Security News

Aussie Businesses Racing Ahead with AI While Governance Lags Behind

Key Takeaway SMBs should set clear, fast-to-approve AI usage policies now, rather than letting staff turn to unauthorised tools while formal governance catches up.

Australian businesses are adopting AI faster than they can govern it, according to OneTrust's 2026 AI-Ready Governance Report, based on a survey of 1,200 senior decisionmakers across eight countries including Australia. The report found that 37% of Australian respondents describe their AI governance as defined but slow and manual, while 21% call it reactive and fragmented, the highest rate among all countries surveyed.

This governance gap is placing real strain on businesses. Australian organisations reported spending 25% more time managing AI-related risk than a year ago, and 41% said employees had used unapproved AI tools because sanctioned options weren't available quickly enough. Meanwhile, 44% of organisations are encouraging the use of AI agents even as controls for them are still being developed.

The trend isn't unique to Australia. Globally, 87% of organisations encourage AI agent use but only 47% have clear governance and oversight in place, and 28% experienced multiple incidents where AI systems took unapproved actions. Despite 86% of respondents reporting at least one AI-related incident in the past year, including data exposure or unapproved use, most organisations responded with more employee training rather than slowing down AI deployment.

AI governance shadow AI risk management
Putting a number on risk like this? How to run an ISO 31000 risk assessment ->

Summarised by CISO AI from Australian Cyber Security Magazine. We link back to every original so you can read it yourself.