How an Australian healthcare organisation cut Shadow AI prompts by 92.9% in three months.
The organisation needed defensible evidence and real-time enforcement to keep staff on its approved AI tool. Aona delivered monitoring, governance, and guardrails without a heavy IT lift.
92.9%
reduction in Shadow AI prompts
Three months after guardrails
446
Shadow AI prompts
Submitted outside the approved tool
8,904
unapproved AI visits
Surfaced across 12 months
7+
unapproved platforms
Detected in active use
Customer
Identity withheld
Sector
Healthcare & professional education
Region
Australia · Privacy Act
Aona stack
Browser extension + governance portal
When AI adoption is happening anyway, governance has to be real-time.
This healthcare organisation operates in a high-trust environment with strict confidentiality expectations. Staff were adopting AI quickly, but usage was fragmented across consumer tools and the approved option, Microsoft Copilot, was not enforceable in practice.
Customer background
A high-trust healthcare organisation handling sensitive information.
The organisation supports professional education, stakeholder services, governance and communications. Its workforce handles sensitive assessment, member, financial and strategic information under Australian Privacy Act obligations.
AI adoption was already happening across teams without central oversight. Governance needed to match the speed of adoption, not sit beside it as a policy document.
Outcome
92.9%
fewer Shadow AI prompts in three months, while overall AI usage continued to grow.
“We needed a way to monitor AI usage across the organisation and implement an AI staff policy. We support the use of new technology, but we needed guardrails to make sure it was happening safely.”
Senior systems and security administrator
Australian healthcare organisation · identity withheld
The customer’s name, location and individual identities are withheld at its request. Industry context, quoted feedback and measured outcomes are published with permission.
They had a policy. They didn’t have proof, control, or a safety net.
Staff handled sensitive assessment, member, financial and strategic information. As generative AI went mainstream, they naturally experimented with whichever tools helped them move faster. The risk moved to the browser; governance did not follow.
Unapproved platforms
7+
Distinct AI tools in active use across the workforce.
Shadow AI prompts
446
Prompts submitted outside the approved tool over 12 months.
Site visits
8,904
Visits to unapproved AI experiences, including AI search.
The uncomfortable part
Without prompt visibility and an audit trail, the security team could not answer the questions leadership and auditors actually ask: What data left? Who shared it? When? And could it happen again tomorrow?
Three layers of pain, at the same time
Operational
A constant stream of new AI tools to chase, with no reliable way to measure compliance with the approved option.
Strategic
No defensible evidence for board reporting or compliance assurance under Privacy Act expectations.
Human
Staff were trying to get work done. They needed guidance in the moment, not another document in a shared drive.
Fast time-to-value with real controls, not just reporting.
Lightweight deployment
A browser extension that rolled out with minimal disruption and no network re-architecture.
Workforce-wide visibility
One view of approved and unapproved AI usage, with the context needed to understand risk.
Real-time guardrails
In-the-moment guidance that steered staff back to the approved tool before data could be exposed.
Configurable governance
Policies and reporting tailored to the organisation’s operating context and governance model.
Browser monitoring, governance portal, and guardrails.
Aona captured AI traffic at the browser layer and centralised it into a governance portal. When staff reached for an unapproved tool, guardrails surfaced policy guidance and steered them back to Microsoft Copilot.
Browser extension
Captured AI traffic at the source across approved and unapproved platforms.
Governance portal
Centralised the audit trail and turned workforce activity into leadership-ready evidence.
Real-time guardrails
Displayed policy guidance and redirected staff to Microsoft Copilot at the moment of risk.
What was included
Visibility across approved and unapproved AI platforms, centralised leadership reporting, just-in-time user guidance and governance aligned to internal policies.
What was not required
No DNS-layer blocks, new identity provider, invasive endpoint agent or policy retraining sprint. Aona slotted into the existing browser workflow.
Outcomes a security leader can take to a board, auditor, or executive team.
92.9%
Drop in Shadow AI prompts in three months after guardrails were enabled, while staff AI usage continued to grow. The organisation did not ban AI; it made the safe path the easy path.
Shadow AI prompts
In the three-month window after enforcement
Active unapproved platforms
In the latest reporting period
At-risk users
Behavioural risk became concentrated and addressable
Policy violations
With guardrails intercepting risk in the latest period
Operational efficiency
Guardrails intercept risk in real time instead of relying on after-the-fact awareness. Evidence is available on demand, shifting leadership reporting from “we think” to “we know.”
Governance maturity
The organisation reported complete workforce visibility into AI traffic and classified 41 prompt use cases, adding business context beyond raw site visits.
An approved AI tool is not the same as proof that people are using it.
If your organisation has approved AI tools but no evidence that the policy is being followed, you likely have Shadow AI risk you cannot see. Aona shows what is happening, then applies guardrails that make governance measurable.