Nearly every company now has an AI policy. What leaders are struggling with is that an AI agent can violate it faster than most organizations can enforce it.
In Delinea’s newest report, 87% of IT and security leaders say an AI tool or agent has already exceeded its intended scope in the past year. Three quarters say they know it happened, and the rest suspect it but can't prove otherwise. Not knowing is its own kind of answer.
99.7% of IT and security leaders say their organization has a formal policy governing what data AI tools can access, up from just 57% eight months ago. That's one of the fastest shifts we've tracked in enterprise security policy, but enforcement hasn't kept pace.
Only 51% of those same leaders check AI access against policy as it happens. The rest rely on periodic reviews, a one-time check at setup or nothing until an incident forces the question. Push further and it gets thinner: fewer than one in five organizations can catch a scope violation at the moment it occurs.
A policy nobody enforces with technical controls isn’t really a policy. It’s an honor system, and honor systems only work when everyone involved moves slowly enough for someone to notice a violation or the actors understand and respect the social contract. AI doesn’t move at that pace or have a conscience. An agent can query a database, call an API and chain ten more actions together before a person notices the first one all in the overwhelming intention of answering the question asked of it.
The employee data makes the disconnect even clearer. Forty-four percent of employees say they’ve personally used an AI tool that accessed more company data than it should have. A third of those never told anyone. Not because they were covering something up, but because they assumed that if it has access, it must have been allowed to do what it did.
IT sees a governed environment. The workforce is living in a different one and mostly isn’t aware there’s a difference.
A policy that exists as a document that IT can point to during an audit protects nothing if in the moment, or worst case after, it isn't possible to verify whether an agent is complying. Identity governance is the process of deciding if an agent should have access or not, but does nothing when an agent behaves outside of what was expected.
Most people using AI at work are trying to get things done faster, and most agents doing something unintended aren’t malicious. They’re just operating with more reach than anyone accounted for. The failure isn’t individual judgment. It’s the space between what the policy says and what the technology actually enforces.
That’s the AI enforcement gap. Closing it means moving control out of policy documents and access reports, and into the path of the action itself: checking what an identity is allowed to do, in the context of the request, before the action happens. For identity security, it’s no longer enough to decide whether an identity gets access. AI security requirers tools that enforce policy at the moment it matters.