Ask an Indian CIO whether their organisation has a policy governing what data AI tools can touch, and the answer is almost certainly yes. According to Delinea’s 2026 Identity Security Report: The AI Enforcement Gap, published September 30, 99% of Indian organisations have a formal AI data access policy. Ask the same CIO whether an AI tool or agent has accessed sensitive data beyond its intended scope in the past year, and there is an 84% chance the answer is also yes.
That contradiction sits at the center of the report, and it raises an uncomfortable question for technology leaders: if nearly everyone has a policy, and nearly everyone is seeing overreach, what is the policy actually doing?
Ahead of the world on governance, and on exposure
On paper, India leads. The report finds 87% of Indian organisations say their AI data access policy is actively enforced, compared with 71% globally. But the same organisations are also granting AI far broader reach into sensitive data. Some 76% say AI tools can access employee data, against 51% globally, and Delinea says the gap is similar for customer data, financial records and source code.
In other words, Indian enterprises have extended AI deeper into their most sensitive systems while relying on policy to keep it contained. Delinea calls the result the “AI enforcement gap”: standing access that creates the conditions for agent overreach.
“India’s enterprises have done the hard work on AI governance,” said Cynthia Lee, Vice President, APJ at Delinea. “But AI agents here also reach more customers, employees and financial data than the global average. At that point, a policy alone stops being enough.”
Confidence outpacing control
The report’s most striking figures concern how sure organisations are of themselves:
Regulatory confidence: 98% say they could demonstrate compliant AI access to a regulator, despite the high rate of overreach respondents reported.
Credential hygiene: 99% say they treat AI agent credentials, such as API tokens and MCP configuration files, as governed privileged credentials. Yet 45% admit some of those credentials remain active until the next audit, long after the task they were issued for has ended.
Accountability: Nearly every organisation requires a named individual to approve AI access to a new sensitive data source, but only 47% can always trace a sensitive AI access event back to that person.
For CIOs, the last figure may matter most. An approval process that cannot be traced afterward is closer to a ritual than a control.
The DPDP test
The timing adds pressure. As obligations under India’s Digital Personal Data Protection (DPDP) framework take effect, enterprises will be expected to show, not merely assert, how personal data was handled. Lee framed the coming test in practical terms: organisations will need to prove “who authorized each access, what the agent did and why it was allowed.”
A 98% confidence level in regulatory readiness looks fragile against a 47% ability to trace access to an accountable approver. Auditors are likely to probe precisely that distance.
Faster detection, blind spots in the pipeline
The findings are not uniformly negative. Indian organisations detect problems faster than peers: 34% caught their most recent scope violation as it happened, versus 20% globally. And nearly half can immediately revoke both an AI tool’s credentials and an active agent session, compared with 35% globally.
The weakness lies in the execution layer, particularly where coding agents are most active. Only 43% of Indian organisations can enforce AI access at the point of action in CI/CD pipelines, and Kubernetes is the one environment where India trails the global average. As autonomous coding tools gain write access to build and deployment systems, these are the places where overreach can do the most damage, and where visibility tends to be thinnest.
What closing the gap looks like
Delinea’s prescription is to move authorisation from login to the moment of action. That means continuous, runtime authorization with least-privilege scoping and full session visibility across AI, human and machine identities, producing a defensible record of each access decision.
Practically, CIOs reviewing their own posture might start with a few questions:
Are agent credentials time-bound? Tokens and configuration files that outlive their tasks are standing access, regardless of what the policy says.
Can every sensitive AI access be traced to a named approver? If not, sign-off is not delivering accountability.
Is enforcement happening at runtime? Controls that stop at authentication will not catch an agent acting beyond its scope mid-session.
Are CI/CD and Kubernetes covered? These environments deserve priority given how much autonomous work happens there.
The report’s central message is that governance maturity and governance effectiveness are different things. Indian enterprises have moved quickly to adopt policies and have strong detection and revocation capabilities by global standards. But with AI agents granted wide access to sensitive data, and with regulators preparing to ask for evidence, the next phase is about proving that controls work in real time.