Australian businesses have spent the past two years in a hurry to bolt artificial intelligence onto almost everything, from customer service and marketing copy to supply chains and financial reporting. The enthusiasm is real, and so is the spending. What has not kept pace, according to fresh research from enterprise software giant SAP, is the far less glamorous work of governing the technology once it is switched on.
The SAP research, reported this week by SMBtech, lands on a conclusion that will sound familiar to anyone who has sat in an Australian leadership meeting lately: organisations are adopting AI faster than they can govern it. The tools are going live, the productivity promises are being made, and the guardrails are being assembled after the fact, if at all.
The gap between switching on and signing off
The finding matters because governance is not a bureaucratic afterthought when it comes to AI. It is the difference between a system that quietly improves a process and one that leaks sensitive data, embeds bias into a hiring decision, or produces confident nonsense that a staff member then acts on. The faster a business scales AI across departments, the more of these failure points it creates, and the harder they become to see once dozens of tools and quiet vendor features are in play.
SAP sits at an interesting vantage point to make this argument. Its software runs the back office of a large share of Australia’s biggest companies, handling the financial, human resources and logistics systems that AI is now being layered onto. When a vendor of that scale says the governance is lagging, it is describing conditions inside its own customer base, not a distant abstraction. That gives the research weight, even as it is worth remembering that SAP also sells the platforms and controls it says organisations need.
The pattern the research describes is not unique to Australia, but it is arguably sharper here. Local adoption has been fuelled by a competitive fear of being left behind, by boards demanding an AI story, and by a wave of tools that require little more than a subscription to deploy. That combination makes it easy to say yes to a pilot and much harder to track what happens when the pilot becomes a permanent fixture that no one formally owns.
Two ways to read the warning
There are two honest ways to interpret a finding like this. The first is the optimistic reading favoured by many technology leaders: governance always trails innovation, and that is how it should be. On this view, the point of the early phase is to learn what AI can actually do inside a business, and heavy-handed rules imposed too soon would smother experiments that turn out to be valuable. Governance, the argument goes, can be retrofitted once an organisation understands which uses are worth keeping.
The second reading is more cautious, and it is the one governance and risk professionals tend to hold. They point out that retrofitting oversight onto AI that is already woven through core systems is genuinely difficult, and that the costs of getting it wrong are not evenly distributed. A marketing team using a chatbot to draft posts carries very different risk from an AI model influencing credit decisions, insurance pricing or clinical triage. Treating every deployment as a low-stakes experiment until proven otherwise is precisely how a serious incident slips through.
Both camps agree on one uncomfortable fact: most organisations cannot yet answer basic questions about their own AI. Which tools are in use, what data they touch, who approved them and who is accountable when they misfire are questions that many Australian businesses would struggle to answer with a straight face. That absence of a simple inventory is the quiet symptom the SAP research is pointing at.
Why this hits harder in Australia
For Australian organisations, the governance gap arrives at an awkward moment. The federal government has spent the past year signalling a shift towards firmer expectations around high-risk AI, building on the voluntary AI Safety Standard and the work of the National AI Centre, while stopping short of the comprehensive statute that Europe has passed. That leaves businesses in a grey zone where the rules are tightening but not yet fixed, and where a rush to deploy now could mean expensive rework later.
There is also a distinctly local set of pressures. Australia’s data sovereignty concerns, its comparatively strict privacy reforms and the Office of the Australian Information Commissioner’s growing interest in automated decision-making all raise the stakes for any company that has scaled AI without clear records of what it is doing. Regulated sectors such as banking, insurance and health carry the heaviest exposure, and they are also among the most aggressive adopters. The combination of high ambition and thin oversight is not a comfortable one for a board to explain if something goes wrong.
The skills question compounds it. Governance is not only a matter of policy documents; it needs people who understand both the technology and the risk, and that talent is scarce and expensive in Australia. A business can buy an AI tool in an afternoon. Building the capability to supervise it responsibly takes far longer, which is exactly why adoption and governance have drifted apart.
What comes next
The practical takeaway from the research is not that Australian organisations should slow down, and few of them will. It is that the governance work can no longer be treated as a later phase. That means the unglamorous basics: a live register of where AI is being used, clear ownership of each system, defined boundaries for high-risk applications, and a way to audit outputs rather than trusting them by default.
Expect this theme to sharpen through the rest of 2026. As more Australian companies move from pilots to production and as regulators firm up their expectations, the businesses that treated governance as part of the build, rather than a clean-up job, will be the ones spared the most painful surprises. SAP’s message, stripped of the vendor framing, is really a timing argument. The organisations racing ahead on AI are not wrong to move quickly. They are increasingly likely to be caught out if they cannot say, plainly, what their AI is doing and who is answerable for it.
Sources: SMBtech.



















































