OneTrust research flags AI governance gaps as Australian adoption accelerates
OneTrust has released its 2026 AI-Ready Governance Report, reporting that Australian organisations are moving beyond AI experimentation into broader adoption, while governance and risk controls struggle to keep pace.
The report, based on a survey of 1,200 senior business decisionmakers across the United States, Canada, the United Kingdom, France, Germany, Spain, Australia and Singapore, was conducted by Sapio Research on behalf of OneTrust. It points to fragmented oversight and rising AI risk management workloads, with incidents doing little to slow enterprise deployment.
In Australia, the report says visibility and governance remain key constraints. According to the findings, 37% of Australian respondents said their AI governance is defined but slow and manual, while 21% described it as reactive and fragmented, which OneTrust said was the highest result among surveyed countries.
The report also links AI adoption to operational pressure on risk and compliance functions. Australian organisations surveyed said they are spending an average of 25% more time managing AI-related risk than 12 months ago.
It also highlights “shadow AI” concerns, with 41% of Australian respondents reporting employees used unapproved AI tools in the past year because approved tools or processes were not available quickly enough.
Use of AI agents is also increasing, with 44% of Australian respondents saying their organisations encourage AI agents while governance and controls are still developing.
Blair Hasforth, Country Manager ANZ at OneTrust, said Australian businesses were now focused on scaling AI “responsibly, with the right visibility, accountability and controls in place.”
Globally, OneTrust reported that 87% of surveyed organisations encourage AI agent use, but 47% said they have clear governance, oversight and controls in place. The report also said 28% experienced two or more incidents in the past year in which AI systems or agents took unapproved actions.
The report found AI-related incidents were widespread, with 86% of respondents reporting at least one incident measured in the survey in the past year, including sensitive data or IP exposure, unapproved employee AI use, misinformation or data loss. In response, respondents were most likely to increase employee training (49%) and least likely to pause or slow AI deployment (27%).
OneTrust said the results indicate that approval delays and governance friction can push AI use outside formal controls, with one-third (33%) of surveyed organisations globally reporting employees used unapproved AI because approved tools or processes were not available quickly enough.
You can read the full report here.
