30 Days Gen AI Risk Trial -Start Now
Book a demo
All case studies
Anonymous customer story

How an Australian healthcare organisation cut Shadow AI prompts by 92.9% in three months.

The organisation needed defensible evidence and real-time enforcement to keep staff on its approved AI tool. Aona delivered monitoring, governance, and guardrails without a heavy IT lift.

92.9%

reduction in Shadow AI prompts

Three months after guardrails

446

Shadow AI prompts

Submitted outside the approved tool

8,904

unapproved AI visits

Surfaced across 12 months

7+

unapproved platforms

Detected in active use

Customer

Identity withheld

Sector

Healthcare & professional education

Region

Australia · Privacy Act

Aona stack

Browser extension + governance portal

At a glance

When AI adoption is happening anyway, governance has to be real-time.

This healthcare organisation operates in a high-trust environment with strict confidentiality expectations. Staff were adopting AI quickly, but usage was fragmented across consumer tools and the approved option, Microsoft Copilot, was not enforceable in practice.

Customer background

A high-trust healthcare organisation handling sensitive information.

The organisation supports professional education, stakeholder services, governance and communications. Its workforce handles sensitive assessment, member, financial and strategic information under Australian Privacy Act obligations.

AI adoption was already happening across teams without central oversight. Governance needed to match the speed of adoption, not sit beside it as a policy document.

Outcome

92.9%

fewer Shadow AI prompts in three months, while overall AI usage continued to grow.

“We needed a way to monitor AI usage across the organisation and implement an AI staff policy. We support the use of new technology, but we needed guardrails to make sure it was happening safely.”

Senior systems and security administrator

Australian healthcare organisation · identity withheld

The customer’s name, location and individual identities are withheld at its request. Industry context, quoted feedback and measured outcomes are published with permission.

Business challenge

They had a policy. They didn’t have proof, control, or a safety net.

Staff handled sensitive assessment, member, financial and strategic information. As generative AI went mainstream, they naturally experimented with whichever tools helped them move faster. The risk moved to the browser; governance did not follow.

Unapproved platforms

7+

Distinct AI tools in active use across the workforce.

Shadow AI prompts

446

Prompts submitted outside the approved tool over 12 months.

Site visits

8,904

Visits to unapproved AI experiences, including AI search.

The uncomfortable part

Without prompt visibility and an audit trail, the security team could not answer the questions leadership and auditors actually ask: What data left? Who shared it? When? And could it happen again tomorrow?

Three layers of pain, at the same time

Operational

A constant stream of new AI tools to chase, with no reliable way to measure compliance with the approved option.

Strategic

No defensible evidence for board reporting or compliance assurance under Privacy Act expectations.

Human

Staff were trying to get work done. They needed guidance in the moment, not another document in a shared drive.

Why Aona

Fast time-to-value with real controls, not just reporting.

Lightweight deployment

A browser extension that rolled out with minimal disruption and no network re-architecture.

Workforce-wide visibility

One view of approved and unapproved AI usage, with the context needed to understand risk.

Real-time guardrails

In-the-moment guidance that steered staff back to the approved tool before data could be exposed.

Configurable governance

Policies and reporting tailored to the organisation’s operating context and governance model.

Solution delivered

Browser monitoring, governance portal, and guardrails.

Aona captured AI traffic at the browser layer and centralised it into a governance portal. When staff reached for an unapproved tool, guardrails surfaced policy guidance and steered them back to Microsoft Copilot.

01

Browser extension

Captured AI traffic at the source across approved and unapproved platforms.

02

Governance portal

Centralised the audit trail and turned workforce activity into leadership-ready evidence.

03

Real-time guardrails

Displayed policy guidance and redirected staff to Microsoft Copilot at the moment of risk.

What was included

Visibility across approved and unapproved AI platforms, centralised leadership reporting, just-in-time user guidance and governance aligned to internal policies.

What was not required

No DNS-layer blocks, new identity provider, invasive endpoint agent or policy retraining sprint. Aona slotted into the existing browser workflow.

Key results and impact

Outcomes a security leader can take to a board, auditor, or executive team.

92.9%

Drop in Shadow AI prompts in three months after guardrails were enabled, while staff AI usage continued to grow. The organisation did not ban AI; it made the safe path the easy path.

Shadow AI prompts

44628

In the three-month window after enforcement

Active unapproved platforms

72

In the latest reporting period

At-risk users

134

Behavioural risk became concentrated and addressable

Policy violations

0

With guardrails intercepting risk in the latest period

Operational efficiency

Guardrails intercept risk in real time instead of relying on after-the-fact awareness. Evidence is available on demand, shifting leadership reporting from “we think” to “we know.”

Governance maturity

The organisation reported complete workforce visibility into AI traffic and classified 41 prompt use cases, adding business context beyond raw site visits.

Key takeaway

An approved AI tool is not the same as proof that people are using it.

If your organisation has approved AI tools but no evidence that the policy is being followed, you likely have Shadow AI risk you cannot see. Aona shows what is happening, then applies guardrails that make governance measurable.