Survey Identifies Data Governance Enforcement Gap for Agentic AI Tools

According to a new survey from identity security company Delinea, 99.7% of IT and security leaders said their organization has a formal policy governing what data AI tools and agents are permitted to access. Yet only about 51% said AI access is checked against those policies in real time. Perhaps more worrying is that only 19% said their organization could detect in real time when an agent last accessed data outside its intended scope.

That disconnect is at the center of Delinea's fall 2026 Identity Security Report, "The AI Enforcement Gap," which suggests companies have made quick progress establishing AI governance but have not necessarily built the technical controls needed to enforce it.

The findings come from a pair of surveys covering 2,254 IT and security leaders and 2,250 non-IT employees at organizations with at least 500 employees across the U.S, U.K, Germany, Australia, Singapore, UAE, France, and India.

All the organizations were using or piloting AI, while the employees surveyed used at least one AI tool for work.

AI Agents Complicate the Permissions Problem

The problem becomes more consequential as companies move from AI tools that primarily respond to users toward agents capable of taking actions on their behalf.

Eighty-seven percent of IT and security respondents said their organization had experienced or suspected of an incident during the past year in which an AI tool or agent accessed sensitive information beyond what was required for its task.

Delinea's research also suggests companies are giving agents access that can persist longer than necessary. Only 58% of IT and security leaders said they have mechanisms that automatically revoke or expire AI access when a session ends, and those controls do not necessarily cover every agent or tool. Forty-two percent said many agent credentials remain active until an audit.

Agents also are not always receiving their own narrowly defined permissions. Half of IT leaders said their organizations use the employee's existing permissions as a boundary for what an agent can access. That can effectively hand an agent years of accumulated access belonging to the person who launched it.

That is particularly significant because an AI agent does not necessarily behave like a traditional service account. A service account typically performs a predefined process, while an agent can choose different tools, actions and sequences at runtime depending on the situation.

"Service accounts run fixed scripts," said Mike Albrecht, associate director in the Risk Advisory Practice at Cross Country Consulting. "An AI agent decides what actions it's going to take at runtime."

Employees aren't Always Waiting for Approval

The enforcement problem is not limited to autonomous agents.

The researchers found that 76% of employees surveyed had bypassed formal approval at some point to use AI tools with company data, applications or systems. And 48% said they always or extensively use AI tools without going through formal approval.

Meanwhile, 60% said they had felt pressure to use AI with sensitive or confidential information even when they were not sure doing so was permitted.

Executives were particularly likely to circumvent the process. Eighty-one percent of C-level respondents said they always or regularly bypass AI access approval, compared with 33% of intermediate-level employees.

The result is a widening gap between written AI governance and what companies can see and control. Delinea found that only 41% of IT leaders said all AI tools and agents accessing company data are actively monitored. When an AI tool or agent went outside its intended scope, 55% said it took at least a day to detect the incident, while 30% said detection took four days or longer.

That suggests the next phase of enterprise AI governance may depend less on writing additional rules and more on whether organizations can enforce existing ones while an agent is working.

"Most organizations cannot confidently answer three questions: What agents are running in our environment? What can they access? What have they actually done?" said Delinea CEO Art Gilliland. "An agent can begin a session with legitimate access and drift into something it was never meant to do."

The full report is available for download here.

Featured

  • Neon blue security locks with a single red highlight

    With AI, Cybersecurity Focus Shifts from Finding Flaws to Fixing Them

    For decades, one of cybersecurity's biggest challenges has been finding vulnerabilities before attackers do. A growing number of security professionals now say artificial intelligence is changing that equation, shifting the focus from discovering flaws to fixing them quickly enough to prevent exploitation.

  • abstract smartphone translucent screen displaying AI interface

    Apple Unveils Redesigned Siri AI

    At its recent Worldwide Developers Conference, Apple announced Siri AI, a redesigned version of its voice assistant that Apple describes in its own announcement as "a profoundly more capable and personal assistant." The update is intended to make Siri more conversational, more context-aware, and more useful across iPhone, iPad, Mac, Apple Watch, and Vision Pro.

  • Blurred silhouettes of business people in a modern office with a glowing blue network overlay

    Open Secure AI Alliance Moving Under Linux Foundation

    Governance of the Open Secure AI Alliance has moved to the Linux Foundation, giving the initiative what the organizations describe as a neutral home for developing open source tools, shared standards and defensive practices. The Alliance was launched by NVIDIA in July to develop open security technologies for AI systems and agents.

  • Digital cloud security with protected data flow on a futuristic network background

    Security Researchers: Passkey Phishing Attacks Are Leading to Cloud Account Takeovers

    In an active social engineering campaign, cyber attackers are impersonating IT help desks and using fake passkey setup requests to compromise employee identities and gain access to enterprise cloud data.