NAITEC Digital
← Back to News

Public Generative AI in Government: Build a Managed Path, Not a Shadow AI Problem

Government teams have spent several years debating whether staff should be allowed to use public generative-AI tools. The more useful question is now becoming: what does safe, managed access look like in ordinary work?

The Digital Transformation Agency's current agency guidance on public generative AI recommends a risk-based approach. It advises agencies to enable appropriate use of public tools for government information classified up to OFFICIAL, while prioritising security-assessed enterprise solutions for classified information.

That is not a blanket permission to paste government data into any chatbot. It is a move from a simple allow-or-block debate to a delivery problem: selecting approved services, matching access to roles and information, constraining risky actions, building staff capability, and preserving the records and oversight that government work requires.

Why a Blanket Ban Creates Its Own Risk

Public generative AI is no longer confined to a few well-known chat websites. It is appearing inside search, productivity software, development tools, meeting platforms and browser features. An agency can block one domain while staff encounter similar capabilities in many other places.

The DTA also makes a practical point: overly restrictive policies can drive shadow usage outside organisational oversight. Staff who believe a tool will save time may use personal accounts or unapproved services, leaving the agency with less visibility, weaker controls and no reliable way to learn what people are trying to achieve.

Managed access gives the organisation a better option. Staff receive approved pathways for appropriate tasks, while risky information and consequential uses are kept behind stronger controls. The agency can then monitor demand, improve training and move repeatable high-value work into assessed enterprise environments.

OFFICIAL Does Not Mean Unrestricted

The classification label is only one part of the decision. The Protective Security Policy Framework's Policy Advisory 001-2025 says OFFICIAL information can be used with generative-AI technologies only within existing PSPF responsibilities.

The accompanying provider and authorisation advice retains technology-approval requirements and requires suitable hosting or provider assurance, or a Foreign Ownership, Control or Influence risk assessment. An agency still needs to decide which product, account type and configuration are approved for which work.

Privacy creates another boundary. The Office of the Australian Information Commissioner says privacy obligations apply to personal information in both AI inputs and outputs. Its commercial AI guidance recommends, as a matter of best practice, not entering personal information — particularly sensitive information — into publicly available generative-AI tools.

A useful access decision therefore considers at least four things together:

  • the information: classification, personal information, sensitivity, legal restrictions and business value;
  • the service: provider assurance, account type, data handling, retention, training use and administrative controls;
  • the task: drafting, summarising, coding, research, analysis or a decision that affects a person;
  • the consequence: how an error, disclosure or unrecorded action could affect the public, the agency or another system.

That is why a one-page list of approved tools is not enough. The same product can be suitable for generic brainstorming and unsuitable for a case file containing personal information.

Design Three Practical Access Lanes

Most agencies can make policy easier to use by turning it into a small number of recognisable work lanes.

  • Public-tool lane: approved public services for low-risk tasks using information permitted by agency policy. Access is role-based, uploads may be restricted, and staff see clear reminders about prohibited information and mandatory review.
  • Enterprise-assistant lane: a security-assessed organisational service with managed identities, contractual data protections, central configuration, monitoring and supported integration with approved information repositories.
  • Integrated-system lane: AI embedded in a service, workflow or decision process. This needs use-case governance, testing, privacy and security assessment, logging, records design, change control, incident handling and accountable product ownership.

The lane should follow the work, not the enthusiasm of the user or the novelty of the model. If a task crosses a boundary — for example, a generic draft becomes a response based on a citizen's case — the work must move to an environment and process authorised for that information.

Put Controls at the Point of Use

Policies fail when staff must remember a long document at the exact moment they are trying to finish a task. The DTA recommends technical controls such as upload blockers, splash screens and data-loss-prevention tools. Used well, those controls turn abstract rules into visible, timely decisions.

A practical managed-access design can include:

  • single sign-on and role-based access rather than personal accounts;
  • a short pre-use notice naming permitted information and prohibited uses;
  • upload restrictions for public tools, with approved enterprise alternatives for document work;
  • data-loss-prevention rules for common sensitive patterns and repositories;
  • managed browser and application settings that reduce accidental use of embedded AI features;
  • human validation before AI-assisted content becomes advice, a decision, code, a publication or an official record;
  • monitoring that measures adoption and incidents without collecting unnecessary prompt content;
  • a clear path for reporting mistakes, suspected disclosure and unsafe output.

The aim is not to make every low-risk prompt feel like a security incident. It is to make the safe route the easiest route and place friction where the consequence justifies it.

Records Need to Be Designed In

AI-assisted work does not sit outside government recordkeeping. The National Archives of Australia's guidance on records created using AI applies existing records authorities according to the purpose, value and risk of the business activity.

Routine, low-value drafts may be transitory under an agency's approved normal administrative practice. Final business records and AI outputs that materially support a high-value or consequential decision may need to be retained. Depending on the risk and evidential value, the agency may also need prompts, inputs, source material and metadata explaining how the output was created.

This creates an important procurement and architecture question: can the chosen service export the evidence the agency may be required to keep? If a tool cannot preserve necessary context for a consequential workflow, the correct answer may be to restrict the use case rather than accept an accountability gap.

Train for Decisions, Not Prompt Tricks

Prompt-writing tips are useful, but they are not an operating model. Staff need enough AI literacy to recognise when a task changes risk category, when an output requires verification, and when a public tool is the wrong environment.

Scenario-based training works better than generic slogans. Give teams examples from their work: summarising a public report, drafting an internal brief, analysing a spreadsheet of contact details, generating code against a private repository, or preparing advice that will affect an entitlement. Ask which lane applies, what information can be used, what evidence must be checked and what record must be kept.

The DTA recommends building on existing security and privacy training, not creating an isolated AI compliance course. That is sensible. Generative AI changes the interface, but staff still need to apply enduring obligations around information handling, integrity, professional conduct, privacy and accountability.

A 30-Day Managed-Access Pilot

An agency does not need to settle every future AI question before it can learn safely. A bounded pilot can establish the operating pattern.

  1. Week 1 — map actual demand. Interview representative teams and identify the tasks already being attempted, the information involved and the friction created by current policy. Do not collect personal prompt histories to prove shadow use.
  2. Week 2 — define lanes and controls. Approve one low-risk public-tool lane and one managed enterprise lane. Configure identity, notices, upload rules, data-loss prevention, monitoring and a simple incident path.
  3. Week 3 — train with scenarios. Run role-specific exercises, require human validation and test whether staff can recognise when work must move to another lane.
  4. Week 4 — measure and decide. Compare useful tasks completed, avoided incidents, policy questions, review effort and unmet demand. Expand, revise or stop each use case based on evidence.

This complements our recent guide to moving AI from proof of concept to production. Stage gates decide whether a use case should advance; managed-access lanes decide where everyday work can happen safely while the organisation learns.

What This Means for GovCMS and Drupal Teams

Website and content teams are likely to encounter generative AI through drafting, summarisation, search, translation, accessibility support, code assistance and editorial automation. The safe boundary cannot rely on the final publishing approval alone.

Teams should define which content may leave GovCMS or Drupal, which environments may receive unpublished material, how personal information in forms or support requests is excluded, how sources and human edits are recorded, and which checks remain mandatory before publication. Integrated features also need ordinary software controls: least privilege, testable behaviour, accessible fallback, logging, change management and a way to disable the AI dependency.

Our article on governing agentic AI in government software delivery covers the stronger controls needed when a system can take actions. Public-tool access is usually less autonomous, but the same design principle applies: capability should never outrun authority, evidence or accountability.

Working with NAITEC Digital

NAITEC Digital helps Australian Government and business teams turn AI policy into a usable delivery system. We can map real workflows, design access lanes and data controls, assess enterprise integrations, build governed pilots, and connect AI-assisted work to testing, monitoring and records requirements.

We are a Newcastle, NSW software consultancy, a BuyICT registered supplier, and GovCMS/Drupal specialists on the Drupal Services Panel. Our capabilities span AI integration, automation and custom software delivery and government digital services, GovCMS and Drupal.

If your organisation is caught between an impractical ban and unmanaged adoption, talk to NAITEC Digital. We can help design a controlled path that people will actually use.

Frequently Asked Questions

Can Australian Government staff use public generative-AI tools with OFFICIAL information?

Current DTA guidance recommends enabling appropriate use for government information classified up to OFFICIAL, but access must follow the agency's risk profile, PSPF responsibilities, technology authorisation, approved-provider or FOCI assurance, privacy obligations and specific rules for the task and information.

Does an approved AI tool make every use case safe?

No. Approval of a service does not remove restrictions on personal information, sensitive material or consequential decisions. Agencies must assess the information, service configuration, task and potential impact together.

Should agencies block all public AI tools to prevent data leakage?

A blanket block may be appropriate for particular environments, but the DTA warns that overly restrictive policies can drive shadow use. A managed approach combines approved pathways, role-based access, upload controls, training, monitoring and stronger enterprise options.

Do AI prompts and outputs need to be retained as government records?

It depends on the business purpose, value and risk. Final records and outputs supporting high-value or consequential decisions may need to be kept, sometimes with prompts, inputs, sources and metadata. Low-value drafts may be managed under an agency's approved normal administrative practice.

Can NAITEC Digital help design managed AI access?

Yes. NAITEC Digital can assess workflows and information risks, design public and enterprise access lanes, implement technical controls, integrate approved systems and run a measurable pilot. Contact us to discuss your environment.

Design a managed AI access pilot →