By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Data Governance Lags for AI Agents, Survey Finds
A recent survey conducted by identity security firm Delinea highlights a substantial disparity between the establishment of data governance policies for AI tools and their actual real-time enforcement within organizations. The report indicates that an overwhelming 99.7% of IT and security leaders surveyed confirmed their organization possesses a formal policy dictating the data that AI tools and agents are allowed to access. This high percentage suggests a widespread recognition of the need for structured data governance in the rapidly evolving landscape of artificial intelligence.
However, the survey data reveals a critical enforcement gap. Despite the near-universal existence of these policies, only approximately 51% of the surveyed leaders stated that AI tool access is actively checked against these established policies in real time. This means that for nearly half of the organizations with AI data access policies, there is a significant period where AI agents could potentially access data without immediate validation against the defined rules. This discrepancy poses a considerable risk, as unauthorized or inappropriate data access by AI agents could lead to data breaches, privacy violations, and non-compliance with regulatory requirements.
The findings underscore the challenges organizations face in operationalizing AI governance. While the intent to govern AI data access is clearly present, the technical and procedural mechanisms for ensuring continuous, real-time compliance appear to be lagging. This gap is particularly concerning given the increasing sophistication and autonomy of AI agents, which can process and interact with vast amounts of data. The survey's methodology involved polling IT and security leaders, providing a perspective from those responsible for implementing and overseeing such policies. The implications of this enforcement gap extend to various sectors, including finance, healthcare, and technology, where data sensitivity and regulatory scrutiny are paramount.
Delinea's report suggests that organizations need to move beyond simply creating policies and focus on robust, automated enforcement mechanisms. The ability to monitor and control AI data access in real time is crucial for mitigating risks associated with AI deployment. Without this, the existence of formal policies may offer a false sense of security, leaving organizations vulnerable to the very risks they aim to prevent. The survey did not specify the types of AI tools or agents surveyed, nor did it detail the specific industries represented by the IT and security leaders, but the overarching trend points to a universal challenge in AI data governance.
Original source — read the full reporting at the publisher:
Read on Campus TechnologyGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.