AI Agents Retain Unchecked Access to Company Data Post-Task, Delinea Report Finds
A new Delinea report reveals that while most organizations have AI policies, a significant gap exists in enforcement, allowing AI agents to retain access to sensitive company data long after their tasks are completed.

IT and security leaders are grappling with a critical challenge posed by the rapid adoption of AI agents: ensuring these autonomous systems do not retain unauthorized access to sensitive company data after their assigned tasks are finished. A recent report by Delinea, titled "The AI Enforcement Gap," highlights that while 99.7% of organizations have formal policies governing AI data access, a substantial majority struggle with effective enforcement, leading to potential identity security risks.
The research indicates a significant disconnect between policy creation and real-time enforcement. While most organizations document AI access policies, only about 51% actively check AI access against these policies in real time. Alarmingly, fewer than one in five organizations detected instances of AI agents accessing data outside their intended scope as they occurred. This lack of immediate oversight means that AI agents can continue to operate with existing permissions, potentially accessing and processing sensitive information without proper scrutiny.
Compounding the issue, employees often feel pressured to use AI tools with sensitive data to meet business demands, sometimes bypassing formal approval processes. The report found that 60% of employees felt pressured to use AI tools with confidential information, and 76% admitted to bypassing approval procedures at least once to use these tools on work systems. This behavior, driven by deadlines and a lack of clear guidance or governance, creates a fertile ground for policy violations and data exposure.
A core concern identified by Delinea is that AI agents are frequently granted permissions that remain active indefinitely or until explicitly revoked. This persistent access allows tools to connect to company systems and data long after their initial purpose has been served. Many organizations lack automated mechanisms to remove AI access once a session ends, with 42% of IT and security leaders reporting no automatic way to revoke permissions. This leaves a window for potential misuse or unintended data access.
Furthermore, AI agents can inherit the broad permissions of the user who initiates them. This means an agent might gain access to privileges accumulated by an employee over years, granting it capabilities far beyond its intended operational scope. When an agent can select tools and take a sequence of actions to achieve a goal, these broad permissions can enable unanticipated steps, potentially leading to significant damage or data breaches.
Visibility into AI actions remains a significant hurdle for security teams. Many organizations have limited insight into what AI agents do once connected, with monitoring often covering only a subset of tools. Detection of unauthorized AI activity can take days, during which an agent might continue to operate without human intervention. This lack of real-time monitoring and slow detection times create substantial security blind spots.
Traceability of AI access events is also a major challenge. Only 36% of IT respondents reported being able to consistently trace an AI access event involving sensitive data back to the individual who authorized it. This limited traceability hinders incident investigations, makes it difficult to establish accountability, and complicates efforts to demonstrate compliance with security protocols. Employees also express uncertainty about what constitutes sensitive information and who is responsible for its improper use.
The findings underscore an urgent need for organizations to bridge the gap between AI policy development and robust enforcement mechanisms. Without real-time monitoring, automated access revocation, and clear accountability frameworks, the increasing reliance on AI agents poses a significant and growing threat to data security and identity protection.