A recent report by Delinea has revealed a significant gap between AI policy and enforcement within Singaporean organisations. The 2026 Identity Security Report: The AI Enforcement Gap highlights that whilst nearly all Singaporean companies have formal AI data-access policies, enforcement remains weak. A staggering 98.8% of IT leaders reported instances where AI tools accessed sensitive data beyond their intended scope in the past year, yet only 14% could detect such violations in real time.
The report, based on surveys of over 2,000 IT leaders and employees globally, underscores the challenges faced by organisations in maintaining control over AI usage. In Singapore, 84% of employees admitted to bypassing the required approval process for AI use, with 51% doing so regularly. This suggests that despite having policies in place, many employees feel pressured to use AI on sensitive data, often due to tight deadlines or unclear governance rules.
Cynthia Lee, VP of APAC at Delinea, commented, “Singaporean organisations have done the hard part already; nearly every one of them has a formal AI policy. What’s missing is enforcing it in the moment.”
Key findings from the report include that 99.6% of Singaporean organisations have formal AI policies, yet less than half check AI access against these policies in real time. Additionally, 72% of organisations take a full day or longer to detect out-of-scope AI access, the highest among the eight markets surveyed.
The report calls for improved real-time enforcement and accountability, suggesting that organisations need to authorise AI access at the moment of action. Delinea’s platform offers continuous, runtime authorisation to help bridge this enforcement gap, providing security teams with a defensible record of AI access and actions.



