Skip to content
The AI-First Web

Delinea survey: 42% of leaders cannot end AI agent access automatically

Nearly all surveyed security leaders say their firm has an AI policy. Far fewer can enforce it as agents act.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Delinea survey: 42% of leaders cannot end AI agent access automatically

AI-generated image for WebPulse. About our images

In brief
  • Delinea's 2026 Identity Security Report found nearly all surveyed leaders have an AI policy, but fewer can enforce it while an agent acts.
  • Agents can inherit a user's permissions, and 42% of surveyed leaders had no automatic way to remove access when a session ended.
  • Leaders should test whether they can end an agent's access, trace it to an approver and detect misuse quickly.

A written policy is a promise. Enforcement happens at one moment: when the agent acts. Delinea's 2026 Identity Security Report, titled "The AI Enforcement Gap," suggests many surveyed firms have made the promise and are still working on the moment.

99.7%
IT and security leaders who said their organization has a formal AI data policy
Source: Delinea, 2026 Identity Security Report, as reported by Help Net Security (October 2, 2026)

Nearly all have a policy. Fewer can see what agents do.

Almost every leader surveyed said their organization has a formal rule on what data AI tools and agents may reach. Yet just 57% said their rules were written down and enforced well enough to know which data those tools could access.

Checking in real time is rarer still. About half of organizations, 51%, compare AI access with policy as it happens. Fewer than 20% caught the latest out-of-scope access while it was under way. Respondents often said a day or more passed before they noticed.

Delinea's chief executive, Art Gilliland, described a visibility problem. Leaders have written the rules, he said, but cannot report on what their agents do.

How access outlives the task

The report describes cases where agents keep their permissions after the work is done. Until the permission expires or a person revokes it, the agent can still reach systems and data.

Cleanup methods vary. Some firms revoke access on a timer. Some leave credentials in place until an audit. Others count on staff to disconnect tools.

42%
Surveyed leaders with no automatic way to remove AI access when a session ends
Source: Delinea, 2026 Identity Security Report, as reported by Help Net Security (October 2, 2026)

A second problem is inheritance. An agent can start with the same access as the person who launched it. That person may hold privileges built up over years. The agent then reaches systems unrelated to its task.

An agent also picks its own tools and steps. With broad permissions, it can do things nobody expected when access was approved. Picture a contractor whose badge still opens every door months after the project ended. The agent differs in one way: it may keep acting without a person in the loop.

Revoking a credential is not the same as ending a session. Delinea notes that some organizations can pull credentials at once but need more time to stop an agent's live session. During that gap, the tool may keep running.

The people in the gap

Delinea also surveyed employees. Six in ten said they had felt pushed at work to use AI tools on sensitive or confidential material without knowing if that was allowed. Many were unsure what counts as sensitive and who would answer for misuse.

76%
Employees who said they had bypassed approval at some point to use AI tools on work systems
Source: Delinea, 2026 Identity Security Report, as reported by Help Net Security (October 2, 2026)

Some employees who saw a tool reach more data than expected said nothing. Security teams then miss a warning sign. The lesson here is that a rule people cannot follow at deadline speed is a rule they route around.

Where the risk concentrates

Respondents reported the weakest enforcement at the moment of action in two places. One is the pipelines that build and ship software. The other is Kubernetes, a system for running applications. A coding agent in those places may be able to change live applications and infrastructure.

The data in play ranges from customer and employee records to financial data, security logs and source code.

36%
IT respondents who said they could always trace an AI access event on sensitive data to the person who authorized it
Source: Delinea, 2026 Identity Security Report, as reported by Help Net Security (October 2, 2026)

Weak tracing slows investigations. It also makes it harder to show auditors why access was granted and who decided.

What to ask your team

These figures come from a vendor survey of self-reported answers. The coverage does not give the sample size or method. Treat them as a prompt for internal checks, not a benchmark.

Ask five questions. Which AI agents hold access today, and who approved each one? What ends that access when the task finishes? Can we stop a live session, not just a credential? Does each agent get narrow permissions of its own, or the launcher's full set? How fast would we notice an agent acting outside its scope?

Start with build pipelines and Kubernetes, where reported enforcement was lowest. Give employees a fast approval path too, so deadlines do not push them around the rules.

A policy tells an agent what it should do. Only enforcement decides what it can do.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Help Net Security.

Share this insight