For the complete documentation index, see /llms.txt. Markdown version of this page: /en/insights/ai-security/delinea-ai-policy-data-access-gap.md.
AI Security ↗

An AI policy does not decide which files an assistant can read

Delinea's new survey highlights the difference between an assistant's approved task and its actual access to company data.

AI-generated illustration of a written access policy beside a tablet showing broader access to reports, payroll and customer records.
AI-generated illustration. The document and interface are concepts, not evidence from the survey.

In brief: A rule saying which data an AI assistant may use does not itself restrict what the software can read. Delinea’s new survey examines the gap between intended use and actual access.

What the survey reports

In findings published on 29 September, identity-security vendor Delinea says 87% of surveyed IT leaders reported an AI tool or agent accessing sensitive data beyond its intended scope during the previous year.

This is a survey result, not a count of independently verified breaches.

What “beyond its scope” means

Imagine an assistant approved to summarise monthly sales reports. The written rule says it should use only those reports, but its connection to the document system also permits reading payroll files.

The assistant does not have to break into that system to reach the wrong material. In this hypothetical example, the technical access is broader than the business task.

An AI model can request information through tools supplied by the application around it. Those tools use accounts and permissions to reach other systems. OWASP describes excessive permissions as one cause of excessive agency: an AI application being able to take damaging actions beyond what it needs to do.

A policy expresses the intended boundary. Access controls determine whether a particular request is allowed. A record of what happened serves a third purpose: making the action visible afterward.

What the figures say about Norwegian businesses

The report draws on 2,254 IT and security leaders and 2,250 non-IT employees at AI-using organisations with at least 500 employees, across eight countries outside the Nordics. Its percentages cannot be treated as measurements of Norwegian SMBs.

The distinction is still relevant to a smaller company: approving an assistant for one job and giving it access to an entire shared drive are separate decisions. Reading information outside a task also does not, by itself, establish that the information was sent to an outsider.

Our explanation of AI hacking introduces how models use tools to act on other systems.

← Back to all insights
Questions or inquiry? [email protected] Contact us →