SYDNEY – September 30, 2026 – Delinea, the identity security platform that continuously controls what AI agents, humans and machines can do and for how long, today published new research examining where AI governance breaks down in practice. According to the report, 2026 Identity Security Report: The AI Enforcement Gap, 99.6% of Australian IT leaders say an AI tool or agent accessed sensitive data beyond its intended scope in the past year. The report also found that only 12% can detect a scope violation as it happens, lower than the global average (19%).

The findings draw on two global surveys of 2,254 IT and security leaders and 2,250 non-IT employees at organisations of 500 or more employees that use AI, across the UK, US, Germany, Australia, Singapore, UAE, France and India. Together, they show that near-universal policy adoption has done little to change how employees handle AI in practice. Australia has the widest policy-enforcement gap in the report, and employees are already routing around it: 64% say they have bypassed the required approval process for using AI at some point.

“Australia leads in AI policy, but a policy on paper doesn’t tell you who’s accountable when something goes wrong,” said Cynthia Lee, APAC Vice President at Delinea. “Our research echoes what I hear and see in this region: companies have AI policies in place, but are not able to see whether they are being followed or have mechanisms to enforce them.”

Key Australian findings from the report include:

  • Australia leads in policy but lags in enforcement: Every Australian organisation surveyed reported that they have a formal policy governing what data AI tools and agents can access, yet only 34% check that access against policy in real time, the highest policy-enforcement gap globally.
  • Employees feel pushed past the guardrails: Almost 1 in 2 (48%) say they have felt pressured to use AI on sensitive or confidential data even when they were unsure it was permitted. When deadlines outpace the governance process, many look for a faster route instead of following it.
  • Accountability is thin: While nearly all Australian organisations (99.6%) require named-individual approval for at least some sensitive use, just 42% of Australian IT leaders can always trace a sensitive AI access event back to a named human authoriser. The gap lies in execution rather than in the rules.

The gap is widest where developers offload the most work to coding agents

Across six major environments, 47% of organisations globally lack enforcement at the moment of action in at least two.  In Australia, the weakest are Kubernetes, CI/CD pipelines and on-premises file systems, and even the strongest, cloud data stores and SaaS applications, leave gaps. When an agent steps outside its scope, detection lags: 67% of Australian organisations take a full day or longer to catch it, slower than the global average.

Closing the gap between policy and enforcement calls for authorising AI access at the moment of action, not only at login. Delinea applies continuous, runtime authorisation with least-privilege scoping and full sessioTn visibility across AI, human and machine identities, giving security teams a defensible record of who authorised each access, what the agent did and why it was allowed.

To read the full findings, download the report here: [LINK]  

Have a press release to share? Contact our team today.

Have an article or a piece you would like to contribute? Get in touch with the editorial team.