84% of Indian Enterprises Say AI Overstepped Its Access, Despite Strong Policy

Delinea has published a new report, the 2026 Identity Security Report: The AI Enforcement Gap, examining where AI governance breaks down in practice. Among Indian organizations, 99% report having a formal policy governing what data AI tools and agents can access. Yet 84% say an AI tool or agent accessed sensitive data beyond its intended scope in the past year.

Strong Policy, Weaker Control

By most measures, India’s AI governance maturity actually exceeds global levels. 87% of Indian organizations say their AI data access policy is actively enforced, compared with 71% globally. But that stronger enforcement sits alongside far broader access. 76% of Indian organizations say AI tools can reach employee data, compared with 51% globally, and the gap is similarly wide for customer data, financial records, and source code.

Put together, this creates what Delinea calls an AI enforcement gap: standing access broad enough that AI agents can overreach, even inside organizations that believe their policies are working.

Cynthia Lee, Vice President, APJ at Delinea, framed the disconnect directly. India’s enterprises have done the hard work on AI governance. Almost every organization has a policy, and most enforce it more rigorously than their global peers, she said. But AI agents here also reach more customers, employees and financial data than the global average. At that point, a policy alone stops being enough. As DPDP obligations take effect, Indian enterprises will be asked to prove what actually happened: who authorized each access, what the agent did and why it was allowed.

Three Gaps Behind the Numbers

The report points to three specific places where confidence outpaces actual control.

Confidence is running ahead of control: 98% of organizations say they’re confident they could demonstrate compliant AI access to a regulator, despite how widely AI overreach was reported in the same survey.

Standing access hides behind the policy: 99% say they treat AI agent credentials, like API tokens and MCP configuration files, as governed privileged credentials. Yet 45% admit some of those credentials stay active until the next audit, well after the task they were originally issued for has ended.

Accountability is thin: nearly every organization requires a named individual to approve AI access to a new sensitive data source. Yet only 47% can always trace a sensitive AI access event back to that specific person.

India Catches Problems Faster, But Has a Blind Spot in Execution

Indian organizations do detect AI overreach faster than their global peers. 34% caught their most recent scope violation as it happened, compared with 20% globally, and nearly half could immediately revoke both an AI tool’s credentials and an active agent session, compared with 35% globally.

The blind spot sits in the environments where coding agents do the most active work. Only 43% of organizations can enforce AI access at the point of action within CI/CD pipelines. Kubernetes stands out as the one environment where India actually trails the global average.

What Closing the Gap Would Require

According to the report, closing this gap means authorizing AI access at the moment of action, not just at login. Delinea’s own approach applies continuous, runtime authorization with least-privilege scoping and full session visibility across AI, human, and machine identities, aiming to give security teams a defensible record of who authorized each access, what the agent did, and why it was allowed.

Latest articles

Related articles