Nearly nine in 10 IT leaders surveyed by Delinea said an AI tool or agent accessed sensitive data beyond its intended scope during the past year, highlighting a widening gap between enterprise AI governance policies and organizations’ ability to enforce them.
AI policies are widespread, but enforcement lags
The research draws on two global surveys of 2,254 IT and security leaders and 2,250 non-IT employees at organizations with at least 500 employees that use AI. Respondents were based in the U.S., UK, Germany, Australia, Singapore, UAE, France, and India.
Delinea found that 99.7% of organizations have a formal policy governing what data AI tools and agents can access, but only about half check that access against policy in real time.
“Written policy is only as good as your ability to enforce it at the moment an AI agent acts,” said Art Gilliland, chief executive officer at Delinea.
“Our research echoes what I hear from leaders constantly: they have the AI policies in place, but they can’t see or report on what their agents actually do.”
Employees bypass AI approval processes
The report also found signs that employees are working around established governance processes:
- 76% of employees surveyed said they had bypassed required AI approval processes at some point.
- 48% said they always or regularly use AI tools without going through a formal approval process.
- 60% said they had felt pressured to use AI on sensitive or confidential data even when they were unsure whether it was permitted.
- 15% of those respondents said they felt that pressure frequently.
Delinea said the findings show that employees may still bypass established rules even when they understand how AI tools and agents are supposed to interact with company data, applications, and systems.
Runtime visibility remains a challenge
Accountability also remains limited, according to Delinea. Just 36% of IT leaders said they could always trace a sensitive AI access event back to a named human authorizer, despite nearly all surveyed organizations requiring named-individual approval for at least some sensitive AI use.
Across six environments examined in the report, 47% of organizations lacked enforcement at the point of action in at least two environments. Delinea identified CI/CD pipelines and Kubernetes as the environments with the weakest enforcement, while cloud data stores performed better but still showed gaps.
Detection can also be delayed after an AI agent exceeds its authorized scope. Delinea reported that 55% of organizations take at least a full day to identify such an event. For 30% of organizations, that detection window was four days or longer.
“For an AI agent capable of selecting tools and chaining actions without waiting for human input, even a day between an out-of-scope action and detection can leave a significant window for unintended activity,” Delinea said in its report.
Real-time AI access controls remain limited
The report also found that only one in three IT leaders said their organizations could both revoke an AI tool’s access and terminate an agent session in real time.
Mike Albrecht, associate director in the Risk Advisory Practice at CrossCountry Consulting, said the way AI agents operate makes traditional identity controls more difficult to apply.
“An AI agent decides what actions it’s going to take at runtime. Most times it evaluates its environment, selects tools and takes actions that aren’t necessarily specified in advance. That changes everything we do from an identity perspective because it’s not deterministic anymore.”
Delinea argues that organizations need to move beyond authorization at login and apply access controls when an AI agent takes an action.
Its platform uses continuous runtime authorization, least-privilege access controls, and session visibility across AI, human, and machine identities to track what was authorized and what an agent subsequently did.
What Delinea’s findings mean for MSPs and MSSPs
The findings suggest customers may need more support enforcing AI policies as tools and agents gain access to sensitive systems and data. That could increase demand for services around identity governance, privileged access, and runtime monitoring.
Auditability is another likely area of focus. Providers may be asked to help customers trace sensitive AI activity back to a named authorizer and maintain clearer records of what an agent was permitted to do.
As AI use expands, the challenge may shift from creating policies to enforcing them consistently across different environments. That gives MSPs and MSSPs a potential role in helping customers close the gap between governance requirements and technical controls.
Want to learn more about how MSPs and MSSPs are building offerings to address these challenges? Tune into Channel Insider: Partner POV and hear directly from leaders and practitioners.




