AI agents keep data access after tasks end, Delinea finds

AI agents keep data access after tasks end, Delinea finds

Organizations are writing policies for AI tools, but many cannot enforce them when an agent actually acts. That is the main finding of Delinea's 2026 Identity Security Report: The AI Enforcement Gap. The report describes AI agents that keep their permissions long after their work is finished.

The report surveyed IT and security leaders as well as employees. Identity security teams said they are worried about two things: the ongoing access AI agents have to company systems, and the actions these agents take on behalf of users.

"Written policy is only as good as your ability to enforce it at the moment an AI agent acts," said Art Gilliland, CEO of Delinea. "Our research echoes what I hear from leaders constantly: they have the AI policies in place, but they can't see or report on what their agents actually do."

Policies exist, enforcement lags

Almost every respondent, 99.7% of IT and security leaders, said their organization had a formal policy on which data AI tools and agents may access. These leaders also reported or suspected that an AI tool or agent had reached sensitive data beyond what its task needed during the past year.

Only 57% said their policies were documented and enforced clearly enough to tell what data AI tools were allowed to touch. About 51% check AI access against policy in real time. Fewer than one in five caught the most recent case of an agent going outside its intended scope while it was happening.

Employees describe the same gap. Sixty percent said they had felt pressure at work to use AI tools with sensitive or confidential information without knowing whether this was allowed. When deadlines push AI use faster than governance processes can keep up, some staff do not know which steps to take. Most know that formal approval is required to connect AI tools to company data, applications or systems. Still, 76% admitted they had skipped that approval at some point.

Permissions that outlive the task

Agents often receive permissions that stay active after the job ends. They can keep reaching systems and data until the access expires or someone revokes it.

Access is sometimes granted by business teams or individual employees without IT or security sign-off. Tools may connect through a user's work account, or employees set up the connections themselves. The data involved includes customer records, employee information, financial data, security logs and source code.

Cleanup practices vary. Some organizations revoke permissions on a schedule, others leave credentials active until an audit, and some rely on employees to disconnect tools. Forty-two percent of IT and security leaders said they had no automatic way to remove AI access when a session ended.

Agents can also inherit the permissions of the person who launches them. IT leaders said they use a user's existing permissions to limit an agent's reach, but those permissions may include privileges collected over years. An agent can choose tools and chain actions to reach a goal, so broad access lets it take steps nobody expected when access was approved. Those unintended actions can cause damage.

Limited visibility and slow detection

Monitoring often covers only some tools, leaving individual actions unchecked. Build and deployment pipelines and Kubernetes environments had the lowest reported enforcement at the moment of action. Coding agents working there may be able to change applications and infrastructure.

Respondents often needed a day or more to detect the most recent case of out-of-scope access. During that time, an agent may keep acting without human input. Some organizations can revoke credentials immediately but need more time to end an active session, which may let the tool keep running.

Traceability is weak too. Only 36% of IT respondents said they could always trace an AI access event involving sensitive data back to the person who authorized it. Employees were unsure what counts as sensitive, whether their tools could reach it, and who would be accountable. Some who saw a tool access more than expected never reported it.

Our Take

The numbers suggest that AI governance has become a paperwork exercise in many organizations: the policy exists, but the controls at the point of action do not. For defenders, the familiar identity problems of standing privileges, orphaned credentials and permission creep now apply to software that acts on its own.

This fits a pattern we have covered recently, from AI agents leaking screenshots to flaws that let attackers hijack Salesforce Agentforce. Agents with broad, lasting access widen the impact when something goes wrong.

It is worth watching whether organizations move toward task-scoped, automatically expiring credentials for agents, and whether CI/CD pipelines and Kubernetes get stronger enforcement. The high rate of bypassed approvals also indicates that controls may need to be easier to follow, not just stricter.