Research & InsightsAI

AI governance readiness: where mid-sized businesses stand in 2026

Most mid-sized organisations are using AI tools daily, but few have the policies, controls and data hygiene to use them safely. What we see across our client base and what to fix first.

FLYONIT Research Team10 September 20267 min read
Executive summary

The short version

Generative AI has moved from experiment to everyday tool. Staff paste customer data, contracts and code into AI assistants whether or not the business has a policy.

The gap is not adoption. It is governance: who can use which tools, with what data, and how the outputs are checked before they reach a customer.

The organisations doing this well treat AI like any other business system. They start with an inventory, set clear rules, and use the controls already in Microsoft 365 before buying anything new.

Findings

What we found

1

AI use is widespread and mostly unmanaged

Across the environments we review, AI assistants are in daily use in almost every team. In most cases there is no approved list of tools, no usage policy and no visibility of what data is leaving the business.

2

Data quality decides the outcome

Businesses that had already tidied permissions, retired stale file shares and labelled sensitive data got value from AI quickly. Those that had not found the tools surfaced information people should never have been able to see.

3

Existing licences already contain most of the controls

Sensitivity labels, data loss prevention and conditional access in Microsoft 365 cover the majority of AI-related risks. Few organisations have switched them on.

Recommendations

What to do next

  • Run a short AI inventory: which tools, which teams, which data.
  • Publish a one-page acceptable-use policy that staff can actually follow.
  • Turn on sensitivity labels and data loss prevention before enabling Copilot or similar tools broadly.
  • Nominate an owner for AI governance and review usage quarterly.

Methodology and sources

  • Drawn from AI readiness and security reviews FLYONIT completed for Australian organisations between 50 and 1,000 staff over the past twelve months.
  • Observations are anonymised and aggregated. No individual client is identifiable.
  • Guidance is aligned with the Australian Cyber Security Centre's advice on secure AI use and the ISO/IEC 42001 AI management standard.