India, Sept. 30 -- Indian organisations appear to have made strong progress on AI governance, but a new Delinea security report points to a gap between having rules and controlling what AI actually does.

The 2026 Identity Security Report: The AI Enforcement Gap found that 99% of Indian organisations have a formal policy governing what data AI tools and agents can access. Yet 84% said an AI tool or agent accessed sensitive data beyond its intended scope in the past year.

That contrast puts AI data access at the centre of the challenge. Governance may be widespread, but controlling access at the moment AI acts remains harder.

India exceeds global levels on several governance measures. About 87% of Indian organisations say their AI data a...