Delinea has released its 2026 Identity Security Report: The AI Enforcement Gap, highlighting a gap between AI governance policies and their practical enforcement across Indian enterprises.
The report found that 99 per cent of Indian organisations have a formal policy defining what data AI tools and agents can access. While this is accompanied by stronger reported enforcement than the global average, 84 per cent of respondents said an AI tool or agent had accessed sensitive data beyond its intended scope during the past year.
India also recorded higher levels of AI access to sensitive organisational information than global respondents. According to the report, 76 per cent of Indian organisations allow AI tools to access employee data, compared with 51 per cent globally. Similar differences were reported for customer information, financial records and source code.
Cynthia Lee, Vice President, APJ, Delinea, said Indian enterprises have made significant progress in establishing AI governance frameworks, but wider access to sensitive information means organisations need stronger controls beyond policy-making. She added that as data protection obligations take effect, organisations will need greater visibility into who authorised access, what an AI agent did and the reasons behind that access.
The research also found that confidence in compliance remains high despite reported incidents of AI overreach. About 98 per cent of Indian respondents said they were confident they could demonstrate compliant AI access to a regulator.
Another concern relates to persistent credentials. While 99 per cent of organisations said they treat AI agent credentials, including API tokens and MCP configuration files, as governed privileged credentials, 45 per cent reported that some of these credentials remain active until the next audit, even after the original task has ended.
The report further points to gaps in accountability. Although nearly all organisations require a named individual to approve AI access to a new sensitive data source, only 47 per cent said they could always trace a sensitive AI access event back to the person who authorised it.
Indian organisations reported faster detection and response to AI access violations than their global counterparts. Around 34 per cent said they detected their most recent scope violation while it was occurring, compared with 20 per cent globally. Nearly half also said they could immediately revoke both AI credentials and an active agent session, compared with 35 per cent globally.
However, enforcement remains challenging in development environments. Only 43 per cent of Indian organisations said they can enforce AI access controls at the point of action within CI/CD pipelines, while Kubernetes remains an area where India trails the global average.
Delinea said the findings underline the need to move from access controls applied primarily at login towards continuous, runtime authorisation. The company advocates least-privilege access and session visibility across AI, human and machine identities to help organisations monitor and establish accountability for AI-driven access to sensitive resources.
Send news announcements/press releases to:
jeevika@thefoundermedia.in
