Skip to content

Security1 publisher2 min readPublished

Delinea survey finds about half of firms check AI access against policy in real time

Delinea's 2026 survey found 99.7% of IT and security leaders have a formal AI data policy, but only about 51% check AI access against it in real time. For responders, the shortfall comes after an agent starts acting: how fast out-of-scope access is seen, and how fast it is taken away.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Delinea survey finds about half of firms check AI access against policy in real time
Generated illustration

What happened

  • Fewer than one in five organizations caught their most recent case of AI access outside an agent's intended scope while it was happening.
  • Forty-two percent of IT and security leaders said their organizations had no automatic way to remove AI access when a session ended.
  • Agents can inherit the permissions of the person who launches them, including privileges that employee accumulated over years.
  • Build and deployment pipelines and Kubernetes environments had the lowest reported enforcement at the moment an agent acts.
  • Only 36% of IT respondents said they could always trace an AI access event involving sensitive data to the person who authorized it.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Coding agents in pipelines and clusters may be able to change applications and infrastructure, so an over-scoped one can alter the systems themselves as well as read data from them.
  • decision Teams that cap an agent at its user's existing rights now have a choice: draw the scope from the task, or let the agent carry every privilege that user has built up.
  • constraint Connections that business teams or employees set up without IT approval fall outside the revocation schedules and audits IT runs.
  • cost For the 64% of IT respondents who cannot always tie an AI access event to its authorizer, investigations lose the record of why access was granted and under what conditions.

Permissions granted to AI agents stay active after the work ends. The tool can keep reaching company systems and data until those permissions expire or someone revokes them [7]. Removal varies by organization. Some revoke on a schedule or leave credentials live until an audit, and others rely on employees to disconnect tools [8].

How far that leftover access reaches depends on whose rights the agent runs under [9]. An agent picks its own tools and chains actions toward a goal, so broad permissions let it take steps nobody anticipated when access was approved [10]. The data in reach includes customer records, employee information, financial data, security logs and source code [11].

Only 57% of leaders said their policies were documented and enforced well enough to tell them what data AI tools were allowed to reach [21]. Holding a policy and checking access against it in real time are about 49 percentage points apart [1]. Respondents often took a day or longer to find their most recent case of out-of-scope access [5]. In that window an agent may keep selecting tools and acting without human input [5].

Containment takes two steps [13]. Some organizations can revoke credentials immediately but need more time to end the agent's session, and an active session may let the tool keep operating [13].

The shortfalls point to three controls: access scoped to each task, removed automatically when the session ends, and checked at the moment the agent acts [9][6][3].

"Written policy is only as good as your ability to enforce it at the moment an AI agent acts," said Art Gilliland, CEO of Delinea [15]. "Our research echoes what I hear from leaders constantly: they have the AI policies in place, but they can't see or report on what their agents actually do," he said [16].

The figures come from Delinea's own survey of IT and security leaders and employees [1]. The published summary does not state a sample size or describe any attacker using an agent's retained access [1]. Leaders also reported or suspected that an AI tool or agent had reached sensitive data beyond what its task required in the past year [20]. Among employees, 76% said they had bypassed approval at some point to use AI tools on work systems [18]. Sixty percent said they had felt pressured to use AI with sensitive or confidential information without knowing whether it was permitted [17].

What to watch

  • Delinea releasing the sample size and respondent mix behind its 99.7% and 51% figures.
  • A disclosed intrusion that ran through an AI agent's retained or inherited credentials would move this from posture data to an exploited path.
  • Pipeline and Kubernetes tooling adding per-action checks for coding agents.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories