagged records alone only tells you about the model's positives. The no-signal sample is where coded threats, sarcasm and language the model handles poorly show up, and those are exactly the exposures workers report and systems miss.
Does an approved tool and a WHS purpose label authorise the data reuse?
No. The OAIC's guidance says the use and disclosure of personal information must comply with APP 6. An approved tool, a WHS purpose label and removing direct identifiers do not themselves authorise a secondary use. Confirm the APP 6 basis with privacy, security and records owners before extracting anything.
Is screening historical data the same as threat detection?
No, and conflating them is dangerous. Screening past records for patterns is not live threat detection, an emergency response, an incident investigation or a notifiability decision. Ordinary reporting and emergency routes stay open, and a person receiving an immediate threat follows the approved human escalation and emergency procedure.

For practitioners

Break the signal down before you trust it. Abusive language in complaints is too broad to act on; hostile contact concentrated at one journey stage, in one time window, on one channel, after a specific service event is a statement you can test against records and against what workers say. Build the validation set from flagged, low-confidence and no-signal records, and treat a false negative as the more serious finding, because it is the exposure nobody is counting.

For governance leads

Set the prohibitions before the extract, not after the dashboard. Write down the WHS purpose, the work-group scope and the decisions this analysis is forbidden from influencing, then confirm the APP 6 basis with privacy, security and records owners. If the output can reach a customer decision, a performance system or an individual record, the control has failed regardless of how good the pattern looks.

Primary sources

WHS provisions referenced

Work Health and Safety Act 2011 (Cth) s 47Work Health and Safety Act 2011 (Cth) s 49Work Health and Safety Regulations 2011 (Cth) regs 55A, 55C and 55DWork Health and Safety Regulation 2025 (NSW) ss 36, 55C and 55DOccupational Health and Safety (Psychological Health) Regulations 2025 (Vic) reg 15
Customer AggressionPsychosocial HazardsContact CentresAI GovernanceWork Design
← Back to WHS & AI

Content disclaimer: This article is for general educational purposes only and does not constitute legal advice, WHS advice, or a substitute for professional judgement. Work health and safety duties, including psychosocial duties and incident notification duties, vary by jurisdiction under the model WHS laws (with Victoria, Western Australia, and the Comcare scheme differing). Risk ratings, controls, and notifiability decisions must be made by a competent person. All AI outputs described in this article require human review before use.