Srinagar, Sep 30: Nearly 84% of Indian organisations say an AI tool or agent accessed sensitive data beyond its intended scope in the past year, even as almost all of them have formal policies governing what AI can access, a new report by identity security company Delinea has found.
The findings highlight a gap between having rules for AI systems and enforcing those rules when the technology is actually in use.
According to Delinea’s 2026 Identity Security Report: The AI Enforcement Gap, 99% of Indian organisations surveyed said they have a formal policy governing the data AI tools and agents can access. Yet 84% reported at least one instance of AI accessing sensitive information beyond its authorised scope.
India also reported higher levels of AI governance than the global average on several measures. About 87% of Indian organisations said their AI data-access policies are actively enforced, compared with 71% globally.
But Indian companies also give AI systems access to substantially more sensitive information. For example, 76% said AI tools can access employee data, compared with 51% globally. Similar gaps were reported for customer data, financial records and source code.
Policies meet reality
The result, the report suggests, is that organisations may have policies in place without sufficiently controlling what AI systems can actually reach once they are operating.
“India’s enterprises have done the hard work on AI governance. Almost every organization has a policy, and most enforce it more rigorously than their global peers,” said Cynthia Lee, vice president, APJ, Delinea.
“But AI agents here also reach more customers, employees and financial data than the global average. At that point, a policy alone stops being enough,” Lee said.
The report also found a disconnect between confidence and the ability to prove what happened when an AI system accessed sensitive information.
Some 98% of Indian organisations said they were confident they could demonstrate compliant AI access to a regulator. But only 47% said they could always trace a sensitive AI access event back to the individual who had approved it.
The study found another potential weakness in AI credentials. While 99% of respondents said they treat credentials used by AI agents—including API tokens and MCP configuration files—as governed privileged credentials, 45% said some such credentials remain active until the next audit, even after the task for which they were issued has ended.
That creates the possibility of what the report describes as “standing access”—permissions that remain available after they are no longer needed.
Faster detection, uneven control
Indian organisations did report some stronger operational controls than their global counterparts. About 34% said they detected their most recent AI scope violation while it was happening, compared with 20% globally. Nearly half said they could immediately revoke both an AI tool’s credentials and an active agent session, compared with 35% globally.
However, enforcement was weaker in some of the environments where AI coding agents are increasingly being used.
Only 43% said they could enforce AI access at the point of action in CI/CD pipelines. Kubernetes was the one environment in which India trailed the global average.
The findings come as Indian organisations prepare for obligations under the Digital Personal Data Protection framework.
“As DPDP obligations take effect, Indian enterprises will be asked to prove what actually happened: who authorized each access, what the agent did and why it was allowed,” Lee said.
The report argues that organisations need to move beyond granting permissions when an AI system logs in and instead authorise access at the moment an action is performed.
In practical terms, that means limiting an AI agent’s access to only the data and systems it needs for a particular task, monitoring what it does during that task and being able to revoke its access when necessary.









