
Enterprise AI adoption has moved faster than the governance designed to contain it. That much is understood. What Delinea’s 2026 Identity Security Report makes uncomfortably concrete is how wide that gap has become — and how consistently organisations on both sides of it are underestimating the exposure.
The report surveyed over 4,500 respondents across two distinct groups: IT and security leaders, and the non-IT employees who actually spin up enterprise AI tools day to day. The contrast between what each group believes is happening is the report’s most important finding.
Two organisations, One security problem
On the IT side, 99.7% of leaders say a formal AI data-access policy exists at their organisation. On the employee side, 30% aren’t sure a policy exists or cannot describe what it covers. IT says 19% of employees find workarounds without formal approval. Employees report the actual figure is 41%. IT says 96% could demonstrate to a regulator that AI stays within enforced boundaries. Meanwhile, 44% of employees say they’ve used AI tools that accessed more information than expected — and one in three of those never reported it.
These are not marginal discrepancies. They describe two organisations operating with fundamentally different pictures of the same risk environment.
The enforcement gap is structural
76% of employees say they have bypassed IT approval to use AI tools. 48% say they do so always or regularly. The reasons are not recklessness — they are systemic. When business deadlines require AI tools to move faster than governance processes allow, fewer than two in five employees say they’ll stick to the approved path. An aggregate of 36% of respondents cite friction in the governed path itself — IT or legal is too slow, approved tools aren’t effective enough, or governance rules are simply unclear.
When the compliant route is harder than the workaround, the workaround wins. That is not a culture problem. It is a design problem.
The report also surfaces a finding that should concern CIOs directly: the biggest shadow AI risk sits in the C-suite. 81% of C-level executives bypass AI access approval always or regularly, compared to 33% of intermediate staff. Despite having the highest awareness of any group that approval is required, executives are nearly three times more likely than intermediates to use unapproved AI because IT or legal responds too slowly.
AI agents add a layer of governance
Beyond human behaviour, the report identifies a deeper structural issue: AI agents are creating a new category of standing privilege that most identity programmes are not equipped to handle.
87% of IT leaders confirm that an AI tool or agent accessed sensitive data beyond what the task required in the past year. Yet only 19% were able to detect a scope violation in real time. For 55% of organisations, when an AI tool last accessed out-of-scope data, it took a full day or longer to detect. For 30%, that detection window stretched to four days or more.
The data AI agents touch is not trivial. Employee data, customer data, financial records, security logs, legal and compliance information — all appear among the most commonly accessed categories. And 42% of IT organisations have no automatic mechanism to revoke agent access when a session ends. Credentials, in many cases, remain live until manually disconnected or until an audit catches them.
This is the enforcement gap in its most consequential form. Organisations are checking access at the door, then losing visibility entirely once an agent is inside the system.
What CIOs need to act on
The report’s recommendations centre on a principle that identity security programmes have long accepted for human accounts but have not yet extended to agentic ones: scope authority to the task, and extend authorisation beyond the point of access to the moment of action.
For CIOs, the practical translation is clear. Policies alone do not constitute governance. Real-time enforcement, just-in-time access, and runtime authorisation — the ability to evaluate and act on what an agent is doing, not just what it was permitted to do at login — are what the agentic environment actually demands. The EU AI Act’s enforcement deadline in December 2027 moves audit capability for AI-initiated activity from best practice to legal requirement. The window to close the enforcement gap before that deadline is narrower than most organisations currently appreciate.
