For the last two years, most workplace AI conversations have been about adoption: which licence, which pilot group, which use cases. In 2026 a second conversation has arrived, and it is landing on employers' desks uninvited. Employees are misusing AI at work, and the misuse now shows up in three distinct forms: confidential data pasted into public chatbots, AI-drafted internal grievance campaigns, and AI-generated claims arriving at the Fair Work Commission after a dismissal.
Each form needs a different control, and most Australian businesses have none of the three. This guide sets out what the misuse actually looks like, the new Fair Work Commission requirements that took shape this year, and a response checklist covering detection, policy, the sanctioned alternative, and what to do when an incident has already happened. One caveat up front: this is process and technical guidance from an IT provider, not legal advice. Where a matter is heading toward disciplinary action or a Commission claim, the employment lawyer comes in early, not last.
What AI misuse looks like in practice
The quiet form is data leakage. An employee pastes a client contract, a salary spreadsheet or a customer list into a free public chatbot to get a summary or a redraft. No malice, no exfiltration in the criminal sense, just confidential information leaving the company's control and landing with a consumer service whose terms the business never reviewed. Most organisations that go looking find far more of this than they expected.
The loud form played out in Wibmer v Fujifilm Data Management Solutions, decided by the Fair Work Commission in March 2026. A senior developer with an unblemished record since 2013 fell into a workplace grudge, and over three days sent at least 17 emails to managers and HR, many drafted with AI and citing the Fair Work Act, the Work Health and Safety Act, the Sex Discrimination Act and the Australian Human Rights Commission Act. Colleagues observed him consulting ChatGPT on his phone during meetings. The Commission upheld the dismissal, describing the employee as ungovernable and the AI-generated emails as disproportionate, and observed that the AI had given him a false sense of the strength of his position.
The third form arrives after employment ends. The Commission's president, Justice Adam Hatcher, told the Victorian Bar in February 2026 that the FWC's total workload had grown around 70 per cent in three years, with unfair dismissal claims up 41 per cent between 2022-23 and 2024-25, and attributed much of the growth to claims built with AI tools rather than to any rise in retrenchments. He noted the trade-off plainly: AI that tells workers their rights is a win for access to justice, but AI that invents facts to prop up a weak claim is not. For an employer, the practical effect is that a dismissal which once ended quietly is now more likely to come back as a polished, legislation-quoting application.
The FWC's new rules on AI-prepared claims
The Commission has responded. In August 2026 the FWC published a guidance note on the use of generative AI in Commission cases, applying from 20 October 2026. It sets three requirements for anyone using generative AI to prepare documents in a case: disclose when and how AI was used, check that the document is correct and relevant to the case, and, for witness statements and declarations, confirm the content is based on the person's own knowledge and words.
Two lessons for employers sit inside this. First, expect AI-assisted claims as the norm, not the exception, and brief whoever handles responses accordingly: invented authorities and confidently wrong facts are a known failure mode the Commission itself is now policing. Second, take the procedural-fairness lesson from the Fujifilm case. The Commission noted the employer had never explicitly warned the employee that the volume and tone of his emails could itself become a basis for termination. The misconduct outweighed that gap in the end, but a business that puts the warning in writing early keeps the gap from opening at all.
Detect: find the shadow AI first
None of the policy work matters if the business cannot see which AI tools staff already use. For organisations on Microsoft 365, Microsoft Defender for Cloud Apps does this discovery work: its cloud app catalogue has a dedicated generative AI category covering hundreds of applications, each with a risk score across security, compliance and legal factors, and its discovery reporting shows which of them are actually in use, by whom, and how much data is moving. From there, individual apps can be sanctioned or unsanctioned, and unsanctioned apps blocked at the endpoint through Defender for Endpoint.
Frontrow covers the full discovery setup at /insights/defender-cloud-apps-shadow-it-discovery-australia. The pattern seen in Australian tenants is consistent: the first discovery report is a shock, with several times more AI tools in use than IT expected, and a long tail of niche services nobody had heard of. That report is not a disciplinary instrument. It is the evidence base for the next two steps.
Policy and the sanctioned alternative
An AI acceptable-use policy does not need to be long, but it needs to exist before an incident, because a policy written after the fact protects nobody. The elements that earn their place:
- Which tools are approved, which are banned, and who decides. Name the tools; a policy that says 'approved AI services' without a list is unenforceable.
- What data may never leave the tenant: client-identifying information, personal information, credentials, financial records, anything under an NDA.
- Accountability for output: the person who submits AI-assisted work owns its accuracy, mirroring the FWC's own verification requirement.
- Disclosure expectations, both internal (when a manager asks) and external (where a client contract or a tribunal requires it).
- Consequences, stated plainly, and a warning that misuse of communication tools, including AI-drafted campaigns, can itself be a conduct issue.
A ban alone fails, because staff reach for AI to solve real problems and a blocked website simply moves the pasting to a personal phone. The businesses that get ahead of this pair the policy with a sanctioned alternative: Microsoft 365 Copilot inside the tenant, where enterprise data protection applies, prompts and responses stay within the Microsoft 365 service boundary, and nothing is used to train foundation models. Frontrow's assessment of those protections is at /insights/is-microsoft-365-copilot-safe-company-data. Give people a tool that is allowed to see work data, and the incentive to smuggle work data into tools that are not largely evaporates.
Respond: when an incident has already happened
When misuse surfaces, the order of operations matters more than speed. A workable sequence:
- 1Establish the facts before any conversation with the employee. Pull the Defender for Cloud Apps activity, the audit log, the message trail. Screenshots and hearsay are not a file.
- 2Assess what actually left the tenant. A marketing paragraph pasted into a chatbot and a client database are different incidents; classify the data before classifying the conduct.
- 3Check notification obligations. If personal information went to an external service, assess against the Notifiable Data Breaches scheme with the privacy officer or external adviser.
- 4Close the technical gap the same week: block the tool, or sanction a safe alternative, so the incident cannot quietly repeat while HR deliberates.
- 5Keep the conduct process procedurally clean: put concerns in writing, warn explicitly that the specific behaviour may lead to termination if it continues, and give a real opportunity to respond. The Fujifilm decision shows the Commission checks for exactly this.
- 6Involve HR and an employment lawyer before any disciplinary decision, and before responding to any Commission claim. The technical evidence an IT team preserves in step one is what makes their advice useful.