IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
Australian firms struggle to enforce AI data rules

Australian firms struggle to enforce AI data rules

Wed, 30th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Research published by Delinea found that 99.6% of Australian organisations surveyed reported an AI tool or agent accessing sensitive data beyond its intended scope in the past year, the highest rate among the markets covered.

The findings point to a gap between formal AI rules and day-to-day enforcement in Australian businesses. While every Australian organisation surveyed said it had a policy governing what data AI tools and agents can access, only 34% said they check that access against policy in real time.

Delinea's report drew on two global surveys of 2,254 IT and security leaders and 2,250 non-IT employees at organisations with 500 or more staff that use AI. The research covered Australia, the UK, the US, Germany, Singapore, the UAE, France and India.

Australia also trailed the global average on real-time detection when an AI agent moved outside its approved scope. Only 12% of Australian respondents said they could detect a scope violation as it happened, compared with 19% globally.

In many cases, detection took much longer. Some 67% of Australian organisations took a full day or more to identify a scope violation, above the global figure of 61%.

Approval gaps

The research also suggested many employees use AI outside formal approval channels. Delinea found that 64% of Australian respondents had bypassed the required approval process for using AI at some point.

Workplace pressure appeared to be a factor. Nearly half of Australian respondents, 48%, said they had felt pushed to use AI on sensitive or confidential data even when they were unsure whether it was permitted.

The report identified a further weakness in accountability. Although 99.6% of Australian organisations required approval from a named individual for at least some sensitive AI uses, only 42% of Australian IT leaders said they could always trace a sensitive AI access event back to a named human authoriser.

That leaves a significant gap between policy design and operational oversight. Organisations may have documented rules in place but still struggle to show who approved a given action and when approval was granted.

Weakest points

Enforcement was also uneven across technical environments. Globally, 47% of organisations lacked enforcement at the moment of action in at least two of the six major environments assessed in the study.

In Australia, the weakest areas were Kubernetes, CI/CD pipelines and on-premises file systems. Cloud data stores and SaaS applications performed better, though gaps remained even in those environments.

The study comes as businesses face closer scrutiny over how staff and software agents use AI systems with access to internal and sensitive information. It also follows broader concern about whether organisations can apply conventional security controls to AI tools that act with a degree of autonomy.

For employers, the data suggests the problem is not a lack of policy adoption. Rather, it is the difficulty of monitoring and enforcing those policies when AI tools are embedded in everyday workflows and employees are under pressure to move quickly.

Cynthia Lee, APAC Vice President at Delinea, said the Australian results reflected a broader problem around oversight and responsibility.

"Australia leads in AI policy, but a policy on paper doesn't tell you who's accountable when something goes wrong," Lee said.

"Our research echoes what I hear and see in this region: companies have AI policies in place, but are not able to see whether they are being followed or have mechanisms to enforce them," she said.