Industry NewsAI Business & Ecosystem

Delinea report finds Australia facing a widening gap between AI policy and enforcement

By Ash Kate
Delinea report finds Australia facing a widening gap between AI policy and enforcement

Article content

Australian organisations are putting formal policies around AI use in place, but new research from Delinea suggests that enforcement is struggling to keep pace.

According to Delinea's 2026 Identity Security Report: The AI Enforcement Gap, 99.6% of Australian IT leaders surveyed said an AI tool or agent accessed sensitive data beyond its intended scope during the past year.

At the same time, only 12% said they can detect such a scope violation as it happens, compared with 19% globally.

The findings point to a growing distinction between having AI governance policies and being able to enforce those policies as AI becomes more deeply embedded in enterprise workflows.

Australia leads in AI policy adoption, but enforcement lags

Delinea found that every Australian organisation surveyed reported having a formal policy governing what data AI tools and agents can access.

However, only 34% said they check AI access against those policies in real time.

According to the report, this represents the widest policy-enforcement gap among the countries surveyed.

The findings suggest that organisations may have established governance frameworks without having equivalent visibility into whether AI systems are operating within those boundaries at the moment access occurs.

Employees are bypassing approval processes

The research also highlights the practical challenges organisations face when AI governance requirements meet day-to-day business demands.

In Australia, 64% of employees surveyed said they had bypassed the required approval process for using AI at some point.

Almost half, or 48%, also said they had felt pressured to use AI with sensitive or confidential data even when they were unsure whether doing so was permitted.

The findings indicate that formal approval processes can become difficult to follow when employees are under pressure to deliver work quickly and AI tools are readily available.

Accountability remains a challenge

The report also identifies a gap between assigning responsibility and being able to trace AI activity back to a specific human decision.

Nearly all Australian organisations surveyed, 99.6%, require named-individual approval for at least some sensitive AI use.

Yet only 42% of Australian IT leaders said they can always trace a sensitive AI access event back to a named human authoriser.

This creates a distinction between having approval requirements in place and maintaining a clear record of who authorised a particular action.

For organisations deploying AI agents with increasing levels of autonomy, that distinction becomes particularly relevant to security and governance teams.

Coding environments present additional exposure

Delinea's research also points to areas of enterprise infrastructure where enforcement can be more difficult.

Across six major environments, the report found that 47% of organisations globally lack enforcement at the moment of action in at least two environments.

In Australia, Kubernetes, CI/CD pipelines and on-premises file systems were identified as the weakest environments for enforcement.

Even environments identified as stronger, including cloud data stores and SaaS applications, continue to have gaps.

The findings are particularly relevant as organisations increasingly use AI and coding agents to automate development and other technical workflows.

Detection can take more than a day

The research also highlights the time between an AI agent exceeding its authorised scope and an organisation detecting the activity.

Delinea found that 67% of Australian organisations take a full day or longer to detect when an agent has moved outside its intended scope.

Only 12% can detect a scope violation as it happens.

For security teams, this creates a window in which unauthorised activity may continue before it is identified and investigated.

Moving from AI policy to real-time enforcement

Delinea argues that AI governance needs to extend beyond access controls established at login and into the actions AI systems take during runtime.

The company advocates continuous, runtime authorisation combined with least-privilege access and visibility into AI, human and machine identities.

The broader challenge for organisations is connecting policy with enforcement so that AI access can be evaluated at the point of action and linked to a clear authorisation trail.

As AI agents become more capable and increasingly integrated into enterprise workflows, the ability to understand what an agent accessed, who authorised it and why the action was permitted is becoming an important part of AI security governance.


About Delinea

Delinea is an identity security platform focused on controlling what AI agents, humans and machines can do and for how long. Its platform applies just-in-time authorisation and privileged access management across on-premise, multi-cloud and ephemeral infrastructure. Delinea says more than 9,000 organisations, including two-thirds of the Fortune 100, rely on its platform.


Source and Credits

Source: Delinea, 2026 Identity Security Report: The AI Enforcement Gap