Responsible AI

OneTrust report finds Australian AI governance lagging as adoption accelerates

OneTrust's 2026 AI-Ready Governance Report finds 21% of Australian organisations describe their AI governance as reactive and fragmented, the highest rate among surveyed countries.

OneTrust report finds Australian AI governance lagging as adoption accelerates

Key takeaways

  • OneTrust's 2026 AI-Ready Governance Report found 21% of Australian organisations describe their AI governance as reactive and fragmented, the highest proportion among all countries surveyed.
  • 86% of respondents globally reported at least one AI-related incident in the past year, yet most organisations responded by increasing training rather than slowing deployment.
  • Australian organisations are spending an average of 25% more time managing AI-related risk than 12 months ago, while 41% report employees have used unapproved AI tools due to slow approval processes.
  • 44% of Australian respondents said their organisations are encouraging AI agents even as governance controls remain incomplete.

What Happened

In-body image for: OneTrust report finds Australian AI governance lagging as adoption accelerates
Illustrative AI-generated image by Mindiam (Flux 1.1 Pro Ultra)

OneTrust published its 2026 AI-Ready Governance Report on 15 September 2026, drawing on a survey of 1,200 senior business decision-makers across eight countries: the United States, Canada, the United Kingdom, France, Germany, Spain, Australia and Singapore. The survey was conducted by Sapio Research on behalf of OneTrust.

The report's central finding for Australia is that AI adoption is outpacing the controls organisations have in place to manage it. Among Australian respondents, 21% described their AI governance as reactive and fragmented. OneTrust noted this was the highest result among all surveyed countries. A further 37% said their governance is defined but slow and manual.

The report also recorded a sharp rise in compliance workloads. Australian organisations surveyed said they are spending an average of 25% more time managing AI-related risk than they were 12 months ago.


Why It Matters

The findings point to a widening gap between the pace of AI deployment and the maturity of the controls organisations have in place to manage it. According to the report, 86% of respondents reported at least one AI-related incident in the past year. Incidents included sensitive data or IP exposure, unapproved employee AI use, misinformation and data loss. Among those, 28% experienced two or more incidents in which AI systems or agents took unapproved actions.

Despite the frequency of incidents, organisations were most likely to respond by increasing employee training (49%) and least likely to pause or slow AI deployment (27%), according to the report.

The report also identifies what OneTrust describes as "shadow AI" as a contributing factor. Globally, one-third (33%) of surveyed organisations reported employees used unapproved AI because approved tools or processes were not available quickly enough. In Australia, that figure was higher: 41% of Australian respondents reported the same behaviour. OneTrust said the results indicate that approval delays and governance friction can push AI use outside formal controls.


Key Details

The report covers several dimensions of AI governance maturity. On AI agents specifically, 44% of Australian respondents said their organisations encourage AI agent use while governance and controls are still developing. This is a separate concern from general AI adoption, as agents can take autonomous actions within systems, raising distinct accountability questions.

The survey covered senior business decision-makers, not technical staff alone, which means the governance gaps described reflect conditions at the leadership level, not only at the operational layer.

OneTrust framed the report's purpose as helping organisations manage AI "responsibly, with the right visibility, accountability and controls in place."


Background and Context

Australia does not yet have a standalone AI-specific regulatory framework equivalent to the European Union's AI Act, though the federal government has been consulting on mandatory guardrails for high-risk AI applications. The Office of the Australian Information Commissioner (OAIC) has issued guidance on how the Privacy Act 1988 applies to AI systems, particularly where personal information is involved. The Australian Competition and Consumer Commission (ACCC) has also flagged AI-related consumer protection concerns in its digital platform work.

Against that backdrop, the OneTrust findings arrive at a point when Australian regulators are still developing binding rules, meaning the governance gaps the report describes are largely self-regulated at present.


What Comes Next

The report does not prescribe a specific regulatory response. OneTrust said the findings are intended to inform how organisations approach AI governance maturity. The Australian government's AI safety work, including the Department of Industry, Science and Resources' consultation on mandatory guardrails, remains ongoing as of the report's publication date.

Whether the incident rates and governance gaps documented in the report will accelerate regulatory timelines in Australia is not addressed by the source material.

Sources & citations

  1. Australian Cyber Security Magazine: OneTrust research flags AI governance gaps as Australian adoption accelerates
  2. Security Brief Australia: AI accountability gap widens as organisations scale faster than governance
JUST THE WEEKLY ROUNDUP

One Friday email. The five things AU operators actually need to know.

Operator-tested, primary-source linked, citation-first. Written by an operator, not a marketing team. Or, for a personalised view first, take our 90-second quiz.

Unsubscribe anytime. No spam. See our privacy policy.