Report by Delinea

2026 Identity Security Report The AI Enforcement Gap

10 FINDINGSPublished Sep 29, 2026
View Original Report →

Key Findings

76% of employees say they have bypassed the required approval process for using AI at some point.

Policy ComplianceEmployee BehaviorAI Usage

99.7% of organizations have a formal policy governing what data AI tools and agents can access.

Policy AdoptionAI GovernanceIdentity Security

About half of organizations check AI access against policy in real time.

Real-Time MonitoringPolicy EnforcementAI Governance

36% of IT leaders can always trace a sensitive AI access event back to a named human authorizer.

AccountabilityAuditabilityAI Governance

47% of organizations lack enforcement at the moment of action in at least two major environments.

Policy EnforcementInfrastructureCI/CD

87% of IT leaders say an AI tool or agent accessed sensitive data beyond its intended scope in the past year.

AI GovernanceData AccessIdentity Security

Fewer than one in five IT leaders can detect AI scope violation as it happens.

AI GovernanceSecurity Monitoring

60% of employees say they have felt pressured to use AI on sensitive or confidential data even when they were unsure it was permitted.

Employee BehaviorData PrivacyAI Usage

55% of organizations take a full day or longer to detect when an AI agent steps outside its scope.

DetectionIncident ResponseAI Governance

Nearly all organizations require named-individual approval for at least some sensitive AI use.

Approval ProcessesPolicy AdoptionAI Governance