Report by Delinea
2026 Identity Security Report The AI Enforcement Gap
Key Findings
76% of employees say they have bypassed the required approval process for using AI at some point.
99.7% of organizations have a formal policy governing what data AI tools and agents can access.
About half of organizations check AI access against policy in real time.
36% of IT leaders can always trace a sensitive AI access event back to a named human authorizer.
47% of organizations lack enforcement at the moment of action in at least two major environments.
87% of IT leaders say an AI tool or agent accessed sensitive data beyond its intended scope in the past year.
Fewer than one in five IT leaders can detect AI scope violation as it happens.
60% of employees say they have felt pressured to use AI on sensitive or confidential data even when they were unsure it was permitted.
55% of organizations take a full day or longer to detect when an AI agent steps outside its scope.
Nearly all organizations require named-individual approval for at least some sensitive AI use.