Nearly nine out of 10 IT leaders reported that an AI tool or agent accessed sensitive data beyond what it was supposed to during the past year, according to research published by Delinea, a cybersecurity firm. The findings point to a growing disconnect between the AI governance policies that enterprises have written and their ability to actually enforce those rules. The research drew on two global surveys covering 2,254 IT and security leaders and 2,250 non-IT employees at organizations with at least 500 workers that use AI, spanning the U.S., UK, Germany, Australia, Singapore, UAE, France, and India.
The study found that 99.7% of organizations have a formal policy dictating what information AI tools and agents can access, but only about half verify that access against policy as it happens. Three-quarters of employees surveyed said they had sidestepped required AI approval processes at some point, while 48% said they always or regularly use AI tools without going through formal approval. Sixty percent said they had felt pressure to use AI on sensitive or confidential information even when they weren't sure whether it was allowed, with 15% of those respondents saying they felt that pressure frequently. Accountability also remains constrained: just 36% of IT leaders said they could always trace a sensitive AI access event back to a specific human who authorized it, despite nearly all surveyed organizations requiring named-individual approval for at least some sensitive AI use.
Detection delays compound the problem. Fifty-five percent of organizations take at least a full day to spot when an AI agent has exceeded its authorized limits, and for 30% of organizations, that detection window stretches to four days or longer. Across six environments examined in the study, 47% of organizations lacked enforcement at the point of action in at least two environments, with CI/CD pipelines and Kubernetes showing the weakest enforcement. Only one in three IT leaders said their organizations could both revoke an AI tool's access and end an agent session in real time. "Written policy is only as good as your ability to enforce it at the moment an AI agent acts," said Art Gilliland, chief executive officer at Delinea.
The report argues that the way AI agents operate makes traditional identity controls harder to apply, since an agent decides what actions to take at runtime rather than following a predetermined script. For an AI agent capable of selecting tools and chaining actions without waiting for human input, even a day between an out-of-scope action and detection can leave a significant window for unintended activity, according to the study. Delinea contends that organizations need to shift from authorization at login to applying access controls when an AI agent actually takes an action, using continuous runtime authorization and least-privilege access controls.
The findings suggest that as AI tools and agents gain access to sensitive systems and data, customers may need more help enforcing policies rather than simply writing them. That could drive demand for services around identity governance, privileged access, and runtime monitoring, with auditability emerging as another likely focus area. Providers may be asked to help customers trace sensitive AI activity back to a named authorizer and keep clearer records of what an agent was permitted to do, particularly as the challenge shifts from creating policies to enforcing them consistently across different environments. The enforcement gap creates an opening for managed service providers to help customers align governance requirements with technical controls that actually work when an AI agent acts. Organizations that treat AI governance as a compliance checkbox rather than an operational discipline risk discovering breaches long after the damage is done, while vendors able to demonstrate real-time visibility and control may find themselves fielding calls from boards anxious to close the gap before regulators arrive.

