Western Health’s response to shadow AI is a useful warning for Microsoft 365 administrators and healthcare IT teams: governing a product name such as Microsoft Copilot is not enough. The Melbourne health service is separating the tool from the work performed with it, and says every clinical deployment should be handled as an innovation with a defined scope, monitoring plan and endpoint.

At a HIMSS26 APAC session, as reported by Healthcare IT News, Western Health Digital Health divisional director Lily Liu said nearly four in 10 of the organisation’s 13,000 staff use AI. About 800 employees were found using unapproved AI, while others had access to tools they were not authorised to use. The scale matters less as a precise prevalence statistic—no second outlet has independently reported Western Health’s internal count—than as evidence that an “approved tools only” policy does not describe how staff actually work once generative AI becomes readily available.

Western Health’s public material reveals one small but telling discrepancy: its organisation chart and annual reports identify the divisional director of Digital Health as Lily Lui, while Healthcare IT News spells the speaker’s surname Liu. The title and employer align, but the health service and conference organisers should clarify the record. In an AI-governance conversation centred on traceability and assurance, correct ownership details are hardly cosmetic.

The bigger point stands: an AI assistant is a delivery mechanism. Risk arrives through the data, workflow, recipients and decisions connected to it.

A healthcare analyst monitors interconnected clinical dashboards beside a hospital ward.Copilot Is a Tool; Discharge Documentation Is a Use Case​

Lui’s distinction at HIMSS is the most operationally useful part of Western Health’s approach. Microsoft Copilot, she said, is an AI tool. Using it to draft a memo or an internal email is a non-clinical use case; using it to draft a discharge summary makes it a clinical use case. Those two uses can involve the same model interface and the same employee account, but they should not receive identical governance treatment.

That is a corrective to a common enterprise rollout failure. IT departments often assess a platform during procurement, settle its identity, access and data-residency settings, publish a short acceptable-use policy, and treat subsequent work as adoption. In a clinical environment, that leaves the most consequential question unanswered: what is the model being allowed to influence?

A discharge summary can become part of a patient’s record, affect clinical handover and shape follow-up care. A hallucinated, omitted or misattributed detail has a different consequence from a poorly drafted internal memo. The appropriate controls therefore extend beyond whether the organisation’s Copilot tenant is configured securely. They include who reviews output, whether the source record remains visible, whether generated text is labelled or auditable, when a clinician must reject it, and how the organisation detects a workflow change after a vendor model update.

Victoria’s Department of Health has moved in the same direction. Its AI guidance for Victorian public health services, updated in June and July 2026, specifies risk-based governance models, responsibilities and escalation paths, and a separate advisory for ambient AI scribes. The department also says metropolitan and regional health services use new-technology committees to oversee introductions of technology and clinical-practice changes. That makes Western Health’s framework less an isolated experiment than an early practical application of the direction Victorian health services are being asked to take.

For Windows and Microsoft 365 administrators, this means the inventory cannot stop at “Copilot enabled” or “ChatGPT blocked.” The workable inventory unit is a use case tied to an owner, data classification and workflow. A staff member prompting an approved enterprise AI service with internal policy text, patient information, source code or operational data may create four entirely different assurance cases.


Shadow AI Is Both a Security Signal and a Demand Signal​

Western Health’s report of unauthorised AI use should not be read solely as employee misconduct. It is also evidence of unmet demand. Staff use outside tools when sanctioned systems are unavailable, too slow, poorly integrated, or unable to perform the task that makes their day easier. A blanket prohibition may reduce visible use briefly, but it can force the activity into personal accounts, unmanaged browsers, copied data and private devices—precisely where audit and retention controls disappear.

Lui’s public HIMSS comments, echoed in a post about the session, frame governance as a way to enable responsible use rather than stop AI outright. That is an important management choice. Security teams need the ability to block high-risk services and prevent protected data from leaving approved channels. They also need a credible path for employees to request a permitted alternative or have a specific task assessed quickly.

Western Health has said it uses AI for documentation, translation, email and report drafting, code verification, internal reporting analysis, HR chatbots and support for staff using its electronic medical record system. Those are not one implementation. They span language assistance, knowledge retrieval, software engineering, staff support and potentially clinical documentation. Treating them as a single “AI program” risks over-controlling low-risk work while under-specifying high-risk clinical work.

The Australian Government’s Digital Transformation Agency has reached a similar conclusion in its AI assurance work. Its updated AI impact-assessment tool requires agencies to assess AI use cases, beginning with the potential for material influence over decisions that could cause more than insignificant harm. The tool then examines fairness, reliability and safety, privacy and security, transparency, accountability, human-centred values, and ongoing review. Agencies must implement the assessment requirement for in-scope use cases by December 15, 2026.

The DTA’s pilot findings are useful context for Western Health’s five-step assurance process. Participating agencies reported that assessment could uncover risks their existing processes had missed, yet they also said risk assessment and legal review were difficult. The lesson is that governance cannot be a one-page declaration signed at kickoff. It must be structured enough to expose blind spots, but proportionate enough that a team does not wait months to approve routine internal drafting assistance.

Treating Implementation as Innovation Changes the Exit Criteria​

“Treat every AI implementation as an innovation” can sound like conference-stage language. In a hospital, it should translate into a stricter operating model than ordinary software deployment.

Innovation work begins with a hypothesis: which burden, delay, error rate or service problem is the system meant to improve? It defines the trial population and setting, measures the baseline, identifies failure conditions and names the human accountable for intervening. It also has an endpoint. Lui’s advice to time-box projects is significant because AI pilots can otherwise become permanent informal services, still labelled “experimental” long after staff have incorporated them into routine care.

Western Health already has precedent for this approach. Its 2024 announcement of an AI-driven length-of-stay prediction initiative described development, clinician co-design, testing and eventual handover to operational departments. The health service said then that the project would be supported by recently endorsed AI guidelines. That does not independently validate the new five-step process described at HIMSS, but it shows the organisation was already framing AI as a governed clinical change rather than a standalone technology purchase.

The necessary exit criteria should be explicit:

  • The implementation should identify the decision or task the AI may support, and state what it is prohibited from doing.
  • The project should define measurable benefits and harms before deployment, rather than relying on user enthusiasm after the fact.
  • The operational owner should know how to suspend the use case if output quality, privacy controls or clinical workflow conditions change.
  • The organisation should record which model, configuration, connectors and knowledge sources were validated, so a vendor update does not silently invalidate the original assurance decision.
  • The system should move into business-as-usual only after an accountable team accepts ongoing monitoring, review and incident handling.

This is where the distinction between model upgrades and workflow monitoring becomes concrete. A vendor may regard a model refresh as an ordinary service improvement. A health service must decide whether it changes accuracy, language performance, guardrails, retention, data flows, integration behaviour or the meaning of output in a clinical process. A model version change is not automatically a clinical-practice change—but it is an event that needs a defined triage path to determine whether reassessment is required.


An Outpatient AI Scribe Will Test the Framework​

Western Health plans to deploy an AI scribe across outpatient services in coming months, according to Healthcare IT News. That is the deployment most likely to test whether the health service’s stated philosophy works under real operational pressure.

Ambient scribes promise to remove documentation work by turning consultations into draft notes. They also create concentrated risk: sensitive audio capture, patient consent and notice, transcription accuracy, speaker attribution, record integrity, clinician review, access to the resulting note and the possibility that staff begin to trust a fluent draft more than the underlying encounter. Victoria’s dedicated ambient-scribe advisory acknowledges those concerns by specifically highlighting privacy, accuracy and clinical safety.

Western Health has not publicly identified the scribe vendor, rollout dates, outpatient specialties, integration method, consent process, success measures or whether clinicians will be required to verify every generated note before it enters the electronic medical record. Those omissions are normal at an early announcement stage, but they are the details staff, patients and peer health services will need before judging the rollout.

The health service’s stated approach gives it the right framework for that work: assess the implementation, not merely the product; separate clinical and non-clinical use; monitor the live workflow; and revise governance instead of filing it away. For enterprise administrators, the parallel is clear. The durable control is not a list of allowed AI brands. It is a living register of approved work, accountable owners, permitted data and the conditions under which each AI-assisted workflow must be stopped.