Observations from Australia’s CIO Summit: AI-ready starts with the data, not the AI
An insider look at the state of enterprise IT: why AI readiness fails without trusted data foundations, governance, and cultural alignment.

Last week I was fortunate enough to attend the Marcus Evans CIO Summit on the Gold Coast, Australia, where I had the opportunity to speak 1:1 with CIOs and CTOs about their digital transformation journeys, AI readiness, and the challenge of innovating without losing control of enterprise information.
While there were varying levels of AI maturity, one theme came through consistently: Most organisations don't have an AI problem. They have a data and governance problem, and a lot of it links back to culture.
From data sprawl to AI sprawl
Many Australian leaders described information spread across siloed repositories, legacy platforms and line-of-business applications.
Interestingly, AI adoption is happening in much the same way. Different teams are adopting different AI tools, models and use cases, often independently and without an enterprise-wide approach. It’s simply a case of staff downloading ChatGPT or Claude and embedding them into their everyday tasks across the business.
The result is AI sprawl layered on top of existing data sprawl. Looking at the conversations and investment roadmaps from the summit, this is a shared anxiety; multiple enterprise leaders explicitly named “AI sprawl” and “responsible AI” as their top governance challenges for the coming year.
The question for CIOs and CTOs is shifting from
How do we get people using AI?
to
How do we govern and scale the AI they’re already using?
Deloitte’s State of AI in the Enterprise highlights the challenge: 74% of organisations plan to deploy Agentic AI within two years, yet only 21% report having a mature governance model for autonomous agents. This isn’t just a global statistic. Looking at the investment roadmaps of the delegates in the room, Agentic AI was overwhelmingly the most common technology slated for investment over the next 6 to 18 months.
Trusted AI starts with trusted data
AI readiness isn’t simply about choosing an LLM or turning Copilot on and hoping for the best.
Organisations need to first understand what information they have, where it resides, whether they should still have it, who should have access to it and whether AI should be allowed to use it. Trust needs to be built into the data and its lineage from day zero, before it is ingested and used by AI.
That means cleansing information while maintaining compliance, applying retention and disposition policies, and making governance continuous through ongoing policy management. This is particularly critical given that many CIOs at the event admitted their biggest hurdle to AI is actually dealing with legacy platform transformation and dark, unstructured historical data.
Agentic AI raises the stakes further. If an AI agent is retrieving information, making decisions and triggering downstream digital workflows, governance needs to travel with the data.
From governance to business outcomes
This was one of the areas that generated the most interest in my conversations.
Consider processes where employees manually review documents, identify and redact TFNs or PII, validate information, and then re-key that data into another system. This becomes even more challenging in highly regulated industries, particularly financial services, where meeting APRA obligations around information security, operational risk and data governance was another hot topic in my conversations.
At scale, these processes can consume thousands of hours of human effort simply because someone needs to put eyes on every document. Agentic AI has the potential to fundamentally redesign that workflow.
Documents can be ingested and classified, sensitive information automatically identified and redacted, relevant data extracted and validated, and the information passed directly into the next system or business process.
The outcome isn’t simply better governance. It’s removing unnecessary manual
touch points altogether. That means fewer hours spent reviewing documents, less
manual data entry, fewer opportunities for error, faster processing and
employees freed up for higher-value work. Many of my conversations therefore moved beyond
What can AI do?
to a much more interesting question:
Which processes can we redesign so humans no longer need to sit in the middle
of them?
That’s where Agentic AI, trusted data and governance start translating into genuine business outcomes.
AI governance is also about culture
Managing AI sprawl isn’t purely a technology problem.
Employees are already experimenting with AI. Trying to stop that experimentation risks slowing innovation, while ignoring it creates shadow AI and greater governance risk. One attendee shared a great example. Her organisation introduced an AI chatbot to its customer base with the goal of streamlining support requests and improving the customer experience. Technically, the solution worked. The challenge was trust.
To identify customers, the agent needed to request sensitive information such as contact details and answers to security questions. Customers were uncomfortable providing that information to an AI agent, and adoption suffered. The result? They pulled the chatbot from the frontline. It was a powerful reminder that successful AI adoption isn’t just about whether the technology works. It’s about whether the people expected to use it understand it, trust it and feel comfortable with how their information is being handled.
The goal shouldn’t simply be to deploy more AI. It should be to create a culture where AI adoption happens within trusted boundaries, with employees and customers brought along on the journey. Trust isn’t something you add after deploying AI. It needs to be designed into the experience from the beginning.
My biggest takeaway
What struck me most on the Gold Coast wasn’t the appetite for AI. That’s clearly there. It was the combination of siloed enterprise information and increasingly siloed AI adoption. Without an enterprise approach to data, governance and culture, yesterday’s data sprawl risks becoming tomorrow’s AI sprawl.
So perhaps the question organisations need to ask before racing towards the next AI use case is, “Is the information we’re giving AI governed, trusted and ready to be used?”
The organisations that get this right won’t simply have more AI. They’ll have AI their employees can embrace, their customers can trust, and their organisation can govern and scale.
Unlocking the path forward: Building your AI-ready foundation
In the era of AI, your data is your advantage. Yet too often, it remains untapped—disconnected from systems, underutilised, untrained and exposed to risk. At Iron Mountain, we believe you shouldn’t just mine your data: you need to manage it. We help organisations unlock what’s possible with data management solutions that protect, connect and activate this vital asset like never before.
By digitising your information and preparing it with AI-powered intelligent document processing, we ensure your data is accurate and ready for automation. We combine expert governance, custom retention schedules and certified secure storage to safeguard your critical assets. Through Iron Mountain InSight® DXP, you can manage your content in a single-pane view, conquering legacy data sprawl, transforming information into intelligence, and building the trusted data foundation required to make enterprise AI a reality.
Don’t let disconnected data hold back your AI ambitions. Explore how InSight DXP can help you automate workflows, mitigate risk and turn your enterprise information into a vital competitive advantage.
