SINGAPORE – September 30, 2026 – Delinea, the identity security platform that continuously controls what AI agents, humans and machines can do and for how long, today published new research examining where AI governance breaks down in practice. According to the report, 2026 Identity Security Report: The AI Enforcement Gap, 98.8% of Singaporean IT leaders say an AI tool or agent accessed sensitive data beyond its intended scope in the past year, second highest globally. The report also found that only 14% can detect a scope violation as it happens, lower than the global average (19%).

The findings draw on two global surveys of 2,254 IT and security leaders and 2,250 non-IT employees at organisations of 500 or more employees that use AI, across the UK, US, Germany, Australia, Singapore, UAE, France and India. Together, they show that near-universal policy adoption has done little to change how employees handle AI in practice.  Singaporean employees are already routing around it: 84% say they have bypassed the required approval process for using AI at some point, with 51% saying they do it always or regularly.

“Singaporean organisations have done the hard part already; nearly every one of them has a formal AI policy,” said Cynthia Lee, VP of APAC at Delinea. “What’s missing is enforcing it in the moment. Without that, security teams won’t have full visibility and control over what their agents are actually doing.”

Key findings from the report include:

  • Policy adoption has outpaced enforcement: 99.6% of Singaporean organisations now have a formal policy governing what data AI tools and agents can access, yet only under half check that access against policy in real time.
  • Employees feel pushed past the guardrails: 76% say they have felt pressured to use AI on sensitive or confidential data even when they were unsure it was permitted, 3rd highest globally. When deadlines outpace the governance process, many look for a faster route instead of following it.
  • Accountability is thin: while nearly all Singaporean organisations (98.8%) require named-individual approval for at least some sensitive use, just 38% of Singaporean IT leaders can always trace a sensitive AI access event back to a named human authoriser. The gap lies in execution rather than in the rules.

The gap is widest where developers offload the most work to coding agents

Across six major environments, 47% of organisations globally lack enforcement at the moment of action in at least two. The weakest are CI/CD pipelines, Kubernetes and on-premises file systems, and even the strongest, cloud data stores and SaaS Applications, leaves gaps. When an agent steps outside its scope, detection lags: 72% of Singaporean organisations take a full day or longer to catch it, the highest globally.

Closing the gap between policy and enforcement calls for authorising AI access at the moment of action, not only at login. Delinea applies continuous, runtime authorisation with least-privilege scoping and full session visibility across AI, human and machine identities, giving security teams a defensible record of who authorised each access, what the agent did and why it was allowed.

To read the full findings, download the report here: [LINK]

Have a press release to share? Contact our team today.

Have an article or a piece you would like to contribute? Get in touch with the editorial team.