Download the 2026 Identity Security Report, "The AI Enforcement Gap", to see where the gaps are and how to extend control from the point of access to the moment of action.
of organizations check AI access against policy in real time, and fewer than one in five can detect a scope violation as it happens
Inside the 2026 Identity Security Report
Nearly every company has an AI policy. Far fewer can enforce it when and where it matters. Employees are bypassing approval to use AI on company systems, AI agents are inheriting access they don’t need, and few organizations can trace sensitive AI access back to the person who authorized it.
Based on global research with more than 4,500 IT and security leaders and employees, The AI Enforcement Gap reveals a disconnect between AI governance on paper and how AI access actually works, and what organizations can do to close it.
- 99.7% of organizations have a formal AI data-access policy, but only 51% check AI access against policy in real time.
- 87% of IT and security leaders say an AI tool or agent has access sensitive data beyond what was required for its task in the past year.
- 76% of employees have bypassed formal approval to use AI tools, and 48% say they do so always or regularly.
- Only 36% can always trace sensitive AI access back to a human authorizer.