A governance gap that was hiding behind a good-looking policy number
Delinea, an identity security company, surveyed 2,254 IT and security leaders and 2,250 non-IT employees across the US, UK, Germany, Australia, Singapore, the UAE, France, and India, all at organizations with at least 500 employees already using or piloting AI. The headline finding looks reassuring at first: 99.7 percent of IT and security leaders say their organization has a formal policy governing what data AI tools and agents can access. Nearly every organization in this survey has done the paperwork.
The enforcement numbers tell a different story. Only about 51 percent said AI access is actually checked against those policies in real time, and just 19 percent said they could detect in real time when an agent accessed data outside its intended scope. Delinea calls this disconnect "The AI Enforcement Gap" in its fall 2026 Identity Security Report, and the phrase is exactly right: institutions have built the policy layer and skipped the verification layer, which is the part that actually stops a problem before it happens rather than after.
The incident number that should worry every registrar's office
Eighty-seven percent of IT and security respondents said their organization experienced or suspected an incident in the past year where an AI tool or agent accessed sensitive information beyond what its task required. That is not a hypothetical risk being hedged against in a future-state slide. It is a near-universal occurrence being reported in the present tense, across organizations that already have formal governance policies in place on paper, which means the policy itself was never the part standing between an institution and this kind of incident in the first place.
On a campus, that scenario has specific, named systems attached to it: an admissions assistant pulling applicant data beyond its assigned cohort, a financial aid chatbot drawing on FAFSA-linked records outside its approved scope, or a registrar-integrated tutoring tool like the kind the University of Maryland is currently piloting, retaining more student chat history than its data retention policy allows. The survey also found that 58 percent of IT and security leaders have mechanisms to automatically revoke AI access when a session ends, meaning 42 percent of organizations are running agent credentials that can stay live well past the moment anyone intended them to.
The people bypassing the process are the ones writing the policy
The employee-side findings cut against the usual assumption that rank-and-file staff are the weak link. Seventy-six percent of employees surveyed said they had bypassed formal AI approval at some point to use an AI tool with company data, applications, or systems, and 48 percent said they always or extensively use AI tools without going through approval. Sixty percent said they had felt pressure to use AI with sensitive information even when unsure doing so was permitted.
The more pointed finding is who is doing the bypassing most. Eighty-one percent of C-level respondents said they always or regularly bypass AI access approval, compared with just 33 percent of intermediate-level employees. On a campus, that maps uncomfortably well onto deans, provosts, and vice presidents experimenting with AI tools ahead of the policies their own offices are drafting, which means the governance gap starts at the level that is supposed to be closing it.
Detection speed is the metric nobody is tracking yet
Even when an AI tool does go outside its intended scope, the survey found only 41 percent of IT leaders said all AI tools and agents accessing company data are actively monitored. When an incident did occur, 55 percent said detection took at least a day, and 30 percent said four days or longer. A university running agentic AI tools against its LMS, its CRM, and its financial systems should treat detection latency as a metric worth tracking on its own, separate from whether a policy document exists, because a four-day detection window on a FERPA-covered system is the difference between a contained issue and a reportable breach.
This is the single most actionable number in the whole report for a campus CIO building next year's security budget. Policy drafting is largely complete across the sector already, this survey and plenty of prior ones confirm that. Monitoring infrastructure that can flag an out-of-scope access attempt within minutes rather than days is the gap, and it is a gap that shows up in a budget line for identity and access tooling, not in a committee that revises the AI use policy for the third time this year.
What a university CIO should fund next
Delinea's own conclusion is the right one to borrow directly: the next phase of AI governance depends less on writing additional rules and more on whether an institution can enforce the rules it already has while an agent is actively working. For a university, that argues for three concrete investments ahead of the next academic year: real-time access monitoring tied specifically to AI agents and tools, automatic credential expiration tied to session end rather than to an annual audit cycle, and a documented incident response time target for anything touching FERPA-protected data.
None of that requires waiting for a new vendor category to mature. Identity and access management tooling capable of this kind of real-time enforcement already exists in the broader enterprise security market, including from Delinea itself and its competitors. The institutions that move first will be the ones that treat this survey as a checklist against their own environment this semester, rather than as an interesting data point to cite in next year's governance committee meeting.



