Industry NewsAI Business & Ecosystem
Delinea report finds Singapore organisations struggling to enforce AI security policies

Article content
Nearly all Singaporean IT leaders surveyed by Delinea say an AI tool or agent accessed sensitive data beyond its intended scope during the past year, highlighting the gap between formal AI policies and how those policies are enforced in practice.
Delinea's 2026 Identity Security Report: The AI Enforcement Gap found that 98.8% of Singaporean IT leaders reported an AI tool or agent accessing sensitive data beyond its intended scope. Only 14% said their organisations can detect an AI scope violation as it happens, compared with 19% globally.
The findings suggest that while organisations have moved quickly to establish AI governance policies, real-time oversight and enforcement have not progressed at the same pace.
AI policy adoption is nearly universal
Delinea's research found that 99.6% of Singaporean organisations have a formal policy governing what data AI tools and agents can access.
However, fewer than half check AI access against those policies in real time.
The difference points to a distinction between having governance rules and being able to enforce them when an AI system actually attempts to access sensitive information.
For security teams, that creates a visibility challenge as organisations increasingly introduce AI tools and agents into everyday workflows.
Employees are also bypassing approval processes
The report found that the enforcement challenge extends beyond AI systems themselves.
84% of Singaporean employees surveyed said they had bypassed the required approval process for using AI at some point, with 51% saying they do so always or regularly.
Delinea also found that 76% of Singaporean employees said they had felt pressured to use AI on sensitive or confidential data even when they were unsure whether it was permitted.
The findings indicate that employees may be working around formal processes when governance requirements do not keep pace with business demands.
Real-time detection remains limited
One of the report's central findings is the difficulty organisations face in identifying AI activity when it occurs.
Only 14% of Singaporean IT leaders said they can detect a scope violation as it happens, below the 19% global average.
The delay becomes more pronounced after a violation has occurred. Delinea found that 72% of Singaporean organisations take a full day or longer to detect an AI scope violation, the highest figure among the markets surveyed.
That creates a significant gap between the moment an AI system moves beyond its authorised scope and when a security team becomes aware of the activity.
Accountability is another weak point
The report also highlights challenges around determining who authorised sensitive AI activity.
While 98.8% of Singaporean organisations require named-individual approval for at least some sensitive AI use, only 38% of Singaporean IT leaders said they can always trace a sensitive AI access event back to a named human authoriser.
The contrast suggests that the issue is not necessarily the absence of governance requirements, but the ability to maintain accountability when those requirements are put into practice.
Coding environments create additional exposure
Delinea's research also examined AI enforcement across six major technology environments, including CI/CD pipelines, Kubernetes, on-premises file systems, cloud data stores and SaaS applications.
Globally, 47% of organisations lack enforcement at the moment of action in at least two of these environments.
The report identifies CI/CD pipelines, Kubernetes and on-premises file systems among the environments with the weakest enforcement, while cloud data stores and SaaS applications also have gaps.
For organisations increasingly using coding agents and AI-driven development workflows, these environments can introduce additional questions around access, authorisation and accountability.
Moving from policy to enforcement
Delinea argues that the findings point towards a need to move beyond policies that govern access at login and towards controls that can authorise AI activity at the moment an action takes place.
The company advocates continuous, runtime authorisation combined with least-privilege controls and session visibility across AI, human and machine identities.
The broader issue highlighted by the research is the growing need for organisations to connect AI governance policies with the technical controls capable of enforcing those policies as AI systems interact with sensitive data and enterprise environments.
The AI enforcement gap in Singapore
Singapore's findings illustrate the broader challenge facing enterprises adopting AI at scale.
Formal policies are now widespread, but the ability to detect violations in real time, maintain accountability and prevent employees from bypassing approval processes remains less developed.
As AI agents take on more work across enterprise environments, the distinction between having an AI policy and being able to enforce it when an action occurs is becoming increasingly important for security and governance teams.
About Delinea
Delinea is an identity security company focused on controlling what AI agents, humans and machines can do and for how long. Its platform provides capabilities including just-in-time authorisation, privileged access management, identity risk analysis, least-privilege controls and session visibility across enterprise environments. Delinea says more than 9,000 organisations, including two-thirds of the Fortune 100, rely on its platform.
Source and Credits
Source: Delinea, 2026 Identity Security Report: The AI Enforcement Gap, Singapore regional findings
Executive: Cynthia Lee, VP of APAC, Delinea