AI tools exceeded sensitive data access limits at 84% of Indian firms surveyed: Delinea
A survey of 250 IT and security leaders found gaps in credential expiry and accountability, even as 99% of their organisations reported formal policies governing AI access to sensitive information.
The identity security company’s “2026 Identity Security Report: The AI Enforcement Gap”, released on September 30, found that 99% of Indian respondents reported having such policies.

NEW DELHI: Eighty-four per cent of Indian organisations surveyed reported that an AI tool or agent accessed sensitive data beyond its intended scope in the past year, despite near-universal adoption of formal AI data access policies, according to a new Delinea report.
The identity security company’s “2026 Identity Security Report: The AI Enforcement Gap”, released on September 30, found that 99% of Indian respondents reported having such policies. However, the findings point to gaps between stated governance and controls over how AI accesses information.
Eighty-seven per cent said their policies were actively enforced, compared with 71% globally. Indian organisations also reported giving AI tools broader access to sensitive information: 76% allowed access to employee data, against 51% globally. The report identified similar differences for customer data, financial records and source code.
Credential management and accountability remained concerns. While 99% said they treated AI agent credentials as governed privileged credentials, 45% reported that some remained active until the next audit, beyond the completion of their intended task.
Nearly every organisation required a named individual to approve AI access to a new sensitive data source. Yet only 47% could always trace a sensitive access event back to that person. Meanwhile, 98% expressed confidence that they could demonstrate compliant AI access to a regulator.
Cynthia Lee, Delinea’s vice-president for Asia Pacific and Japan, said Indian enterprises had made progress on governance, but broader AI access to sensitive information required stronger controls and records of access decisions.
Indian respondents reported faster detection of access violations than their global peers. Thirty-four per cent detected their most recent violation as it happened, compared with 20% globally. Nearly half could immediately revoke both an AI tool’s credentials and an active agent session, against 35% globally.
However, only 43% reported being able to enforce AI access controls at the point of action in software integration and deployment pipelines.
The India findings are based on a Censuswide survey of 250 IT and security leaders at organisations with at least 500 employees that were using or piloting AI. Conducted from August 3 to 14, 2026, it formed part of a wider eight-country study.





























