The December obligation does not test the AI application you hardened

Your AI security posture is documented and tested. Application-layer controls are in place. The security team has run penetration testing against the agents, not the surrounding infrastructure alone, and the results held. The board has seen the risk profile. The audit trail is clean. Prompt injection, jailbreak attempts, and model-level vulnerabilities sit at the application layer, and that is where the investment has landed.

In Brief


  • The December ADM obligation tests the data layer, not the application layer most AI security investment has hardened.
  • Only 8% of Oceania security professionals feel very prepared to manage generative AI risks.
  • Application-layer security and data-layer governance sit in different budget lines and report to different functions.
  • Each AI application deployed without data governance widens the gap between security posture and compliance position.

The automated decision-making (ADM) transparency and disclosure obligation taking effect in December 2026 does not sit at that layer. It reaches the data underneath: what was used, how it was sourced, whether anyone governed it at the point of retrieval. An organisation that hardened the application while leaving its underlying data access ungoverned has not answered the obligation partially. It has answered at the wrong address.

The application is not the address

Most Australian organisations have concentrated their AI security investment at the application layer because that is where the visible risk sits and where the vendor market has focused its energy. Nexus42 and RedBear (2026) identify three generations of generative AI (GenAI) security thinking: perimeter security (keeping AI tools out), application security (guardrails, penetration testing, access controls), and data security (governing what data can be accessed by any AI system, under what conditions, and with what controls at the retrieval layer). Most Australian organisations are operating at generation one or early generation two. The December obligation sits at generation three.

The scale of the readiness gap is measurable. The ISACA (2026) Tech Trends and Priorities Pulse Poll found that only 8% of Oceania security professionals feel very prepared to manage generative AI risks. Australian organisations are forecast to spend more than $7.5 billion on information security in 2026 (Nexus42 & RedBear, 2026). Most of that spend is reaching the application layer because that is where the vendor market has built and priced its products. The total investment is not the issue; the address it reaches is.

The constraint persists because the two layers sit in different budget lines and report to different functions. Application-layer security is owned by the security team, funded from the security budget, measured by penetration test results and compliance certifications. Data governance, when it exists as a distinct function, is funded from the data management or IT operations budget and measured against objectives that predate the current AI deployment cycle.

No single function holds both questions. The security team has the mandate to harden the application but not the authority to govern the data. The data function has the governance mandate but rarely the AI-specific context to apply it to retrieval-layer access patterns. A security leader working in good faith defaults to the controls they can procure and report against. The vendor market reinforces this because the firms selling AI security products are selling application-layer controls; data governance is harder to productise and harder to attach to a board-ready demonstration. The market signal reaching the security leader is that application-layer security is the AI security question, and the available products confirm it. The underlying accountability question — who at the C-suite level owns AI governance — remains unresolved in most Australian organisations.

Milroy (2026) reports that 67% of organisations surveyed struggle with AI data security and access controls, and 63% struggle to identify trustworthy data or prepare and integrate it for AI use. Both problems sit at the data layer, exactly where the December obligation will land.

Every new application adds exposure

The December obligation does not ask whether the AI application was secure. It asks whether the automated decision was transparent: what data informed it, how that data was sourced, whether the individual affected was told. An organisation with a clean application-layer audit and no data provenance trail has documentation that answers a question the obligation does not ask, and no documentation that answers the question it does.

An organisation with a clean application-layer audit and no data provenance trail has documentation that answers a question the obligation does not ask.

Each AI application deployed without data-layer governance widens the distance between what the organisation can demonstrate and what the obligation requires. The first application is a manageable gap: a single data source with a traceable decision path. By the fifth, drawing on different data sources with different access patterns, the gap has become a remediation project. Milroy (2026) found that enterprise AI initiatives draw on an average of more than 400 data sources, with nearly one in five organisations accessing over 1,000. Each source carries its own access controls and governance status, and its own relationship to the data the obligation will test.

Shadow AI widens the exposure. Nexus42 and RedBear (2026) report that 46% of Australian organisations already have employees using AI tools without organisational oversight, with more than one in three professionals regularly uploading sensitive data to platforms the organisation does not govern. Those tools are making or supporting decisions using data the organisation cannot trace. The December obligation does not distinguish between AI tools the organisation supports and those it does not; it asks about the data behind the decision regardless of which tool made it. The distance between what the organisation can demonstrate and what the obligation requires grows with every application that goes live. Remediation after the obligation takes effect will be materially harder than governing the data before deployment. For Australian Public Service agencies, the assessment capacity the December deadline assumes has not been established.

The executive who has invested in application-layer security has done necessary work. That investment addresses a real and growing threat surface, and it will continue to matter regardless of the regulatory environment. Nexus42 and RedBear (2026) describe the posture correctly: security at this layer is an architectural decision, and the organisations that built it in from the start will move faster than those that try to bolt it on later.

The December obligation tests a different surface entirely. The application breach question has been answered. The obligation asks whether the data the application used to make or support a decision about an individual was governed, sourced transparently, and disclosed. The test the executive should apply to their own posture is specific: for every AI application making or supporting decisions about individuals, can the organisation demonstrate what data was used, where it came from, whether it was the right data for that decision, and whether the person affected was informed?

What this means for senior leaders

  1. Application-layer security investment addresses a real and growing threat surface. That investment remains necessary regardless of the regulatory environment, but it does not answer the question the December 2026 ADM disclosure obligation asks.
  2. The December obligation tests what data informed the automated decision and whether the affected individual received disclosure — not whether the application itself was secure.
  3. The gap between security posture and compliance position is structural: application-layer security and data-layer governance sit in different budget lines, report to different functions, and respond to different mandates. Closing the gap requires bridging that functional divide.
  4. Each AI application deployed without data-layer governance widens the distance between what the organisation can demonstrate and what the obligation requires. Governing the data before deployment is materially easier than remediating after the obligation takes effect.

The December obligation tests the data underneath the application, not the application itself. The organisation that has governed both layers holds a posture built for the right address.

References

  • ISACA. (2026). 2026 tech trends and priorities pulse poll. https://www.isaca.org/resources/tech-trends-pulse-poll
  • Milroy, A. (2026). The gap report: Trustworthy agentic AI requires live data, the right data, and guardrails. Veqtor8 for Denodo.
  • Nexus42 & RedBear. (2026). Your GenAI stack is already an attack surface: Post-event insights report.

About the author

Receive insights on strategy, leadership, and transformation.
By subscribing you agree to our Privacy Policy
© 2026 Zen Ex Machina (ZXM) Pty Ltd. All rights reserved. ABN 93 153 194 220

Discover more from Zen Ex Machina

Subscribe now to keep reading and get access to the full archive.

Continue reading

search previous next tag category expand menu location phone mail time cart zoom edit close