Your organisation has an Agentic AI operating inside it. Maybe several. It accesses your systems. It makes decisions. It acts on your behalf. It can read your CRM, send communications, escalate issues, and trigger downstream workflows without a human hand on every step.
So here is the question you need to answer before it scales any further:
Is that Agentic AI an employee or is it simply software?
It sounds deceptively simple. It is not. The answer determines almost everything about how you govern, secure, and hold accountable the AI agents now acting on your behalf. And right now, most Australian and New Zealand organisations have not answered it at all.
If an AI agent is software in the traditional sense, it belongs inside your existing technology governance lifecycle. Procurement, change management, access controls, decommissioning. It sits in an asset register. It is assessed at deployment and reviewed periodically. The risk team knows it exists.
But Agentic AI does not behave like traditional software. It acts autonomously. It makes decisions. It accesses data and initiates actions on behalf of your organisation without being explicitly instructed to do so for each task. That description does not fit software. It fits a member of staff.
A member of staff who has never been onboarded. Never been background-checked. Has no employment contract, no defined scope of authority, no performance review cycle, and no clear line of accountability when something goes wrong.
The World Economic Forum's Global Cybersecurity Outlook 2026 is direct on this point. Without strong governance, AI agents can accumulate excessive privileges, be manipulated through design flaws or prompt injections, or inadvertently propagate errors and vulnerabilities at scale. Their speed and persistence amplify these risks. The report calls for continuous verification, audit trails, and accountability structures grounded in zero-trust principles. That is not software governance. That is identity and access management applied to a non-human workforce.
APRA made the same observation in its April 2026 letter to all regulated entities. Identity and access management capabilities within Australian banks, insurers, and superannuation trustees have not yet adjusted to non-human actors such as AI agents.
Across Australia and New Zealand, a familiar pattern is playing out. An organisation launches a proof-of-concept. Some value emerges. The pilot is declared a success. And then it stalls. The agent sits in a sandbox while the business waits for clarity that never quite arrives.
The caution is understandable. The reason for it is the problem. Organisations are not pausing because they have done the governance work and found genuine blockers. They are pausing because the governance work has not been done at all. The hesitation is filling the space where a framework should be.
Meanwhile, the pressure to move is building hard from the other direction. Research from TrendAI surveying over 3,700 business and IT decision-makers found that 67 per cent of respondents reported pressure from leadership or market dynamics to accelerate AI deployment, even when security concerns had been raised.
Where do you actually stand?
APRA wrote to industry on AI governance on 30 April 2026. ASIC issued 26-092MR on 8 May 2026. The ASD Essential Eight remains the baseline requirement for government suppliers and insurers. An independent readiness assessment gives you a documented position against the obligation that actually binds you. Two to four weeks. Founder reviewed. Every time.
Frontier AI models. Every week a new capability announcement lands alongside a new vulnerability disclosure. Boards that were cautiously optimistic about Agentic AI six months ago are now getting bombarded with reasons to hesitate.
The concerns are real. More capable models expand the attack surface. They lower the barrier for adversaries to conduct reconnaissance, craft phishing at scale, and probe vulnerabilities faster than security teams can respond. APRA called out frontier models specifically in its April 2026 letter. ASIC followed in May 2026 with its own open letter to AFS licensees and market participants, requiring it be tabled at every board and risk governance committee.
ASIC stated it plainly: frontier AI models are a step-change in capability, but they do not change the fundamentals of good cyber resilience.
They reinforce the importance of strong, end-to-end preparedness. The answer to a more capable threat environment is not paralysis. It is better foundations.
Our position at Insicon Cyber is straightforward. Agentic AI can absolutely be deployed in a meaningfully secure way. The condition is that governance comes first. Not alongside the rollout. Not as a quarterly review item once agents are already running. First.
For Australian and New Zealand organisations, that means resolving five things before scaling.
An AI inventory is not optional. Every agent operating in your environment needs to be named, scoped, and risk-tiered. APRA expects it. The WEF recommends it. Matt Miller, Co-Founder, CEO and Fractional CISO at Insicon Cyber, puts it this way:
"Do you know where AI is being used inside your business, and do you know what would happen if one of those systems was compromised or manipulated? If you cannot answer that, you are not ready to govern it. And you are definitely not ready to defend it."
Every agent needs a defined identity, defined permissions, and defined limits. Least-privilege applies. Zero-trust applies. An agent with access to your CRM, your email environment, and your service management platform has more reach than many junior employees. It should be onboarded with the same rigour.
APRA observed that most organisations are relying on point-in-time, sample-based assurance methods. AI agents are probabilistic systems. They learn. They adapt. They can drift. Continuous monitoring is not a nice-to-have. It is the baseline for any agent operating at scale.
When an AI agent makes a decision that causes harm, the regulatory scrutiny will land on the organisation that deployed it. Ownership of AI risk must be defined at the executive level before a single agent goes live at scale.
APRA found organisations heavily dependent on a single AI provider across multiple use cases, with little evidence of exit planning or contingency. If the underlying model is updated, deprecated, or compromised, what is your fallback?
The organisations moving confidently into full-scale Agentic AI deployment are not the ones that have avoided the headlines. They are the ones that resolved the employee-or-software question early, mapped the floor before they walked across it, and built governance before they needed it.
Greg Bunt, Co-Founder and Director at Insicon Cyber, sees the same dynamic with clients across both sides of the Tasman:
"The organisations that have done the governance work are not the ones pumping the brakes. They are the ones accelerating with confidence, because they know what they have, who owns it, and what happens if something goes wrong."
If your organisation is sitting in pilot purgatory, the answer is not to wait for the headlines to settle. They will not. The answer is to build the governance foundation that makes meaningful, secure deployment possible.
That is what we do. Get in touch at info@insiconcyber.com.
Sources