
Identity security leaders are gaining clearer visibility into how AI agents interact with corporate systems, and the new picture shows persistent access long after a task ends. Delinea’s 2026 Identity Security Report: The AI Enforcement Gap documents how policies on paper rarely match what happens when an agent is connected to production data, leaving security teams to react after the fact rather than govern the moment an agent acts.
What does the report measure about AI policy enforcement?
99.7% of IT and security leaders said their organizations had a formal policy governing the data AI tools and agents could access. Yet 57% said policies were documented and enforced well enough for them to understand what data AI tools were permitted to access. About 51% of organizations check AI access against policy in real time, and fewer than one in five detected the most recent instance of access outside an agent’s intended scope as it happened.
The gap between written policy and real-time control is the defining finding: 99.7% of organizations had a formal policy on AI data access, but only 51% checked AI access against policy in real time, and fewer than one in five caught the most recent out-of-scope access as it happened.
How are employees handling AI access in practice?
60% of employees said they had felt pressured at work to use AI tools with sensitive or confidential information without knowing whether it was permitted. When business demands or deadlines require faster use of AI than governance processes allow, some employees do not know which steps to follow. Most employees know formal approval is required to access company data, applications or systems through AI tools, yet 76% said they had bypassed approval at some point to use these tools on work systems.
When approval paths are unclear, employees bypass the formal policy to meet deadlines. The report links this behaviour to an enforcement problem: tools connect to company systems while security teams lack a record of what was authorised or by whom.
Why do AI agents keep access after tasks end?
Companies give AI agents permissions that remain active after their work ends. This ongoing access allows tools to continue reaching company systems and data until permissions expire or someone revokes them. Business teams and employees sometimes grant access without IT or security approval. Tools may connect through a user’s work account, or employees may set up connections themselves. The data these tools access includes customer records, employee information, financial data, security logs, and source code.
Some organizations revoke permissions on a schedule or leave credentials active until an audit. Others rely on employees to disconnect tools. 42% of IT and security leaders said their organizations had no automatic way to remove AI access when a session ended. An active session may allow the tool to continue operating, making session termination part of the response to unauthorized access.
What permissions do AI agents inherit, and what risks follow?
Agents can inherit the permissions of the person who launches them. IT leaders reported using a user’s existing permissions to limit an agent’s access. These permissions may include privileges the employee accumulated over years, giving the agent access unrelated to its assignment. An agent can select tools and take a sequence of actions to reach a goal. Broad permissions allow it to take steps that were not anticipated when access was approved. Unintended actions can cause damage.
Where is enforcement weakest across the systems surveyed?
Software build and deployment pipelines and Kubernetes environments had the lowest reported levels of enforcement at the moment of action across the systems surveyed. Coding agents operating in these environments may be able to change applications and infrastructure. Respondents often reported taking a day or longer to detect the most recent instance of an AI tool or agent accessing data outside its intended scope. During that period, an agent may continue selecting tools and taking actions without human input. Some organizations can revoke credentials immediately and need additional time to end an agent’s session.
How hard is it to trace AI access back to a person?
Only 36% of IT respondents said they could always trace an AI access event involving sensitive data to the person who authorized it. Limited traceability makes it harder to establish why access was granted, what conditions applied, and who was responsible for the decision. These details help organizations investigate incidents and demonstrate that security rules were followed.
Employees were unsure which information was sensitive, and who was responsible for misuse.
What does effective enforcement look like?
The report points to several levers that close the gap between policy and runtime behavior. Real-time checks against policy, automatic revocation at session end, and consistent traceability back to a human approver are the three capabilities most often missing. Organizations that invest in these controls can answer, in the moment, which agent is acting, on whose authority, and within what scope of data. That visibility is what the report calls the AI enforcement gap, and closing it is the work the 2026 findings put in front of identity and security teams.
FAQ
What did the 2026 Identity Security Report find about AI agent access?
It found that 99.7% of organizations have a formal policy on AI data access, but only 51% check AI access against policy in real time, and fewer than one in five detected the most recent out-of-scope access as it happened.
Why do AI agents keep access after their work is done?
Permissions remain active until they expire or are revoked, and 42% of organizations have no automatic way to remove AI access when a session ends. Some agents also inherit the launching user’s accumulated privileges.
How difficult is it to trace AI access back to a person?
Only 36% of IT respondents said they could always trace an AI access event involving sensitive data to the person who authorized it, and some employees who saw an AI tool access more data than expected never reported it.
This article summarizes reporting from helpnetsecurity.com.
