- Delinea's 2026 Identity Security Report found nearly all surveyed leaders have an AI policy, but fewer can enforce it while an agent acts.
- Agents can inherit a user's permissions, and 42% of surveyed leaders had no automatic way to remove access when a session ended.
- Leaders should test whether they can end an agent's access, trace it to an approver and detect misuse quickly.
A written policy is a promise. Enforcement happens at one moment: when the agent acts. Delinea's 2026 Identity Security Report, titled "The AI Enforcement Gap," suggests many surveyed firms have made the promise and are still working on the moment.
Nearly all have a policy. Fewer can see what agents do.
Almost every leader surveyed said their organization has a formal rule on what data AI tools and agents may reach. Yet just 57% said their rules were written down and enforced well enough to know which data those tools could access.
Checking in real time is rarer still. About half of organizations, 51%, compare AI access with policy as it happens. Fewer than 20% caught the latest out-of-scope access while it was under way. Respondents often said a day or more passed before they noticed.
Delinea's chief executive, Art Gilliland, described a visibility problem. Leaders have written the rules, he said, but cannot report on what their agents do.
How access outlives the task
The report describes cases where agents keep their permissions after the work is done. Until the permission expires or a person revokes it, the agent can still reach systems and data.
Cleanup methods vary. Some firms revoke access on a timer. Some leave credentials in place until an audit. Others count on staff to disconnect tools.
A second problem is inheritance. An agent can start with the same access as the person who launched it. That person may hold privileges built up over years. The agent then reaches systems unrelated to its task.
An agent also picks its own tools and steps. With broad permissions, it can do things nobody expected when access was approved. Picture a contractor whose badge still opens every door months after the project ended. The agent differs in one way: it may keep acting without a person in the loop.
Revoking a credential is not the same as ending a session. Delinea notes that some organizations can pull credentials at once but need more time to stop an agent's live session. During that gap, the tool may keep running.
The people in the gap
Delinea also surveyed employees. Six in ten said they had felt pushed at work to use AI tools on sensitive or confidential material without knowing if that was allowed. Many were unsure what counts as sensitive and who would answer for misuse.
Some employees who saw a tool reach more data than expected said nothing. Security teams then miss a warning sign. The lesson here is that a rule people cannot follow at deadline speed is a rule they route around.
Where the risk concentrates
Respondents reported the weakest enforcement at the moment of action in two places. One is the pipelines that build and ship software. The other is Kubernetes, a system for running applications. A coding agent in those places may be able to change live applications and infrastructure.
The data in play ranges from customer and employee records to financial data, security logs and source code.
Weak tracing slows investigations. It also makes it harder to show auditors why access was granted and who decided.
What to ask your team
These figures come from a vendor survey of self-reported answers. The coverage does not give the sample size or method. Treat them as a prompt for internal checks, not a benchmark.
Ask five questions. Which AI agents hold access today, and who approved each one? What ends that access when the task finishes? Can we stop a live session, not just a credential? Does each agent get narrow permissions of its own, or the launcher's full set? How fast would we notice an agent acting outside its scope?
Start with build pipelines and Kubernetes, where reported enforcement was lowest. Give employees a fast approval path too, so deadlines do not push them around the rules.
A policy tells an agent what it should do. Only enforcement decides what it can do.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Help Net Security.





