Frontrow Technology
← All insights & guides
Guide

Cyber Security

AI misuse at work: the employer response checklist

Staff pasting client data into chatbots, AI-drafted grievance campaigns, AI claims at the Fair Work Commission. The detect, policy and response checklist for employers.

Sam Williams · 28 August 2026 · 10 min read

For the last two years, most workplace AI conversations have been about adoption: which licence, which pilot group, which use cases. In 2026 a second conversation has arrived, and it is landing on employers' desks uninvited. Employees are misusing AI at work, and the misuse now shows up in three distinct forms: confidential data pasted into public chatbots, AI-drafted internal grievance campaigns, and AI-generated claims arriving at the Fair Work Commission after a dismissal.

Each form needs a different control, and most Australian businesses have none of the three. This guide sets out what the misuse actually looks like, the new Fair Work Commission requirements that took shape this year, and a response checklist covering detection, policy, the sanctioned alternative, and what to do when an incident has already happened. One caveat up front: this is process and technical guidance from an IT provider, not legal advice. Where a matter is heading toward disciplinary action or a Commission claim, the employment lawyer comes in early, not last.

What AI misuse looks like in practice

The quiet form is data leakage. An employee pastes a client contract, a salary spreadsheet or a customer list into a free public chatbot to get a summary or a redraft. No malice, no exfiltration in the criminal sense, just confidential information leaving the company's control and landing with a consumer service whose terms the business never reviewed. Most organisations that go looking find far more of this than they expected.

The loud form played out in Wibmer v Fujifilm Data Management Solutions, decided by the Fair Work Commission in March 2026. A senior developer with an unblemished record since 2013 fell into a workplace grudge, and over three days sent at least 17 emails to managers and HR, many drafted with AI and citing the Fair Work Act, the Work Health and Safety Act, the Sex Discrimination Act and the Australian Human Rights Commission Act. Colleagues observed him consulting ChatGPT on his phone during meetings. The Commission upheld the dismissal, describing the employee as ungovernable and the AI-generated emails as disproportionate, and observed that the AI had given him a false sense of the strength of his position.

The third form arrives after employment ends. The Commission's president, Justice Adam Hatcher, told the Victorian Bar in February 2026 that the FWC's total workload had grown around 70 per cent in three years, with unfair dismissal claims up 41 per cent between 2022-23 and 2024-25, and attributed much of the growth to claims built with AI tools rather than to any rise in retrenchments. He noted the trade-off plainly: AI that tells workers their rights is a win for access to justice, but AI that invents facts to prop up a weak claim is not. For an employer, the practical effect is that a dismissal which once ended quietly is now more likely to come back as a polished, legislation-quoting application.

The FWC's new rules on AI-prepared claims

The Commission has responded. In August 2026 the FWC published a guidance note on the use of generative AI in Commission cases, applying from 20 October 2026. It sets three requirements for anyone using generative AI to prepare documents in a case: disclose when and how AI was used, check that the document is correct and relevant to the case, and, for witness statements and declarations, confirm the content is based on the person's own knowledge and words.

Two lessons for employers sit inside this. First, expect AI-assisted claims as the norm, not the exception, and brief whoever handles responses accordingly: invented authorities and confidently wrong facts are a known failure mode the Commission itself is now policing. Second, take the procedural-fairness lesson from the Fujifilm case. The Commission noted the employer had never explicitly warned the employee that the volume and tone of his emails could itself become a basis for termination. The misconduct outweighed that gap in the end, but a business that puts the warning in writing early keeps the gap from opening at all.

Detect: find the shadow AI first

None of the policy work matters if the business cannot see which AI tools staff already use. For organisations on Microsoft 365, Microsoft Defender for Cloud Apps does this discovery work: its cloud app catalogue has a dedicated generative AI category covering hundreds of applications, each with a risk score across security, compliance and legal factors, and its discovery reporting shows which of them are actually in use, by whom, and how much data is moving. From there, individual apps can be sanctioned or unsanctioned, and unsanctioned apps blocked at the endpoint through Defender for Endpoint.

Frontrow covers the full discovery setup at /insights/defender-cloud-apps-shadow-it-discovery-australia. The pattern seen in Australian tenants is consistent: the first discovery report is a shock, with several times more AI tools in use than IT expected, and a long tail of niche services nobody had heard of. That report is not a disciplinary instrument. It is the evidence base for the next two steps.

Policy and the sanctioned alternative

An AI acceptable-use policy does not need to be long, but it needs to exist before an incident, because a policy written after the fact protects nobody. The elements that earn their place:

  • Which tools are approved, which are banned, and who decides. Name the tools; a policy that says 'approved AI services' without a list is unenforceable.
  • What data may never leave the tenant: client-identifying information, personal information, credentials, financial records, anything under an NDA.
  • Accountability for output: the person who submits AI-assisted work owns its accuracy, mirroring the FWC's own verification requirement.
  • Disclosure expectations, both internal (when a manager asks) and external (where a client contract or a tribunal requires it).
  • Consequences, stated plainly, and a warning that misuse of communication tools, including AI-drafted campaigns, can itself be a conduct issue.

A ban alone fails, because staff reach for AI to solve real problems and a blocked website simply moves the pasting to a personal phone. The businesses that get ahead of this pair the policy with a sanctioned alternative: Microsoft 365 Copilot inside the tenant, where enterprise data protection applies, prompts and responses stay within the Microsoft 365 service boundary, and nothing is used to train foundation models. Frontrow's assessment of those protections is at /insights/is-microsoft-365-copilot-safe-company-data. Give people a tool that is allowed to see work data, and the incentive to smuggle work data into tools that are not largely evaporates.

Respond: when an incident has already happened

When misuse surfaces, the order of operations matters more than speed. A workable sequence:

  1. 1Establish the facts before any conversation with the employee. Pull the Defender for Cloud Apps activity, the audit log, the message trail. Screenshots and hearsay are not a file.
  2. 2Assess what actually left the tenant. A marketing paragraph pasted into a chatbot and a client database are different incidents; classify the data before classifying the conduct.
  3. 3Check notification obligations. If personal information went to an external service, assess against the Notifiable Data Breaches scheme with the privacy officer or external adviser.
  4. 4Close the technical gap the same week: block the tool, or sanction a safe alternative, so the incident cannot quietly repeat while HR deliberates.
  5. 5Keep the conduct process procedurally clean: put concerns in writing, warn explicitly that the specific behaviour may lead to termination if it continues, and give a real opportunity to respond. The Fujifilm decision shows the Commission checks for exactly this.
  6. 6Involve HR and an employment lawyer before any disciplinary decision, and before responding to any Commission claim. The technical evidence an IT team preserves in step one is what makes their advice useful.

Common questions

Frequently asked

Can an Australian employee be dismissed for misusing AI at work?
The Fair Work Commission's March 2026 decision in Wibmer v Fujifilm Data Management Solutions upheld a dismissal in which an AI-drafted email campaign was central to the conduct, so yes, AI misuse can form part of a valid dismissal. The same decision shows process matters: the Commission noted the employer had not explicitly warned that the email conduct itself could ground termination. Any specific matter needs advice from an employment lawyer, not an IT provider.
How do we find out which AI tools staff are actually using?
For Microsoft 365 organisations, Microsoft Defender for Cloud Apps is the practical answer. Its cloud app catalogue includes a generative AI category with per-app risk scores, and its discovery reporting shows which AI services are in use across the business, by whom, and with how much traffic. Individual apps can then be sanctioned, unsanctioned or blocked through Defender for Endpoint.
What are the Fair Work Commission's new rules on AI-prepared claims?
From 20 October 2026, the FWC's guidance note on generative AI requires anyone using AI to prepare case documents to disclose when and how it was used, to check the document is correct and relevant, and, for witness statements and declarations, to confirm the content reflects the person's own knowledge and words. The Commission's application and response forms are being updated to match.
Should we just block ChatGPT and similar tools entirely?
A blanket block without an alternative usually moves the problem to personal devices, where the business has no visibility at all. The combination that holds up is a clear acceptable-use policy, blocking of high-risk unsanctioned tools, and a sanctioned tenant-bound alternative such as Microsoft 365 Copilot, so staff have an approved way to use AI on work data.
An employee has pasted confidential data into a public AI tool. What first?
Preserve the evidence and establish what data actually left: pull the audit trail and Defender for Cloud Apps activity before speaking with anyone. Then assess the data class, because personal information may trigger an assessment under the Notifiable Data Breaches scheme. Close the technical gap so the leak cannot repeat, and bring HR and legal in before any disciplinary step.
Does an AI acceptable-use policy need to name specific tools?
Yes. A policy that refers to approved AI services without listing them is very hard to enforce, because nobody can say with confidence which side of the line a given tool sits on. Name the approved tools, name the banned categories, state who can change the list, and review it quarterly, since the discovery report changes faster than most policies do.

The matched next step

Find out where your own tenant would have failed

Most incidents start with a control Frontrow checks in week one: MFA coverage, legacy authentication, admin sprawl, unpatched servers. A security baseline review scores your Microsoft 365 tenant against the Essential Eight and hands you a prioritised fix list — whether or not Frontrow does the fixing.

Want Frontrow to run this with your team?

A 30-minute call with a senior consultant. No deck. Frontrow walks through your tenant, your priorities and the next sensible move.