A recent Delinea study found 99.6% of Australian organizations reported an AI tool or agent accessing sensitive data beyond its intended scope. That figure is the highest rate among all surveyed markets. Every Australian firm claimed to have a policy governing AI data access, yet only 34% verify that access against policy in real time.
Violations Go Undetected for Days
Australian firms also lag globally in catching these violations as they happen. Only 12% of Australian respondents could detect a scope violation in the moment, compared to 19% worldwide. Most incidents sit unnoticed far longer than that. A full 67% of Australian organizations took a day or more to identify a violation, above the global average of 61%.
Employees are also routinely working around official channels. Delinea’s research showed 64% of Australian respondents bypassed required approval for AI use, and 48% said workplace pressure pushed them to use AI on sensitive data without clear permission. That points to a systemic problem rather than a handful of careless employees.
Approval Exists, but Nobody Can Trace It
Accountability breaks down even where approval processes exist on paper. While 99.6% of Australian organizations mandate approval from a named individual for sensitive AI uses, only 42% of IT leaders could actually trace sensitive AI access back to a human authorizer. That gap makes it nearly impossible to assign responsibility once something goes wrong.
Enforcement weaknesses cluster in specific technical environments. Globally, 47% of organizations lacked enforcement at the moment of action in at least two major areas. In Australia, Kubernetes, CI/CD pipelines, and on-premises file systems were the weakest points, while cloud data stores and SaaS applications performed better, though still imperfectly.
Writing a Policy Isn’t the Same as Running One
The core problem isn’t a lack of policy adoption. It’s the difficulty of monitoring and enforcing policies once AI tools are embedded in everyday workflows and employees are under pressure to move fast. Traditional security controls were not built for increasingly autonomous AI agents, and that mismatch is showing.
- 99.6% of firms have a policy, but only 34% verify access in real time
- 99.6% require named approval, but only 42% can trace access back to that person
- 67% take a day or more to catch a violation
Cynthia Lee, APAC Vice President at Delinea, noted Australia excels in AI policy creation. She added that a policy on paper doesn’t tell you who’s accountable when something goes wrong.
That line captures the research well. Australia isn’t short on rules. It’s short on the ability to know whether anyone followed them.
Hashlytics Take
The 99.6% figure is the headline, but the 34% figure is the actual story. Almost every firm in this survey has an AI data policy, which makes the policy itself close to meaningless as a signal of security. What separates a well-governed organization from a vulnerable one is whether it can verify access in the moment and trace it back to a person after the fact, and on both counts, most Australian firms are failing. Writing a policy is the easy part. The harder question these numbers raise is whether Australian IT teams have the tooling to enforce anything they’ve written down, and right now the answer looks like no.
Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates



