News
Delinea Survey Finds Gap Between AI Access Policies and Enforcement
Nearly all IT and security leaders surveyed by identity security company Delinea said their organizations have policies governing AI access to company data, but only about half said that access is checked against the rules in real time.
The report, published September 29, found that 99.7 percent of respondents reported having formal AI data-access policies, while 51 percent said access was checked against those policies as it occurred. Only 19 percent said their organization detected its most recent instance of an agent accessing data outside its intended scope in real time.
The findings highlight a gap between establishing AI governance and implementing controls to enforce it, according to Delinea’s fall 2026 Identity Security Report, “The AI Enforcement Gap.” Delinea commissioned two surveys covering 2,254 IT and security leaders and 2,250 non-IT employees at organizations with at least 500 employees across the U.S., U.K., Germany, Australia, Singapore, United Arab Emirates, France, and India. The organizations represented in the IT survey were using or piloting AI. All employees in the second survey used at least one AI tool for work.
AI Agents Complicate the Permissions Problem
The problem becomes more consequential as companies move from AI tools that primarily respond to users toward agents capable of taking actions on their behalf. Eighty-seven percent of IT and security respondents said their organization had experienced or suspected an incident during the previous year in which an AI tool or agent accessed sensitive information beyond what its task required.
Access can also persist after a task ends. Only 58 percent said their organizations had mechanisms to automatically revoke or expire AI access when a session ended, and those controls did not necessarily cover every tool or agent. Forty-two percent said many AI agent credentials remained active until an audit.
Half of IT leaders said their organizations relied on users’ existing permissions to limit what agents could access. That approach can give an agent access accumulated over time, rather than permissions tailored to a specific task. Agents can also behave differently from traditional service accounts. A service account typically executes a predefined process, while an agent can select tools and actions as it works.
“Service accounts run fixed scripts,” said Mike Albrecht, associate director in the Risk Advisory Practice at CrossCountry Consulting, in the report. “An AI agent decides what actions it’s going to take at runtime.”
Employees aren't Always Waiting for Approval
The enforcement problem is not limited to autonomous agents. Seventy-six percent of employees surveyed said they had bypassed formal approval at some point to use AI tools with company data, applications, or systems.
Forty-eight percent said they did so always or regularly. Sixty percent said they had felt pressure to use AI with sensitive or confidential information even when they were unsure whether it was permitted.
Senior executives reported bypassing approval more frequently than other employees. Eighty-one percent of C-level respondents said they always or regularly bypassed AI access approval, compared with 33 percent of intermediate-level employees. Visibility remained limited. Only 41 percent of IT leaders said all AI tools and agents accessing company data were actively monitored.
Asked about the most recent instance of an AI tool or agent accessing data outside its intended scope, 55 percent said detection took at least a day. Thirty percent said it took four days or longer. The findings reflect respondents’ accounts of their organizations’ practices. Delinea, which sells identity security products, has a commercial interest in stronger access controls.
“Most organizations cannot confidently answer three questions: What agents are running in our environment? What can they access? What have they actually done?” Delinea CEO Art Gilliland said in the report. “An agent can begin a session with legitimate access and drift into something it was never meant to do.”