Nearly all IT leaders say AI accessed sensitive data without permission
A sweeping global survey reveals that AI-enabled tools are dipping into sensitive information beyond their intended scope with striking frequency. In Singapore, the issue is particularly prominent, with nearly every IT executive reporting at least one incident of out-of-scope AI data access in the past year. This places the city-state among the higher-risk regions in the study.
The research covered thousands of IT and security leaders and other staff from large organizations that actively use AI, spanning markets across North America, Europe, Asia, and the Middle East. The goal was to measure governance practices in real-world use, not just what policies state on paper.
Policy adoption remains widespread—almost all organizations report having a formal rule governing how AI can access data. Yet enforcement and day-to-day adherence lag behind. Detecting when a scope violation occurs is not common, and when violations happen, many organisations are slow to realise them. This delay expands the window for potential data exposure and heightens risk across operations and customer trust.
Employee behavior adds to the challenge. A large share admit bypassing required approvals to run AI tools on sensitive data on occasion, with a meaningful minority doing so frequently. Many respondents also feel pressure to apply AI to confidential material even when they are uncertain it’s permitted, highlighting a culture where expediency can outweigh formal controls.
Accountability remains a persistent gap. While most organisations require approval from a specific individual for sensitive AI activities, only a minority can consistently trace an access event back to the designated authoriser. This disconnect between policy and traceability creates blind spots that can undermine safeguards.
Taken together, the findings underscore the tension between leveraging AI for productivity and maintaining strict data governance. They suggest a need for stronger real-time monitoring, clearer audit trails, and practical tools that can flag out-of-scope access as it happens. As AI adoption grows, organisations should invest in governance approaches that preserve agility while ensuring robust data protection and accountability.