Nearly every Australian company using AI has had one break the rules

Cynthia Lee of Delinea says Australian firms have AI policies on paper but no way to check if anyone's actually following them.

Yajush Gupta
Yajush Gupta
News · 1 Oct 2026 · 2 min read
Above Nearly every Australian company using AI has had one break the rules. Dynamic Business

You might think your small business is off the hook when it comes to worrying about AI gone wrong, but some fresh research from Delinea could make you rethink that. It's not that the study specifically focuses on small businesses, but rather that it sheds light on some surprising findings about companies that are supposedly well-prepared.

Delinea, an identity security platform, surveyed more than 2,250 IT and security leaders and 2,250 non-IT employees at organisations of 500 or more staff, across Australia, the UK, US, Germany, Singapore, the UAE, France and India. The headline finding: 99.6% of Australian IT leaders said an AI tool or agent accessed sensitive data beyond what it was supposed to touch, at some point in the past year. Almost all of them. And only 12% said they could detect a scope violation as it happened, below the global average of 19%.

Policy everywhere, enforcement nowhere

The key takeaway here is that even if your business isn't a large corporation, this still applies. What we found is that companies have rules in place - all the Australian organisations surveyed said they have formal guidelines on AI access. The issue isn't having the policies written down, it's that only about a third of them actually enforce those policies in real-time, which is the biggest gap of any country in the study.

"Australia leads in AI policy, but a policy on paper doesn't tell you who's accountable when something goes wrong," said Cynthia Lee, APAC Vice President at Delinea. "Our research echoes what I hear and see in this region: companies have AI policies in place, but are not able to see whether they are being followed or have mechanisms to enforce them."

That gap between having a rule and enforcing it shows up throughout the data. Almost half of respondents, 48%, said they had felt pressured to use AI on sensitive or confidential information even when they were unsure it was permitted. And 64% admitted to bypassing the required approval process for using AI at some point, often because a deadline outpaced the sign-off chain.

Accountability holds up no better. Nearly all Australian organisations, 99.6%, require a named individual's approval for at least some sensitive AI use. But when asked whether they could always trace a sensitive access event back to that named approver, only 42% of Australian IT leaders said yes. The rule exists. Following the paper trail when something goes wrong is a separate matter.

The weakest points cluster around the systems developers lean on most heavily. Across six major environments, Kubernetes, CI/CD pipelines and on-premises file systems came out as the shakiest for Australian organisations, and even the stronger areas, cloud data stores and SaaS applications, still showed gaps. When an agent does step outside its scope, detection lags badly: 67% of Australian organisations take a full day or longer to catch it, slower than the global average.

None of this research was about small business. It was about large, well-resourced organisations with dedicated security teams and every formal policy checkbox ticked. And they are still missing scope violations for a day or more at a time. For a smaller operation without a security team, and often without a formal AI policy at all, the odds that anyone notices an AI tool overstepping are realistically lower, not higher. The lesson isn't that AI itself is dangerous. It's that a policy sitting in a folder achieves nothing on its own unless someone is actually checking what the AI is doing, not just what it's technically allowed to do.

Delinea's own pitch is a system that authorises AI access continuously at the point of use rather than only at login, giving companies a record of who approved what and why. Whatever tool a business ends up using, the underlying point holds regardless of vendor: if AI has been rolled out and nobody has checked who can access what or whether anyone is watching, that's worth fixing this week, not next quarter.

Tags
YG
Yajush Gupta
Yajush Gupta reports for Dynamic Business — covering the founders, money and policy shaping Australia's economy.
From the floor
Closer to this story than we are?
If you're building in this space — or watching it reshape your market — pitch us. We edit it; you get the byline.
More from the desk

Keep reading.

News ◆

What the latest inflation figures mean for the small business squeeze

Employers are dealing with higher borrowing costs and fast rising wages at the same time. Employment Hero's James Keene says that combination puts pressure on SMEs.

Yajush Gupta · 2 min
News ◆

Rates just went up again. Here's what it means for your hiring plans

The Reserve Bank has hiked the cash rate for the fourth time this year, with all nine members of the Monetary Policy Board agreeing to a 25 basis point increase to 4.60 per cent. This latest rise t…

Yajush Gupta · 2 min
Expert ◆

Why 'what can we automate' is the wrong question for retailers

The real test of retail tech isn't what it automates, it's what staff do with the time it returns.

Paul Kyriakos · 2 min
0 people like this

Comments

Loading comments…