Cybersecurity's Next Challenge: Knowing What to Trust
Mon, 5th Oct 2026 (Today)
It is clear that keeping hackers out (confidentiality) and systems up (availability) is no longer enough. There's a critical third pillar: Integrity. Organisations must be able to trust the data, the intelligence generated and the automated decisions that increasingly power their operations.
As autonomous AI agents interact across complex systems, the core security challenge expands from protecting raw data to ensuring the integrity of automated outputs, their actions and, consequently, the business outcomes. Ungoverned agents pose massive risks that can impact beyond the organisation itself.
That risk is already real. In June, an OpenAI agent gained unauthorised autonomous access to public and non-public files on an Australian Government Medicare portal while attempting a legitimate task. The incident shows that AI systems can behave unexpectedly when pursuing objectives, particularly when they encounter constraints not anticipated in their design. Organisations must govern both what an AI system can access and what it can do, and be able to revoke access when needed.
This is unfolding against a difficult backdrop. Australia has recorded its highest number of data breach notifications since mandatory reporting began in 2018, while cybercrime is estimated to cost the economy A$25 billion annually. Meanwhile, Gartner forecasts that pre-emptive, AI-driven security will account for half of cybersecurity spending by 2030.
As a result, AI and cyber risk can no longer be treated separately. To build resilience, security, governance, and AI strategy must function as a unified framework - grounded in complete visibility over where data resides, what AI agents can access, and who remains ultimately accountable.
Sovereignty is about more than where your data lives
While sovereign AI is often framed around data residency, it is fundamentally about maintaining complete and independent operational control and visibility. Beyond knowing where data resides, organisations must track its lineage, movement, access and manipulation permissions across users and AI agents, and decision-making logic. Data location is essential, but it is only one component of end-to-end governance across the AI lifecycle in addressing the three pillars of confidentiality, availability and integrity.
What we see at Cloudera is a shift in how organisations think about data and AI architecture. Many are choosing to bring AI to their data rather than move data to an AI service that they have limited or no control. Across on-premises, sovereign-cloud and multi-cloud environments, this approach allows them to apply common policies without creating unnecessary copies or moving sensitive information beyond approved boundaries.
You can't secure what you can't see
As Australia advances its 2023–2030 Cyber Security Strategy to uplift its cyber resilience and maturity, organisations need accountability for who or what controls critical operations. A zero-trust approach should embed security and governance from the outset. Fine-grained, attribute-based controls can limit each person or AI agent to the information required for a task, with continuous checks ensuring permissions remain appropriate.
Critical data elements can also be tagged with policies that remain attached as data moves between systems or is shared for analysis. In healthcare, for example, a clinician may need a full record while a researcher needs only selected, unidentified information. Persistent policies can enforce that distinction without unnecessarily exposing sensitive data.
Trust is becoming the new measure of resilience
For technology leaders, the real test is whether trust can be demonstrated.
Can you trace where your data came from, identify which models and agents used it, explain how an output was produced and intervene before an automated action causes harm? Can you enforce the same controls across on-premises infrastructure, cloud platforms and third-party apps that talk to your data via numerous APIs? If not, governance remains a policy ambition rather than an operational capability, and the integrity of your data and AI outputs may be compromised.
Modern data architecture must comply with a solid cybersecurity strategy. In the AI era, resilience will depend on moving quickly while retaining visibility, accountability and control from data to decision to action. Trust is no longer an abstract value; it may be the most important security control of all.