A new global survey from SAP, conducted by Oxford Economics across more than 2,600 business leaders in 13 countries, has found that Australian organisations are adopting artificial intelligence faster than they are building the governance frameworks needed to manage it safely. Only 22% of Australian organisations rated themselves mostly or fully ready in AI governance, well below the 33% global average. For anyone responsible for facilities, security systems, or building management networks where AI is increasingly embedded in analytics, monitoring, and automation, the finding is a useful prompt to check whether internal governance is keeping pace with deployment.
Adoption is outrunning oversight
According to the survey, AI now supports 29% of tasks in the average Australian business, up from 25% a year ago, with leaders expecting that figure to climb to 48% within two years. Spending is rising in step, from an estimated AUD $27.5 million last year to AUD $35.5 million this year, though still trailing the global average of AUD $40.4 million.
The governance gap is where the findings get more concerning for operational environments. Some 42% of respondents said they were deploying AI agents faster than they could standardise and govern them, and 54% said staff were increasingly accepting AI outputs without enough scrutiny. Perhaps most notably, 43% of Australian organisations reported no human-in-the-loop process for agentic AI workflows, and 49% said AI agents had already taken incorrect actions during pilots or live deployment, typically resulting in rework and delays.
Leadership structures around AI also appear underdeveloped. Fewer than half of surveyed organisations had a dedicated AI leader, only 33% had leadership KPIs tied to AI outcomes, and just 41% offered staff training on AI use and risk. Angela Colantuono, president and managing director of SAP Australia and New Zealand, described the country’s position as “an incomplete report card” and pointed to a wave of new AI-related regulatory obligations landing before the end of the year.
Data quality and sovereignty constraints
Data readiness is a persistent constraint. While 64% of Australian leaders identified integrated data systems as the biggest enabler of AI readiness, and 51% pointed to data quality, nearly three-quarters of organisations reported ongoing problems with poor data quality. The proportion of businesses considering themselves data-ready for AI has actually fallen since last year.
Sovereign AI requirements are also shaping deployment decisions, with 99% of organisations reporting some form of sovereign AI framework or requirement in place, and 76% citing data residency constraints that limit which models they can use. This is directly relevant to any organisation running video management systems, access control platforms, or BMS analytics with AI-assisted features hosted offshore or in the cloud — data residency and sovereignty obligations are becoming a live procurement consideration, not a theoretical one.
Workforce readiness lags too: more than four in five businesses are not convinced their upskilling efforts are keeping pace with AI’s evolution, and 77% reported at least occasional “shadow AI” use — staff adopting tools without sanction or oversight.
What this means for security and building operations teams
This survey is enterprise-wide in scope, but the pattern it describes is one Mallen sees echoed in physical security and BMS environments specifically: AI-assisted video analytics, automated alarm triage, and predictive maintenance features are being switched on in NVRs, VMS platforms, and access control systems well ahead of any documented governance around who reviews flagged events, how false positives are handled, or where footage and metadata are actually processed and stored.
Facilities managers and IT managers evaluating AI-enabled security platforms should be asking vendors pointed questions about data residency, human review requirements for automated actions (such as auto-locking doors or dispatching alerts), and what happens when an AI agent gets something wrong. The finding that almost half of Australian organisations have seen AI agents take incorrect actions during deployment is a reminder that “smart” features in access control or CCTV systems still need a documented escalation path and a person accountable for outcomes — not just a dashboard.
Professor Toby Walsh of UNSW made a point worth repeating here: governance isn’t about slowing innovation down, it’s what lets people trust the system enough to actually rely on it. For a strata committee or club board approving a new AI-assisted CCTV or access control deployment, that trust has to be built into the procurement and handover process, not bolted on afterwards.
Organisations reviewing their own AI governance posture — including how AI features in security and BMS platforms are documented, monitored and reviewed — may find it useful to start with a baseline review of what’s currently deployed and how it’s configured. A site audit that captures device registers, network topology, and system configurations is a practical starting point before layering governance policy on top.
Original source: https://securitybrief.com.au/story/australia-lags-on-ai-governance-as-adoption-races-ahead