30 jours d'essai gratuit, risques IA générative :Commencer
Demander une démo
All case studies
Anonymous customer story

How an Australian healthcare organisation cut Shadow AI prompts by 92.8% in 30 days.

Aona surfaced 446 prompts submitted outside the approved tool. After the organisation blocked unwanted platforms and introduced pre-submission guardrails, that number fell to 32 in 30 days.

92.8%

reduction in Shadow AI prompts

30 days after guardrails

446

Shadow AI prompts

Submitted outside the approved tool

8,904

unapproved AI visits

Surfaced during the inspection

7+

unapproved platforms

Detected in active use

Customer

Identity withheld

Sector

Healthcare & professional education

Region

Australia · Privacy Act

Aona stack

Browser extension + governance portal

At a glance

When AI adoption is happening anyway, governance has to be real-time.

This healthcare organisation operates in a high-trust environment with strict confidentiality expectations. Staff were adopting AI quickly, but usage was fragmented across consumer tools and the approved option, Microsoft Copilot, was not enforceable in practice.

Customer background

A high-trust healthcare organisation handling sensitive information.

The organisation supports professional education, stakeholder services, governance and communications. Its workforce handles sensitive assessment, member, financial and strategic information under Australian Privacy Act obligations.

AI adoption was already happening across teams without central oversight. Governance needed to match the speed of adoption, not sit beside it as a policy document.

Outcome

92.8%

fewer prompts were submitted outside the approved tool 30 days after guardrails were enabled.

We needed a way to monitor AI usage across the organisation and implement an AI staff policy. We support the use of new technology, but we needed guardrails to make sure it was happening safely.

Senior systems and security administrator

Australian healthcare organisation · identity withheld

The customer’s name, location and individual identities are withheld at its request. Industry context, quoted feedback and measured outcomes are published with permission.

Business challenge

They had a policy. They didn’t have proof, control, or a safety net.

Staff handled sensitive assessment, member, financial and strategic information. As generative AI went mainstream, they naturally experimented with whichever tools helped them move faster. The risk moved to the browser; governance did not follow.

Unapproved platforms

7+

Distinct AI tools in active use across the workforce.

Shadow AI prompts

446

Prompts submitted outside the approved tool before guardrails.

AI-site visits

8,904

Visits to unauthorised AI experiences surfaced during the 30-day inspection.

The uncomfortable part

Without prompt visibility and an audit trail, the security team could not answer the questions leadership and auditors actually ask: What data left? Who shared it? When? And could it happen again tomorrow?

Three layers of pain, at the same time

Operational

A constant stream of new AI tools to chase, with no reliable way to measure compliance with the approved option.

Strategic

No defensible evidence for board reporting or compliance assurance under Privacy Act expectations.

Human

Staff were trying to get work done. They needed guidance in the moment, not another document in a shared drive.

Why Aona

Fast time-to-value with real controls, not just reporting.

Lightweight deployment

A browser extension that rolled out with minimal disruption and no network re-architecture.

Workforce-wide visibility

One view of approved and unapproved AI usage, with the context needed to understand risk.

Real-time guardrails

Intercepted prompts and file uploads before submission, then warned, redirected or hard-blocked according to policy.

Configurable governance

Policies and reporting tailored to the organisation’s operating context and governance model.

Solution delivered

Browser monitoring, governance portal, and guardrails.

Aona detected visits to AI sites and intercepted prompts and file uploads at the browser layer before submission. Policies blocked unwanted platforms and subscriptions; on authorised platforms, real-time guardrails analysed the content and stopped sensitive data before it could leave the device.

01

Browser extension

Detected AI-site visits and intercepted prompts and file uploads at the point of submission.

02

Governance portal

Centralised the audit trail and turned workforce activity into leadership-ready evidence.

03

Real-time guardrails

Blocked unauthorised platforms and stopped risky prompts before they left the device, while guiding staff to Microsoft Copilot.

What was included

Visibility across approved and unapproved AI platforms, pre-submission inspection of prompts and file uploads, hard blocking, centralised reporting, just-in-time guidance and governance aligned to internal policies.

What was not required

No DNS-layer blocks, new identity provider, invasive endpoint agent or policy retraining sprint. Aona slotted into the existing browser workflow.

Privacy and security controls for this deployment

No raw-content retention

Prompt and file contents were evaluated in real time but were not stored. Only high-level analytics were retained.

Australian data residency

Content was processed transiently in Australia, and the resulting analytics data was stored in Australia.

Encrypted throughout

Customer analytics data was encrypted in transit and at rest.

Independently assessed

Aona’s security controls are covered by its SOC 2 Type II attestation.

Key results and impact

Outcomes a security leader can take to a board, auditor, or executive team.

92.8%

Shadow AI prompts fell from 446 to 32 in the 30 days after guardrails were enabled. The organisation blocked unwanted platforms and applied pre-submission controls to the AI tools employees were authorised to use.

How the 92.8% was calculated

(446 Shadow AI prompts before − 32 after) ÷ 446 before × 100 = 92.8%, rounded to one decimal place.

Shadow AI prompts

44632

30 days after guardrails were enabled

Active unauthorised platforms

72

Most unwanted platforms and subscriptions were blocked

At-risk users

134

Behavioural risk became concentrated and addressable

Raw content retained

0

Prompt and file contents were processed transiently and not stored

Operational efficiency

Guardrails intercept prompts and file uploads before submission, then block, warn, redirect or allow according to policy. High-level evidence is available on demand without retaining raw prompt or file content.

Governance maturity

The organisation reported complete workforce visibility into AI traffic and classified 41 prompt use cases, adding business context beyond raw site visits.

Key takeaway

An approved AI tool is not the same as proof that people are using it.

If your organisation has approved AI tools but no evidence that the policy is being followed, you likely have Shadow AI risk you cannot see. Aona shows what is happening, then applies guardrails that make governance measurable.