CiBRAI says sovereign AI must protect business knowledge and the freedom to change providers
SYDNEY, 18 September 2026: Australian businesses could weaken the competitive advantage they hope to amplify with AI if they hand over valuable knowledge without understanding who can access it, retain it or act on it, cybersecurity company CiBRAI warns.
“Your data doesn’t need to be stolen for you to lose control of it,” said Andrew Curtis, Founder and CEO of CiBRAI. “Someone can upload a tender or a pricing spreadsheet because they’re trying to do a good job. The business gets an answer. It also needs to know what happened to the information.”
“The subscription price tells you very little about the value of the knowledge flowing through it. An Australian engineering firm might be connecting decades of expertise to a service it signed up for in minutes.”
The warning follows the ABC’s 16 September report that Anthropic had agreed to use a proposed Queensland data centre, subject to approvals. National Cabinet has also agreed to develop mandatory standards for large data centre energy, water and land use, with Commonwealth legislation intended for early 2027.1,2
“If the board can see the productivity gain but nobody can trace the information behind it, the business case is unfinished,” Curtis said.
National AI Centre research found 43 per cent of surveyed Australian small and medium enterprises reported some AI adoption during the December 2025 to February 2026 quarter.3
CiBRAI says businesses need to follow the whole AI workflow, including connected documents, prompts, outputs and logs. Storage location, processing location and permission to use information for model training are separate questions.4
“An Australian postcode is the beginning of the sovereignty conversation,” Curtis said. “Who can access the information? What gets kept? Which laws apply? A promise not to train on your data still leaves those questions to answer.”
Under the US CLOUD Act, relevant providers subject to US jurisdiction can be required through applicable legal process to disclose information within their possession, custody or control, even when stored outside the United States.5
CiBRAI recommends identifying AI tools already in use, including staff accounts and features inside everyday software. Businesses should classify sensitive information, set written rules for approved tools, and check providers’ processing locations, subcontractors, retention and deletion arrangements. Existing privacy obligations already apply to organisations covered by the Privacy Act.6
“Give people an approved option that works well enough to use,” Curtis said. “If the official process makes a ten-minute job take two hours, you’re creating an incentive to work around it. Good governance has to survive a busy Tuesday.”
The company advocates matching each workload to its risk, using global services where appropriate and controlled Australian cloud or on-premises environments where required. Each arrangement needs suitable access restrictions, encryption and tested recovery, along with a practical plan to move information and workflows to another provider.7
“Ask your AI provider what it would take to leave,” Curtis said. “The answer will tell you how much control you’ll have when the price, the terms or your business needs change. The freedom to change suppliers is worth protecting.”
Curtis expects scrutiny to intensify through 2027 as AI agents gain permission to change records, send messages and trigger business processes. He urges businesses to limit those permissions, require approval for consequential actions and retain a way to stop an agent.8
“When an AI agent can send a quote or change a customer record, you’ve given it authority to act for your business,” Curtis said. “Give it clear limits, a responsible owner and a way to stop it.”
He said demonstrable control can help Australian firms win customers at home and overseas. The government-backed Buy Australian AI Partnership, announced in August, connects local AI companies with enterprise buyers and emphasises responsible AI assurance alongside procurement readiness.9
“Australia has expertise the world wants. AI can give a small Australian firm the reach to compete for customers it could never serve before,” Curtis said. “We should be ambitious about that opportunity. The goal is to grow a business that keeps control of its knowledge and a fair share of the value it creates.”
CiBRAI is challenging business leaders to trace one valuable AI workflow in the next 30 days. Establish who can access its information, who can authorise actions and how the work could move elsewhere. Discuss AI data exposure with CiBRAI at www.cibrai.com/company/contact/.
ENDS
CiBRAI is an Australian cybersecurity technology company behind the CiBRAI Cybersecurity Operating Platform. It brings security signals, AI-assisted investigation, guided response and reporting into a unified environment. Deployment options include cloud, hybrid and on-premises configurations, supporting organisations that need control over sensitive information and security operations.
Andrew Curtis | Founder and CEO, CiBRAI
acurtis@cibrai.com | +61 416 143 454 | www.cibrai.com
Supporting sources checked on 18 September 2026. Numbers correspond to the references in the release.
Reports the proposed Western Downs project near Dalby. The lease is subject to Foreign Investment Review Board approval and development requires council approval. The announcement does not establish current Australian processing for all Claude workloads.
Records agreement to develop mandatory standards for large data centre energy, water and land use. Commonwealth legislation is intended for early 2027, including AI-training conditions. These infrastructure measures are distinct from business obligations when using AI.
Reports 43 per cent SME adoption across the stated quarter. The monthly SME AI Pulse surveys at least 400 business owners and decision-makers per wave and weights results by industry, state and employee size.
Illustrates why processing geography, storage and training use need separate checks. Certain Global deployments can process across geographies; some features retain histories. Controls depend on the service, deployment and configuration.
Amends 18 USC §2713 to cover relevant information in a provider’s possession, custody or control regardless of storage location. Jurisdiction and applicable legal process remain necessary; this is not unrestricted access to every foreign provider.
Explains existing duties for covered organisations, product due diligence, data flows, staff training and ongoing review. Recommends avoiding personal information, particularly sensitive information, in publicly available generative AI tools.
Addresses location and access, contracts, recovery, retention and portability. These considerations support the release’s recommendation to assess control, resilience and exit arrangements in both local and hybrid deployments.
Identifies excessive permissions, functionality and autonomy as risks. Recommends least privilege, downstream authorisation, monitoring and approval for high-impact actions. The release’s 2027 outlook is Curtis’s forecast.
Describes connections between Australian AI companies and enterprise buyers, with responsible AI assurance, governance and procurement readiness supporting commercial scale.