AI agents keep data access after tasks end, Delinea finds
Organizations are writing policies for AI tools, but many cannot enforce them when an agent actually acts. That is the main finding of Delinea's 2026 Identity Security Report: The AI Enforcement Gap. The report describes AI agents that keep their permissions long after their work is finished.
The report surveyed IT and security leaders as well as employees. Identity security teams said they are worried about two things: the ongoing access AI agents have to company systems, and the actions these agents take on behalf of users.
"Written policy is only as good as your ability to enforce it at the moment an AI agent acts," said Art Gilliland, CEO of Delinea. "Our research echoes what I hear from leaders constantly: they have the AI policies in place, but they can't see or report on what their agents actually do."
