Thu, 1 Oct 2026

Singaporean organisations report AI agents accessed unauthorised sensitive data in the past year, study finds

Image by Innova Labs from Pixabay

Delinea’s 2026 Identity Security Report: The AI Enforcement Gap found that almost all (98.8%) Singaporean IT leaders say an AI tool or agent accessed sensitive data it was not supposed to in the past year, the second-highest rate worldwide.

“Singaporean organisations have done the hard part already; nearly every one of them has a formal AI policy,” said Cynthia Lee, VP of APAC at Delinea. “What’s missing is enforcing it in the moment. Without that, security teams won’t have full visibility and control over what their agents are actually doing.”

Closing the gap

According to the report, only 14% can spot a data access violation as it happens, below the global average of 19%.

The report also found that almost all (99.6%) Singaporean organisations now have a formal policy about what data AI tools and agents can access. However, fewer than half check in real time to ensure access follows the policy.

Also, 76% say they feel pressured to use AI on sensitive or confidential data even when they are not sure if it is allowed. Almost all Singaporean organisations (98.8%) require approval from a named person for some sensitive uses. Still, only 38% of Singaporean IT leaders can always track a sensitive AI access event back to a named human approver.

According to Delinea, organisations need to close the gap between policy and enforcement by approving AI access when the action happens, not just at login.

Related:  Many leading LLMs display strategic imbalance across risk scenarios, research finds

Related Stories

MORE STORIES

Subscribe