State of Data & AI 2026: Data Sovereignty & Compliance

proudly sponsored by
NEXTDC

Data sovereignty and compliance have become foundational requirements for enterprise AI, but the challenge facing Australian organisations has evolved well beyond deciding where data should be stored.

The rise of AI has meant organisations are increasingly being judged not by where their data resides, but by how effectively they can demonstrate control over who - and increasingly what - can access it.

At the same time, recent Privacy Act reforms and updated guidance from the Office of the Australian Information Commissioner (OAIC) are pushing organisations towards stronger transparency, security, and accountability around personal information, including cross-border disclosure. Security of Critical Infrastructure (SOCI) obligations are also placing greater emphasis on protecting systems holding business-critical data.

Privacy Commissioner Carly Kind said this emphasis on accountability reflected the intent of Australia's privacy framework.

"Data sovereignty is not essential to the Australian privacy framework," she said. "The bar to send data overseas is relatively low. It isn't an object of the legislation that the data should stay in Australia - the object of the legislation is that data is protected wherever it is.

And there are some not-very onerous obligations on entities to ensure that when they send data overseas it is getting those protections.”

The rise of AI is creating new data flows through prompts, embeddings, logs, model outputs, and agent interactions, requiring organisations to govern not only where data is stored but also how it is retrieved, reused, and shared. That is placing increasing emphasis on identity and access management, with organisations needing to demonstrate least-privilege access and comprehensive audit trails for human and non-human agents.

Kind said this challenge was becoming increasingly complex as more organisations relied on overseas providers and AI platforms, raising questions regarding how Australians could obtain redress when their personal information was shared through complicated international supply chains.

Kind noted that AI was creating additional governance challenges because many organisations no longer fully understood where AI had become embedded within their operations or where it was influencing significant business decisions. That could create compliance challenges when new Privacy Act transparency requirements take effect in December, requiring organisations to disclose certain uses of substantially automated decision-making involving personal information.

However, Kind said many organisations still had significant work to do before they could demonstrate compliance with the Privacy Act. Following a recent compliance sweep of 60 organisations, the Office of the Australian Information Commissioner found a large proportion failed to meet basic privacy policy requirements.

"We are starting from a pretty low level," she said.

"What we ultimately want to see is compliance – not having to spend a lot of resource going after non-compliance."

While data sovereignty might not receive the same emphasis in Australia as in Europe or China, most Australian regimes, including the Privacy Act and the Security of Critical Infrastructure Act, require organisations to manage risks associated with offshore storage, cross-border disclosure, and third-party providers. One notable exception is the My Health Records Act 2012, while certain classes of Commonwealth information are also subject to Australian hosting requirements.

For Australian organisations, Kind suggested the challenge was less about keeping all data within national borders and more about demonstrating they understand where it was, who could access it, how it was protected, and how it was being used.

“Australians generally feel that they have very little control over their privacy, and particularly their personal information, and we know that that is getting worse,” Kind said.

“The public attitudes research that we do every three years found something like 86 percent of people said that they are more concerned today about their privacy than they were five years ago.

"We know that trust levels are very, very low and Australians are now facing this impending tsunami of AI.

"It is the regulator's role to intermediate the relationship so that people can feel that they can trust when they use new technologies and hand over their personal information."

As AI becomes more deeply embedded in enterprise operations, the emphasis on accountability is only likely to increase. For Australian organisations, the challenge is no longer simply knowing where data resides, but demonstrating they can govern and protect it wherever it is.

Case Study – Eightcap

Fast-growing Australian fintech Eightcap is using AI to help manage growing compliance workloads while ensuring customer data complies with privacy, access and data sovereignty requirements across multiple jurisdictions.

Eightcap senior administrator Julius Anuari said operating a global online trading platform meant complying with customer privacy, access governance and data residency requirements that differed across jurisdictions.

That meant engineering, security, and compliance teams all assessed new technology before it was deployed.

“We’re in the fintech business, so we are highly regulated in every jurisdiction,” Anuari said.

“Regulators will have different requirements. In light of that, every tool that we use or try to implement, or feature that comes on … we want to be in a position where it is all above board.

“The compliance team needs to be really across it, the engineering team needs to be really across it, the security team needs to be across it.”

To support that approach, Eightcap has built role-based access controls into its customer relationship management platform, allowing globally distributed sales, onboarding, support, and compliance teams to work from the same customer record while restricting access to sensitive information according to their individual roles.

"We are dealing with teams all over the world that have to speak with the same visibility, so when they are talking to the customer, support knows the same thing that onboarding knows, and sales knows the same thing as well as compliance," Anuari said.

The company uses Salesforce as the foundation for those operations, with Anuari also serving as its platform lead.

“The security of accessing that information is inherently out-of-the-box with Salesforce, so we are leveraging that,” he said.

Anuari said the company was also focused on meeting privacy obligations that varied between jurisdictions, including customers' rights to have personal information deleted or provided on request.

"If the customer needs the right to be forgotten, we are able to provide that," Anuari said. "If the customer asks for information on them, portability information, you have to provide it."

Those governance foundations have also enabled Eightcap to expand its use of AI, particularly within compliance operations, where staff were required to monitor large volumes of customer interactions across calls, emails, and online chats.

Eightcap is using AI to automate the repetitive work of compliance, including generating call transcripts, summarising conversations, identifying duplicate records, and flagging keywords or customer sentiment for further review.

“(We) let the agentic side deal with volume, and then the human side deal with complexity," Anuari said. 

“Over time, we have actually found that frees up the human agent to just deal with more of the complicated issues.”

This approach has significantly reduced the amount of manual review required by compliance teams, who previously might have to listen to thousands of minutes of recorded calls.

"Now you have the internal AI agent that scavenges through the transcripts … and it generates a summary description'," Anuari said.

“All of these are flagged on a record, and then depending on who is responsible, the chain of command is followed from there.”

The company was also using AI to analyse customer sentiment, helping distinguish between routine frustration and potentially abusive behaviour that might require escalation.

Anuari said that while the initial focus had been on automating compliance processes, he said Eightcap was now exploring how AI could strengthen internal security by identifying unusual permissions, insider threats, and other anomalous behaviour before incidents occurred. He believed this would be particularly valuable in detecting insider threats.

"While we have been so strong at blocking out the external, most vulnerabilities have happened from within,” he said.

As Eightcap expanded into additional markets, Anuari hoped AI would shift compliance from a reactive process to one that anticipated regulatory requests and automatically assembled the evidence required.

“We are still scaling and reaching global regions that have various compliance requirements,” he said. 

“I really want to reduce the time it takes us to provide this evidence. We're doing the monitoring, but what if we were ahead of it?"

 

 

Data Sovereignty and Compliance Champion

Browse the report

Click on the tiles below to read each chapter of the State of Data & AI 2026 report.

State Champions

State of Data & AI 2026 champions will be featured here.

Workato
Leidos
Penguin Solutions
NEXTDC

Log In

  |  Forgot your password?