

OneTrust Research Finds Australian AI Adoption Outpacing Governance
Australian businesses are moving beyond artificial intelligence experiments and putting AI into everyday operations. However, new research suggests AI governance in Australia is struggling to keep pace.
OneTrust, the AI-Ready Governance Platform™, released its 2026 AI-Ready Governance Report on September 14. The research points to a widening gap between AI adoption and the controls designed to manage it.
In Australia, 44% of surveyed organisations encourage employees to use AI agents even though their governance and controls are still developing. Meanwhile, 41% reported employees using unapproved AI tools because approved options or processes were not available quickly enough.
For businesses racing to deploy AI, that creates a difficult problem. Slow governance does not necessarily stop AI adoption. Instead, it can push AI activity outside approved systems and beyond the visibility of security, privacy and governance teams.
AI Governance Australia Faces A Growing Visibility Problem
OneTrust found that Australian organisations face significant visibility and governance challenges as AI use expands.
Among Australian respondents, 37% said their AI governance processes were defined but remained slow and manual. A further 21% described their approach as reactive and fragmented. According to OneTrust, that was the highest percentage among all countries surveyed.
At the same time, Australian organisations said they now spend an average of 25% more time managing AI-related risk than they did 12 months ago.
Those figures suggest that AI governance in Australia is becoming an operational workload, not simply a compliance exercise.
The problem also becomes harder as AI spreads across an organisation. Businesses may have approved enterprise AI platforms while employees simultaneously use browser extensions, coding assistants, embedded AI features and public AI services.
As a result, knowing where AI is operating can become almost as important as governing the technology itself.
Shadow AI Grows When Governance Cannot Keep Up
One of the clearest findings involves shadow AI.
In Australia, 41% of surveyed organisations said employees had used unapproved AI tools because approved tools or processes were not available quickly enough during the previous 12 months.
That finding highlights an uncomfortable reality for enterprise security teams. Governance can create risk when organisations make legitimate AI use unnecessarily difficult.
Employees rarely stop needing to complete a task because an approval process is slow. Instead, some will find another tool.
Consequently, organisations can lose visibility over what information employees upload, which AI services process that information and where the resulting data may travel.
Shadow AI therefore creates more than an IT management problem. It can introduce privacy, security, intellectual property and regulatory risks.
AI Agents Are Moving Ahead Of AI Governance In Australia
AI agents add another layer of complexity.
OneTrust found that 44% of Australian surveyed organisations encourage AI agent use while acknowledging that governance and controls remain under development.
Traditional generative AI systems generally respond to prompts. AI agents can go further. Depending on their permissions, they can retrieve information, interact with applications, trigger workflows and take actions on behalf of users.
That distinction matters.
A poorly governed chatbot may produce a bad answer. A poorly governed agent may be able to act on one.
As businesses give AI systems greater access to corporate data and tools, identity, permissions, monitoring and accountability become increasingly important. Organisations therefore need to understand not only which AI systems employees use, but also what those systems can access and what actions they can take.
OneTrust Says AI Governance Must Start Before An Incident
Blair Hasforth, Country Manager ANZ at OneTrust, said Australian businesses have already moved beyond the initial debate over whether to adopt AI.
“Australian businesses have moved beyond asking whether they should adopt AI. The challenge now is making sure they can scale it responsibly, with the right visibility, accountability and controls in place.
“AI governance cannot be something businesses turn to after an incident, it needs to be built into how the technology is adopted and managed from the outset, giving organisations the confidence to innovate, while keeping pace with emerging risks.”
The comments reflect a broader shift in enterprise AI. The question is increasingly moving from whether organisations will adopt AI to whether they can see, control and secure what they have already deployed.
Global AI Governance Findings Show The Problem Is Bigger Than Australia
The global results suggest Australia is not alone.
Across the surveyed organisations, 87% encourage AI agent use. However, only 47% reported having clear governance, oversight and controls in place.
Furthermore, 28% experienced two or more incidents during the previous year in which AI systems or agents took unapproved actions.
AI-related incidents were even more widespread when OneTrust measured a broader range of problems.
Overall, 86% of respondents experienced at least one measured AI-related incident during the previous year. These incidents included sensitive data or intellectual property exposure, unapproved employee AI use, misinformation and data loss.
Yet organisations largely continued deploying AI.
Following incidents, 49% said they increased employee training. In contrast, only 27% paused or slowed AI deployment.
Shadow AI Is Also A Global Governance Challenge
The relationship between slow approvals and shadow AI also appeared globally.
One-third, or 33%, of surveyed organisations reported employees using unapproved AI because approved tools or processes were not available quickly enough.
That creates a difficult balancing act.
Governance that is too weak can expose an organisation to unnecessary risk. However, governance that becomes too slow or restrictive may encourage employees to bypass approved channels.
Effective AI governance in Australia and elsewhere therefore needs to do more than establish policies. It also needs to make secure AI tools practical enough that employees actually use them.
About The OneTrust 2026 AI-Ready Governance Report
The second annual AI-Ready Governance Report surveyed 1,200 senior business decision-makers across the United States, Canada, the United Kingdom, France, Germany, Spain, Australia and Singapore.
Sapio Research conducted the survey on behalf of OneTrust.
The research examines how organisations are governing AI systems already in use, including the challenges created by AI agents, shadow AI, fragmented oversight and rising AI risk-management workloads.
Download OneTrust’s 2026 AI-Ready Governance Report to Learn:
- Which AI-related incidents are keeping organisations up at night
- What’s creating friction as organisations scale AI
- How organisations are responding to AI-related incidents
- Where governance investment is headed next
About OneTrust
OneTrust, the AI-Ready Governance Platform™, enables innovation through the responsible use of data and AI. Trusted by thousands of companies, including over half of the Fortune 500, we help businesses govern well and move fast, turning responsible data use into a catalyst for growth. To learn more, follow OneTrust on LinkedIn or visit www.onetrust.com.
© 2026 OneTrust LLC. All rights reserved. OneTrust and the OneTrust logo are trademarks or registered trademarks of OneTrust LLC in the United States and other jurisdictions. All other brand and product names are trademarks or registered trademarks of their respective holders.
