Survey Identifies Data Governance Enforcement Gap for Agentic AI Tools

According to a new survey from identity security company Delinea, 99.7% of IT and security leaders said their organization has a formal policy governing what data AI tools and agents are permitted to access. Yet only about 51% said AI access is checked against those policies in real time. Perhaps more worrying is that only 19% said their organization could detect in real time when an agent last accessed data outside its intended scope.

That disconnect is at the center of Delinea's fall 2026 Identity Security Report, "The AI Enforcement Gap," which suggests companies have made quick progress establishing AI governance but have not necessarily built the technical controls needed to enforce it.

The findings come from a pair of surveys covering 2,254 IT and security leaders and 2,250 non-IT employees at organizations with at least 500 employees across the U.S, U.K, Germany, Australia, Singapore, UAE, France, and India.

All the organizations were using or piloting AI, while the employees surveyed used at least one AI tool for work.

AI Agents Complicate the Permissions Problem

The problem becomes more consequential as companies move from AI tools that primarily respond to users toward agents capable of taking actions on their behalf.

Eighty-seven percent of IT and security respondents said their organization had experienced or suspected of an incident during the past year in which an AI tool or agent accessed sensitive information beyond what was required for its task.

Delinea's research also suggests companies are giving agents access that can persist longer than necessary. Only 58% of IT and security leaders said they have mechanisms that automatically revoke or expire AI access when a session ends, and those controls do not necessarily cover every agent or tool. Forty-two percent said many agent credentials remain active until an audit.

Agents also are not always receiving their own narrowly defined permissions. Half of IT leaders said their organizations use the employee's existing permissions as a boundary for what an agent can access. That can effectively hand an agent years of accumulated access belonging to the person who launched it.

That is particularly significant because an AI agent does not necessarily behave like a traditional service account. A service account typically performs a predefined process, while an agent can choose different tools, actions and sequences at runtime depending on the situation.

"Service accounts run fixed scripts," said Mike Albrecht, associate director in the Risk Advisory Practice at Cross Country Consulting. "An AI agent decides what actions it's going to take at runtime."

Employees aren't Always Waiting for Approval

The enforcement problem is not limited to autonomous agents.

The researchers found that 76% of employees surveyed had bypassed formal approval at some point to use AI tools with company data, applications or systems. And 48% said they always or extensively use AI tools without going through formal approval.

Meanwhile, 60% said they had felt pressure to use AI with sensitive or confidential information even when they were not sure doing so was permitted.

Executives were particularly likely to circumvent the process. Eighty-one percent of C-level respondents said they always or regularly bypass AI access approval, compared with 33% of intermediate-level employees.

The result is a widening gap between written AI governance and what companies can see and control. Delinea found that only 41% of IT leaders said all AI tools and agents accessing company data are actively monitored. When an AI tool or agent went outside its intended scope, 55% said it took at least a day to detect the incident, while 30% said detection took four days or longer.

That suggests the next phase of enterprise AI governance may depend less on writing additional rules and more on whether organizations can enforce existing ones while an agent is working.

"Most organizations cannot confidently answer three questions: What agents are running in our environment? What can they access? What have they actually done?" said Delinea CEO Art Gilliland. "An agent can begin a session with legitimate access and drift into something it was never meant to do."

The full report is available for download here.

Featured