ResearchAI data governance crisis
More than 3 million Australian workers are feeding sensitive data into AI tools at companies where 40% have no governance framework whatsoever
AI has become the fastest technology uptake in a generation, and safeguards have not kept pace, leaving millions of Australians’ personal and financial data exposed with minimal organisational oversight.
Key findings
- 3 million+ Australian workers regularly enter sensitive or confidential information into AI tools
- 40% of Australian businesses have no formal policy governing AI tool use
- 55% of executives, 49% of managers and 36% of employees admit to inputting sensitive data into AI
- 9 in 10 Australian employees now use AI for work, with nearly three-quarters using it weekly
- Formal AI policies exist at only 41% of businesses, and nearly half of workers at those companies are not fully compliant
- 30% of AI users are inputting customer or client data; 14% are entering personally identifiable information
- 8 in 10 executives flag AI data exposure as a risk, yet more than 1 in 5 don’t understand that consumer AI tools store and train on their inputs
- Adoption rate of AI in workplaces represents the fastest technology uptake in a generation
Why this matters
Australian organisations are experiencing a governance crisis at scale. The speed of AI adoption has fundamentally outpaced the development of safeguards, creating systemic exposure for millions of Australians whose personal and financial data now sits on overseas servers with minimal organisational oversight.
This is not a technical problem but an organisational one: even where policies exist, compliance is fractured, and decision-makers at the highest levels lack baseline understanding of data handling implications. Without urgent intervention, businesses risk substantial Privacy Act violations whilst their customers bear the actual cost of exposure.