Does business need a seatbelt or an airbag for AI?

Government #2
Sep 04 , 2026
| Greg Spencer

Does business need a seatbelt or an airbag for AI?

Treasury has put a number on the gap between using AI and using it seriously. Two-thirds of Australian businesses have adopted it, fewer than one in ten significantly. That gap is a governance problem wearing a technology costume.

Treasury has just put a number on something most of us already suspected. Two-thirds of Australian businesses report they have adopted AI in some form. Fewer than one in ten report adopting it significantly. The Treasurer's response was blunt: "We can't just sit around and hope the benefits of AI fall into our lap. We have to reach out and take them."

He is right to be impatient. This is the biggest productivity opportunity of our generation, and Treasury now rates AI as the first credible global growth accelerant in nearly two decades. But impatience alone will not close that gap, because the gap is not caused by a lack of enthusiasm.

Almost every executive team we speak to has people using AI. What they do not have is the confidence to let it near anything that matters , the client data, the regulated process, the decision that carries consequences. So it stays in the shallow end. A licence here, a pilot there, plenty of activity and very little productivity.

That is a governance problem wearing a technology costume.

Seatbelt or airbag?

Ask a board how it is managing AI risk and you will usually hear about an acceptable use policy, a legal review, and a plan for what to do if something goes wrong.

That is an airbag. It is passive, it sits in the steering column doing nothing, and it only earns its keep after the impact. It limits the damage of a crash you have already had.

To be clear, you want the airbag. Every organisation needs an incident response plan, a legal review, a way to contain the damage when something goes wrong. Cars carry both for a reason. The problem is when the airbag is the only control you have , because an airbag does nothing to prevent the crash.

A seatbelt is different. You engage it deliberately, before you move, every single time. It is a small piece of friction you accept at the start of the journey in exchange for being able to travel at speed.

Here is the part business leaders keep getting backwards: nobody drives slowly because they are wearing a seatbelt. The restraint is what makes the speed reasonable. Done properly, AI governance is not the handbrake on adoption , it is what lets you take your foot off the brake, because you finally know what happens if you hit something.

So what does clicking in actually look like? It is knowing which of your data is sensitive, where it is allowed to travel and which systems it must never enter. It is a defined set of approved uses, so your people know where the edges are without having to ask. It is verification of AI output before it reaches a client, a regulator or the accounts. It is clear thresholds for when a human with real authority steps in, and a named executive who owns the answer when something goes wrong. None of that is exotic. All of it has to be in place before you accelerate , not drafted afterwards in the incident review.

Faster than you can react

The reason the belt has to be on before you move is simple. You cannot brace for a crash. The impact arrives faster than human reaction time, which is exactly why the control has to be engaged in advance rather than applied in the moment.

AI now operates on those same terms. An agent can take a thousand actions in the time it takes a person to read one of them. Content is drafted, decisions are made and records are written faster than any individual can follow, let alone assess. "Human in the loop" stops being a control the moment the loop runs faster than the human in it, and quietly becomes a rubber stamp with an audit trail.

The technology itself moves at the same pace. Capability that did not exist last quarter is embedded in the tools your staff already have this quarter, usually without a procurement decision anywhere in sight. Boards meet monthly or quarterly. The ground shifts weekly. By the time a committee has formed a considered view, the thing it formed a view about has been superseded.

No organisation can out-deliberate that, and trying to is how businesses end up standing still. What you can do is build controls that hold regardless of which model sits behind them , durable decisions about data, disclosure, review and accountability that remain valid when the underlying technology changes again next month. That is the difference between a governance framework and a policy document.

The questions that stall boards

The questions are relentless, and most boards have not worked through them:

  • Your data. Where is it, where does it go when a model touches it, and what are the intellectual property, privacy and confidentiality implications when it gets there?
  • Your processes. Which ones actually need to change, which need compliance testing, and where does a human stay in the loop as a genuine control rather than a formality?
  • Your people. If AI writes the first draft, does the research and builds the model, how does a graduate ever learn to do those things? Treasury is already watching entry-level workers overseas for early signs of displacement. Your apprenticeship pipeline is a business risk, not an HR one.
  • Your costs. Tokens are cheap until they are not. Do you know what you are spending, who is spending it, and at what point a person is simply the cheaper option?
  • Your position. If your competitors get this right and you do not, how long before it shows up in your margin?

Underneath all of them sit the three questions every risk conversation reduces to: what can go wrong, how would we know, and what would we do about it?

In our experience it is the second one that catches organisations out. Most have some idea of what could go wrong. Very few have any way of detecting a bad AI output before a client, a regulator or an auditor does it for them.

A seatbelt is not a destination

Governance tells you how to travel safely. It does not tell you where to go, and this is where the other half of Australian business is going wrong.

Too many AI programs begin with the technology already in the room. We have the licences, now what should we do with them? That is a technology question and it produces technology answers. It is why so many pilots stall at the demonstration stage. They were never anchored to a commercial outcome, so there was nothing for them to graduate into.

The question that works is a duller one. Where does this business genuinely make and lose money? Which of those processes are constrained by how fast a person can read, write, check or decide? What would change if that constraint were removed, and what would it be worth if it were?

Start there and most of the technology choices make themselves. Start with the tool and you will spend a year proving things that were never worth doing.

Treasury's own explanation of the productivity gap says as much: "Realising productivity gains requires investment in organisational capital, including changes to processes, business models, management practices and workforce skills." Not licences. Not tools. Processes, business models, management practices and skills.

AI adoption is a change program, not a purchase. That is precisely why two-thirds have "some" AI and fewer than one in ten have anything significant.

Where to start

The organisations getting real value from AI are not the ones with the best tools. They are the ones that decided what they were trying to achieve, worked out where the risk actually sits, put proportionate controls around it, and trained their people to work confidently inside those controls.

That work is unglamorous, it is genuinely difficult to do from inside the business, and it benefits from an independent perspective.

Beyond Technology's AI Governance Advisory and AI Readiness Assessment have helped organisations do exactly that , understand the strategy, plan the response and prepare the environment before the acceleration rather than after it. For mid-sized organisations without internal IT leadership, our Fractional CIO service provides the executive capability to act strategically instead of reactively.

The Treasurer is right that we cannot wait for the benefits to fall into our lap. But reaching out and taking them is a good deal easier when you are strapped in and you know where you are driving.

Not sure which one your organisation is relying on today? That is the first question worth answering, and it takes days, not months. An AI Readiness Assessment is where most of our clients start the conversation.

Ready to talk?

Independent perspective. One conversation away.

A 30-minute conversation with a partner is the simplest way to see where your organisation stands. No pitch, no sales process - just a senior view of where you are and where the priorities should sit.

accordian pattern

Does your IT lack direction?