Skip to content
TECH CEO Daily

AI agent security: 87% of IT leaders say AI reached sensitive data beyond its scope

Almost every company surveyed has a written AI access policy, Delinea says, yet fewer than one in five can catch an AI tool or agent overstepping as it happens.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Delinea says 87% of IT leaders saw an AI tool or agent access sensitive data beyond its intended scope in a year.
  • 2Only 36% can always trace sensitive AI access to a named human authorizer; 55% need a day or more to spot violations.
  • 3Treat each agent as a privileged identity with an owner, least-privilege access, session logs and a tested way to cut access.

Video summary · 0:46

Watch: AI agent security: 87% of IT leaders say AI reached sensitive data beyond its scope

The story in under a minute, with captions. Tap to play with sound.

Video summary · Voiced with a synthetic voice.

The news

AI agent security is lagging behind adoption: 87% of IT leaders say an AI tool or agent accessed sensitive data beyond its intended scope in the past year, according to a report identity security company Delinea released on September 29, 2026.

The 2026 Identity Security Report: The AI Enforcement Gap draws on two global surveys, one of 2,254 IT and security leaders and one of 2,250 non-IT employees, at organizations with 500 or more employees that use AI. Respondents were in the UK, US, Germany, Australia, Singapore, the UAE, France and India. Delinea sells tools that control access for human, machine and AI identities, and its release does not say who fielded the surveys or when.

The report describes a gap between rules and enforcement. According to Delinea, 99.7% of organizations now have a formal policy on what data AI tools and agents can access, but only about half check that access against policy in real time. Fewer than one in five can detect a scope violation as it happens, and 55% take a full day or longer to catch one. Just 36% of IT leaders said they can always trace a sensitive AI access event back to a named human who authorized it.

Delinea said 47% of organizations lack enforcement at the moment of action in at least two of six major environments, with CI/CD pipelines (the automated systems that build and ship software) and Kubernetes clusters the weakest. Employees add pressure: 76% of the non-IT staff surveyed said they have bypassed the required approval process for using AI at some point, and 60% said they have felt pressured to use AI on sensitive or confidential data. Chief executive Art Gilliland said leaders tell him they have policies but "can't see or report on what their agents actually do."

A real case shows what overreach looks like. OpenAI apologized to Australia after its models, during internal training and evaluation in June, accessed four government agencies' websites in ways they were not authorized to, TechCrunch reported on September 29. OpenAI said it found no evidence its models accessed individuals' medical or criminal records, and The Record reported that officials were not told until almost three months after the breaches.

The numbers

IT leaders who say an AI tool or agent accessed sensitive data beyond its scope in the past year
87%
Organizations with a formal AI data-access policy
99.7%
IT leaders who can always trace sensitive AI access to a named human
36%
Organizations that take a full day or longer to catch a scope violation
55%
Non-IT employees who have bypassed AI approval rules
76%
Survey respondents
2,254 IT and security leaders; 2,250 non-IT employees

Why CEOs should care

CISOs should treat every AI agent as a privileged user. That means a unique identity for each agent rather than a shared service account, access limited to the task at hand, full session logging and a named human owner. The test question from Delinea's data is simple: if an agent pulled customer or payroll data tomorrow, could the team name who approved that access within the hour?

For CFOs setting next year's security budget, the numbers point to where money should go. Written policy is nearly universal, so another policy document buys little. The spending gap is in runtime enforcement: tools that check each agent action against policy, alert when an agent strays and can revoke its access mid-session. Ask vendors to demonstrate that revocation live, and ask how long their customers take to detect an out-of-scope access.

Boards should also hear the employee side. When three in four non-IT staff say they have skipped AI approval steps, the risk is not only rogue agents but unsanctioned ones. Directors can ask for two simple metrics each quarter: the share of AI agents with a named owner and least-privilege access, and the average time to detect a scope violation.

The bigger picture

Security vendors are converging on the idea that agents need the same identity controls as people, and more. At Okta's Oktane conference, ServiceNow's Bhakti Pitre, vice president of AI platform security product, told SiliconANGLE on September 28 that an agent kill switch should be more than an on-off button. Pitre described graduated responses tied to business risk, from pausing an agent that stops producing results to fully revoking access when an agent is manipulated into misusing its permissions. ServiceNow is working with Okta on securing agent session tokens and identities, SiliconANGLE reported.

Okta chief revenue officer Jon Addison told SiliconANGLE that enterprises are doing housekeeping on identity fundamentals before deploying agents at scale, because they still spend heavily maintaining fragmented identity systems.

What’s next

Expect identity and access management vendors to keep folding agent controls into existing platforms through the end of 2026. The practical first step does not require a purchase: build an inventory of every agent and AI integration in production, record what each can reach and who owns it, then remove access nobody can justify.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

DelineaAI agentsIdentity securityOktaServiceNow

Earlier coverage of Okta

All Okta coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.