Your approved-tool register describes the systems management intended. A safe-disclosure inventory should reveal how personal AI has changed real tasks, then trigger proportionate interim controls, worker consultation and human-led decisions without making candour an automatic disciplinary event.
Shadow AI is not primarily a software-list problem. It is an undisclosed change to how work is prepared, checked, paced, escalated or decided.
Find the changed work. Use a bounded discovery lane to map task-level use, apply interim controls and consult workers and HSRs about the work system that exists. Safe-disclosure is a local workflow label, not a statutory category, confidentiality promise or immunity from human-led investigation.
What does an approval register miss?
An approval register answers which tools the organisation authorised. It rarely shows that a branch manager uses a personal account to rewrite customer-aggression notes, an insurer's analyst asks a browser tool to classify complaint themes, or a team leader relies on generated summaries before allocating work.
Those practices may change more than data handling. They can alter task order, throughput expectations, cognitive load, access to supervision, error pathways, role clarity and the point at which a human sees source material. The material WHS question is not simply "Which product?" It is "What changed in the work?"
Safe Work Australia's current WHS duties guidance for AI and digital technologies says PCBUs must identify how AI and digital technologies they implement or use in the workplace might impact health and safety, and control risks as much as they reasonably can, and must consult workers and their health and safety representatives about work health or safety matters. It also says workers need necessary information, training, instruction or supervision and genuine opportunities to ask questions or raise concerns.
The current Commonwealth Work Health and Safety Act 2011, Compilation No. 16 dated 1 July 2024 provides the statutory anchors. Section 19 places the primary duty on the PCBU, so far as is reasonably practicable. Sections 47 to 49 require consultation with directly affected workers when identifying hazards and assessing risks, deciding controls and proposing changes that may affect health or safety. Section 27 keeps officer due diligence with people, not software.
Workers also have duties under section 28, including to take reasonable care and cooperate with reasonable notified WHS policies and procedures. That does not turn a written ban into proof that the real work follows the register. PCBU and worker duties coexist.
Safe Work Australia's managing-risks guidance points to the ordinary cycle: identify hazards, assess risks where needed, control them, then monitor and review. Its examples include increased pace, higher workload, cognitively demanding residual work, low job control, poor support, lack of role clarity and poor organisational change management. Those are psychosocial hazards arriving through a tool nobody approved.
The current Commonwealth WHS Regulations 2011, Compilation No. 28 dated 25 March 2025 require controls implemented under the Regulations to remain effective and to be reviewed and revised in specified circumstances. An interim control for shadow AI needs an owner, test and review trigger. "Email sent to all staff" is not a maintenance method.
This is distinct from consultation before a planned rollout. Here, the first problem is discovery. Consultation cannot travel back in time, but the organisation can consult now about identified hazards, present controls, proposed changes and what workers need to do the task safely without the personal tool.
NSW's newer digital-work-systems scheme remains staged. As at 31 July 2026, SafeWork NSW says only the provisions supporting guideline development have commenced; all other provisions, including the new work-allocation duty and the entry-permit-holder assistance power itself, commence on proclamation, and that start date must be at least one month after the guidelines are published. Treat those uncommenced provisions as future obligations, not current law. Existing WHS duties still apply. The consultation angle differs from the one that matters when a tool is deployed openly: there, the question is what HSRs should be asking about a system already in use. Here, nobody has told them the system exists.
Victoria's separate Occupational Health and Safety Act 2004, version 045 and Psychological Health Regulations, version 001 in force since 1 December 2025 form a different framework. Apply each workforce's law and regulator material rather than copying Commonwealth section numbers into a national procedure.
Use this prompt to convert approved, de-identified discovery material into a work-change inventory. A WHS practitioner must verify each work claim; privacy and security specialists must approve the input fields and review any risk signal before further collection.
How do you discover shadow AI without driving it underground?
Separate safety discovery from conduct adjudication. The first channel should ask workers to describe changed tasks and risk conditions, not confess to a charge. This is not blanket amnesty. Suspected serious misconduct, security events or privacy incidents still go to authorised people under existing processes, with facts assessed by humans.
Use a disclosure firewall with three lanes:
- Pattern lane: collect the work group, task, tool category, information class, frequency, decision influence and work effects. Default to group-level reporting and do not collect prompt contents or names merely to count the pattern.
- Urgent-event lane: immediately route suspected exposure of personal or confidential information, unsafe automated action, decision substitution or another material event to the authorised WHS, privacy, security or legal process. The intake tool does not make the legal finding.
- Conduct lane: where individual investigation may be warranted, create a separate human-authorised process with defined purpose, access and procedural safeguards. Do not quietly repurpose the safety survey into an employee-monitoring dossier.
The firewall protects the quality of the risk picture. If every disclosure automatically becomes a misconduct referral, the register may look cleaner while the work stays unchanged. That is an operational inference, not a promise that conduct will never be examined.

The Privacy Act 1988 is in force in compilation 104 dated 4 June 2026. The OAIC's 4 December 2025 blog on GenAI tools in the workplace restates its October 2024 guidance that regulated entities refrain from entering personal information, particularly sensitive information, into publicly available tools. It warns that information entered can be difficult to track or control and potentially impossible to remove, depending on settings.
The OAIC illustrates the governance gap through its fictional CarCover case study. A policy barred personal-information uploads and technical measures were intended to identify and notify incidents, yet a worker uploaded a financial-hardship application and a generated summary minimised relevant and key aspects of the application before CarCover refused it. CarCover's response combines staff awareness, technical prevention and limits on GenAI use in business areas and circumstances where risks to organisational decision-making were identified. Policy, detection and human review need to work together.
That makes data minimisation part of discovery. Ask whether personal, sensitive, confidential or regulated data categories were used. Do not ask workers to paste the data, upload the prompt history or repeat identifiable customer content into the inventory. A privacy adviser should determine whether further evidence is required and how it may lawfully be handled.
Apply interim controls at the work-pattern level. A useful control card records the activity, immediate boundary, safe alternative, temporary workload adjustment, human owner, consultation step, evidence needed, expiry and review trigger. The safe alternative matters. Stopping a time-saving workaround while leaving the same queue, staffing and deadline can intensify the condition that produced it.
Use this interim-control checklist:
- Pause personal-tool use for sensitive data, safety-critical instructions, automated action and decisions affecting people.
- Preserve a workable manual or approved-tool route and adjust output expectations where needed.
- Require a competent human to return to the source before any output is relied on.
- Consult affected workers and HSRs on task reality, pressure points and proposed controls.
- Review related records using authorised access and minimum necessary information.
- Set a short expiry so an interim restriction cannot become an untested permanent system.
Fictional worked example: Workers in [CONTACT_CENTRE_TEAM] at [BANK_NAME] disclose that a public AI tool is being used to summarise complaint narratives before handover. They say the practice began because [QUEUE_CONDITION] leaves little reading time. No names, prompts or complaint text are collected in the pattern lane.
The human triage group pauses customer-data entry into public tools, routes any suspected disclosure to [PRIVACY_RESPONSE_ROLE] for assessment, and restores an approved manual summary template. It temporarily resets [THROUGHPUT_EXPECTATION], samples whether supervisors can access source narratives and consults the work group and [HSR_ROLE] about workload, accuracy and escalation. It does not ask AI whether a privacy breach occurred or whether any worker should be disciplined.
The final response may include an approved tool, redesigned task, training, technical restriction, workload control or a combination. The answer must follow evidence and consultation. It should not be predetermined by the discovery form.
Use this prompt to prepare interim-control options. A WHS lead must approve the risk boundary, affected workers and HSRs must be consulted, and privacy, security, legal and employee-relations specialists must make decisions within their own authority.
Technical discovery can support the picture, but it is not permission for covert or indiscriminate monitoring. Define purpose, authority, access, retention, worker communication and human review before using network or application signals. Combine system evidence with worker accounts. Neither tells the complete story alone.
Do this Monday
- Open an access-controlled pattern channel. Tell workers what will be collected, what will not, who can see it and how urgent events will be routed. Involve HSRs before launch.
- Map five changed tasks. Capture task, data category, decision influence, frequency, human check and effects on workload, pace, role clarity and support.
- Issue interim control cards. Set the immediate boundary, workable alternative, owner, expiry and consultation step for each material pattern.
- Separate the lanes. Document when a pattern moves to a privacy, security, WHS incident or human-led conduct process. Do not let the inventory tool decide.
- Fix the pressure source. Test whether queues, access barriers, staffing, quality measures or missing approved tools encouraged the workaround, then include those conditions in the final risk decision.
Bottom line
An approval register is not a map of actual work. Find shadow AI through a safe-disclosure inventory that exposes changed tasks without collecting unnecessary personal content. Apply proportionate interim controls, preserve a workable alternative and consult the people doing the work. Keep legal, privacy, investigation and disciplinary decisions with authorised humans.
This article is general information and education only. It is not legal, compliance, financial or professional advice. Obligations vary by organisation and circumstance. Verify current requirements against the primary sources cited and seek advice specific to your situation.
References
- Safe Work Australia, Artificial intelligence (AI) and digital technologies - WHS duties: https://www.safeworkaustralia.gov.au/safety-topic/hazards/digital-technologies-ai/whs-duties
- Federal Register of Legislation, Work Health and Safety Act 2011, current text: https://www.legislation.gov.au/C2011A00137/latest/text
- Safe Work Australia, Artificial intelligence (AI) and digital technologies - Managing risks: https://www.safeworkaustralia.gov.au/safety-topic/hazards/digital-technologies-ai/managing-risks
- Federal Register of Legislation, Work Health and Safety Regulations 2011, current text: https://www.legislation.gov.au/F2011L02664/latest/text
- SafeWork NSW, Work Health and Safety Amendment (Digital Work Systems) Act 2026 (Amendment Act): https://www.safework.nsw.gov.au/legal-obligations/legislation/accordians/work-health-and-safety-amendment-digital-work-systems-act-2026-amendment-act
- SafeWork NSW, Development of the Digital Work Systems Guidelines: https://www.safework.nsw.gov.au/resource-library/consultation/development-of-the-digital-work-systems-guidelines
- Victorian legislation, Occupational Health and Safety Act 2004, current in-force version 045: https://www.legislation.vic.gov.au/in-force/acts/occupational-health-and-safety-act-2004/045
- Victorian legislation, Occupational Health and Safety (Psychological Health) Regulations 2025, in-force version 001: https://www.legislation.vic.gov.au/in-force/statutory-rules/occupational-health-and-safety-psychological-health-regulations-2025/001
- Federal Register of Legislation, Privacy Act 1988, compilation 104, 4 June 2026: https://www.legislation.gov.au/C2004A03712/latest/text
- Office of the Australian Information Commissioner, GenAI tools in the workplace: balancing protection of personal information and business efficiency, 4 December 2025: https://www.oaic.gov.au/news/blog/GenAI-tools-in-the-workplace-balancing-protection-of-personal-information-and-business-efficiency
TheAICommand. Intelligence, At Your Command.


