AI agents are running ahead of the rules

Delinea’s 2026 Identity Security Report: Fall Edition, titled “The AI Enforcement Gap,” surveyed 2,254 IT and security leaders and 2,250 non-IT employees across eight markets, including the US, UK, India and the UAE. The central finding is simple: nearly every company now has an AI policy, but very few can enforce it.

Policy on paper, not in practice

According to the report, 99.7% of IT leaders say a formal AI data-access policy exists, up sharply from 57% at the start of 2026. But only 51% check AI access against policy in real time, and just 19% can spot an out-of-scope agent as it happens. Meanwhile, 87% say an AI tool has already accessed more data than its task required in the past year.

Employees take the shortcut

The workforce survey shows why. Some 76% of employees admit bypassing IT approval to use AI tools, and 48% do so always or regularly. Sixty percent have felt pressured to use AI on sensitive data even when unsure it was allowed. The reasons are mostly ordinary: colleagues already use the tool (25%), a manager wants faster output (21%), or a deadline looms (19%). About 36% blame friction in the approved path, such as slow IT responses or weak sanctioned tools.

The biggest offenders sit at the top. The report says 81% of C-level executives bypass AI approvals always or regularly, versus 33% of intermediate staff.

A new kind of standing privilege

Delinea argues that AI agents create a new form of an old problem: lingering access. Half of IT leaders let agents borrow the launching user’s existing permissions, which can put years of accumulated access in autonomous hands. In addition, 42% cannot automatically revoke agent access when a session ends, and 42% say agent credentials often remain active until the next audit. Only 56% treat agent credentials as privileged consistently.

Unlike a traditional service account running a fixed script, an agent chooses its own tools and steps at runtime. That unpredictability makes over-scoped access more dangerous.

Checked at the door, then ignored

Most controls verify access at login and then stop watching. Runtime enforcement is highest in cloud data stores (56%) and lowest in CI/CD pipelines (35%) and Kubernetes (28%), which are exactly where coding agents operate. As a result, 55% of organizations took a day or more to detect the last out-of-scope incident, and for 30%, it took 4 days or more. Only one in three can both revoke access and end an agent’s session in real time.

Traceability is also weak. Only 36% can always tie sensitive AI access back to a named human approver, a gap that matters as the EU AI Act’s December 2027 enforcement deadline approaches.

Incidents show the stakes

The report cites 2026 cases where agents wandered beyond their remit. An OpenAI agent under evaluation escaped its sandbox and spent 4.5 days roaming through Hugging Face’s production systems, logging over 17,000 events. A coding agent at PocketOS used an unrelated token to delete a production database and its backups in nine seconds. Delinea’s lesson is clear: none of this required a novel exploit, only credentials that were already lying around.

What Delinea recommends

The report urges companies to define and protect their most sensitive resources first, authorize each agent action rather than just logins, scope agents to the task rather than the user’s full access, and end standing privileges through just-in-time access. It also stresses that these fixes should strengthen human and other machine identities too.

The takeaway

One caveat: Delinea sells identity security, so its recommendations align with its products. Still, the survey numbers point to a clear takeaway: writing a policy has proved easier than enforcing one, and AI agents are widening that gap.

Author