Governing enterprise AI: 3 identity rules for Australia and New Zealand

Deloitte and Okta unpack three ways to scale AI safely across Australia and New Zealand.

About the Author

Laurie Isola

Newsroom Editorial Manager

Laurie Isola is a writer, editor, and content strategist with experience that spans newsrooms, nonprofits, and tech. Now in the identity and security space, she uses that experience to uncover stories that provide clarity and utility to readers, from senior decision-makers to everyday users.

10 September 2026 Time to read: ~

Enterprise AI is no longer just answering prompts or drafting summaries. Across production systems, AI agents are actively querying live databases, automating support workflows, and triggering transactions. Because these agents take action independently, they operate with permissions that used to belong strictly to human employees.

In Australia, this shift is already in motion. According to Deloitte’s 2026 State of AI in the Enterprise report, 69% of Australian organisations are using AI agents. Yet governance has struggled to keep pace: 22% of respondents report having highly advanced models to govern them. Without governance, security teams cannot enforce access boundaries on agents they cannot see. That tension is particularly acute in highly regulated sectors such as financial services, healthcare, and government, where compliance requirements are unforgiving.

‘Some of the organisations who are especially compliance-driven … are actually quite confused and actually quite scared at the same time because they’ve got compliance and regulatory requirements,’ explains Shweta Pandey, Partner, Cyber, Technology and Transformation, Deloitte. ‘They want to ensure they’re putting proper governance in, but they have not yet explored the whole depth of AI identities, specifically what kind of access they have.’

To help organisations navigate these risks, Okta and Deloitte recently launched a strategic alliance in Australia and New Zealand, pairing Okta’s modern identity platform with Deloitte’s cyber risk and business transformation advisory.

Mike Reddie, Vice President and General Manager, ANZ at Okta, sat down with Pandey to unpack what happens when autonomous code moves faster than corporate policy. Here are three takeaways from their discussion on governing AI identity:

Don’t copy-paste human rules onto AI

Under pressure from tightening compliance mandates, some organisations take a tactical shortcut. Pandey noted that, in these cases, companies have adopted AI but are applying the same controls as they do for humans. But as she pointed out later in the discussion, trying to force legacy systems and human controls onto fast-moving AI agents isn't sustainable, especially when organisations have yet to explore the full depth of access privileges these agents require.

Solve visibility before writing new rules

Many organisations are getting stuck at the first step: trying to establish comprehensive visibility, Pandey observed. Between internal teams spinning up embedded AI tools and third parties deploying automated agents, unmonitored identities multiply fast. To manage the risk, Pandey recommends a four-step progression: gain visibility across platforms, business units, and third parties, identify AI controls, apply them, and then report on them. That four-step sequence reflects Okta’s blueprint for the secure agentic enterprise, which centres on three key questions organisations should strive to answer: Where are my agents? What can they connect to? What can they do?

Right-size your risk appetite to avoid stalling innovation

Tightening regulations across Australia understandably have many boards on edge. But overreacting to mounting compliance pressure can deliver its own kind of damage: stalling business agility and pushing teams toward shadow AI. 

‘Quantifying the risk itself is quite a challenge,’ Pandey said. Treating it as extreme can trigger false alarms and rushed controls, but measuring it accurately allows teams to define their risk appetite and bring exposure to a manageable level. Pandey recommends taking small steps: first contain and identify the risk, understand the security gaps, and systematically work toward mitigating them.

Want more insights? Watch the conversation

As AI agents take on critical workflows, organisations face a simple reality: They cannot govern what they cannot see. Modernising with a neutral identity platform helps ensure teams maintain visibility and control over automated access across every system.

In the full video discussion, Mike Reddie and Shweta Pandey go beyond these three takeaways to address other critical questions:

  • What changes when AI agents start operating autonomously?

  • How important is an independent identity platform in the current landscape?

  • What happens when an autonomous AI agent goes wrong?

Watch the complete discussion to explore how Okta and Deloitte are helping organisations build a secure foundation for agentic AI.

Vidyard video

About the Author

Laurie Isola

Newsroom Editorial Manager

Laurie Isola is a writer, editor, and content strategist with experience that spans newsrooms, nonprofits, and tech. Now in the identity and security space, she uses that experience to uncover stories that provide clarity and utility to readers, from senior decision-makers to everyday users.

Get our Identity newsletter

Okta newsletter image