Organizations Struggle to Enforce Access Controls After AI Agents Complete Tasks

A Delinea survey reveals that while 99.7 percent of IT and security leaders report having formal policies governing AI tool access to company data, fewer than 20 percent detect unauthorized data access in real time, and 76 percent of employees have bypassed approval processes to use AI tools. AI agents frequently retain active permissions to sensitive systems including customer records, financial data, and source code long after their assigned tasks conclude, creating persistent security risks. The gap between documented policies and actual enforcement remains a critical challenge as organizations struggle to monitor and control AI agent behavior.
Organizations face a fundamental mismatch between their documented AI governance frameworks and their actual capacity to enforce them. While nearly all IT leaders claim formal policies exist, the research demonstrates that most lack real-time detection capabilities—only about half actively monitor AI access against policy guidelines. The problem stems partly from how AI agents are deployed: they often inherit broad user permissions accumulated over years, retain access credentials long after completing specific tasks, and can be deployed by business teams without IT oversight. This creates multiple pathways for agents to access systems and data well beyond their intended scope.
The employee behavior data reveals additional enforcement challenges. Facing business pressures and tight deadlines, three-quarters of employees have bypassed formal approval processes to deploy AI tools on work systems. Additionally, 60 percent report feeling pressured to use AI with sensitive information despite uncertainty about whether such use is permitted. These gaps between policy and practice leave organizations vulnerable to both intentional misuse and unintended system damage.
This enforcement gap could expose organizations to significant operational and financial risks. Customers, employees, and partners whose data is stored in company systems may face privacy breaches or unauthorized data exposure. Competitors could gain access to proprietary source code or strategic information. Financial institutions and regulated industries face potential compliance violations and substantial penalties. The persistent nature of the problem—agents retaining access for extended periods while detection often takes days—may allow unauthorized access to compound before discovery, amplifying potential harm across multiple business domains.