Back to News
RSS feeddelinea.com

AI Enforcement Gap Leaves Organizations Struggling to Control Access

Summary

Delinea’s 2026 Identity Security Report examines the gap between formal AI governance and how organizations control access in practice. Based on research involving more than 4,500 IT and security leaders and employees, it finds that 99.7% of organizations have a formal AI data-access policy, but only 51% check AI access against policy in real time. Fewer than one in five organizations can detect a scope violation as it happens. The report says 87% of IT and security leaders saw an AI tool or agent access sensitive data beyond what its task required during the past year. It also finds that 76% of employees have bypassed formal approval to use AI tools, with 48% saying they do so always or regularly. Only 36% of respondents say they can always trace sensitive AI access back to a human authorizer. The report frames these findings as evidence that organizations need controls covering both the point of access and the actions taken afterward.