Delinea announced its fall 2026 Identity Security Report: The AI Enforcement Gap on September 29, 2026. Its findings highlight weaknesses in access enforcement, monitoring and accountability, rather than proving that autonomous agents inevitably defeat enterprise security.
Policies are not the same as controls
Delinea’s research combines surveys of 2,254 IT and security leaders and 2,250 non-IT employees at organizations with at least 500 employees. The eight countries covered were the United States, United Kingdom, Germany, Australia, Singapore, United Arab Emirates, France and India.
Redmond reports that participating organizations were using or piloting AI, and employee respondents used at least one AI tool for work. Its account says 87% of IT and security respondents had experienced or suspected an incident in the preceding year involving sensitive-data access beyond what an AI task required. That is not a verified breach rate.
Delinea says fewer than one in five respondents can detect a scope violation as it happens. Its report page also identifies an accountability gap: only 36% of IT leaders can always connect sensitive AI access to a human authorizer.
The practical distinction is important. Knowing that an agent has permission to begin work is different from establishing that each subsequent action remains appropriate. That is an interpretation of the reported enforcement gap—not a claim that the survey tested individual security architectures.
Permissions can outlive the task
Redmond’s reporting identifies three additional access-management concerns:
- 58% of IT and security leaders reported mechanisms that automatically revoke or expire AI access when sessions end, without necessarily covering every tool.
- 42% said many agent credentials remain active until an audit.
- About half use employees’ existing permissions as the boundary for agent access.
The first two figures should not be treated as complementary categories. Having an expiration mechanism somewhere does not establish that every agent’s credentials expire.
The inherited-permissions finding raises a useful administrative question: does an agent need everything its launching employee can reach, or only the resources required for this assignment?
Cross Country Consulting’s Mike Albrecht, quoted by Redmond, distinguishes predefined service-account processes from agents that choose actions at runtime. That is useful context, not a universal definition of either technology.
Employees are bypassing approval
Delinea reports that 76% of surveyed employees had bypassed formal AI approval at some point, while 48% said they did so always or regularly. Separately, 60% said they had felt pressure to use AI with sensitive or confidential information despite uncertainty about permission.
Redmond reports a pronounced seniority split: 81% of C-level respondents always or regularly bypassed approval, compared with 33% of intermediate-level employees. It also reports that only 41% of IT leaders said every AI tool and agent accessing company data was actively monitored; 30% said detecting out-of-scope access took four days or longer.
These responses suggest that improving approval workflows deserves attention alongside technical controls. A sensible review would ask whether approved routes are clear, usable and consistently followed—including by executives. Another policy document alone is unlikely to answer those questions.
Developer environments warrant attention
Delinea’s announcement adds a finding beyond the headline policy figures: across six environments, 47% of organizations reported lacking action-time enforcement in at least two. CI/CD pipelines and Kubernetes were the weakest environments; cloud data stores performed best, but still showed gaps. Delinea also confirms that 55% reported detection delays of a full day or longer.
For administrators, that suggests an AI-access review should extend beyond employee-facing chat tools into development and infrastructure workflows.
Turn the findings into an operational review
The following questions translate the findings into a practical review agenda; they are not a product-specific implementation guide or a guarantee against incidents:
- Inventory: Which agents are running, and who owns each one?
- Scope: Which data, applications and actions can each agent reach?
- Authorization: Are permissions tailored to the task, or inherited broadly?
- Expiration: What removes access when work ends—and what exceptions remain?
- Accountability: Can sensitive activity be tied to an agent, task and human approver?
- Detection: Can a controlled, out-of-scope test produce a timely alert and an investigable record?
Ask for evidence, not simply a “yes” beside each control. A policy is a statement of intent; a demonstrated denial, expiration event or attributable activity record is a stronger basis for assessing implementation.
A warning signal, not a universal verdict
Delinea sells identity-security products and recommends runtime authorization, least-privilege access and session visibility. Its commercial interest should remain visible when interpreting its conclusions. The public announcement and report page do not disclose enough sampling and weighting detail to establish global representativeness.
The useful takeaway is therefore narrower—and more actionable—than “AI agents outrun security.” Organizations should be able to demonstrate what agents can access, what they actually did, who authorized sensitive activity and when access ends. Start there before adding another layer of paperwork.
References
- AI Agents Are Outrunning Enterprise Security Controls Redmondmag.com · 2026-09-30T18:33:25
- 2026 Identity Security Report: The AI Enforcement Gap delinea.com
- AI Policy Enforcement Report: The AI Enforcement Gap delinea.com