At first, it sounds like good news: a recent survey of enterprise decision-makers found that 98% of these leaders are confident in their organization’s ability to protect the sensitive data used in AI and machine learning (ML) workflows. But dig deeper into the results and you’ll find that 84% of these same leaders grant data compliance exceptions and 51% worry about audits. Inside that disparity—between how secure leaders say they are and what they actually do—the enterprise’s risk exposure can grow, unseen and unaddressed.
These findings come from the Perforce Delphix 2026 State of AI and Data Privacy Report, which gathered insights from 518 executives in organizations across industries. They’re arriving at a moment when long-established strategies for protecting data no longer fit how software gets built.
For decades, data protection involved manual handoffs. A team masked the sensitive information in a copy of production data, approved it for use and then sent it along to the developers who needed it. Agentic development moves much faster than that model was designed for.
“Compliance was designed into workflows as a checkpoint,” says Mayank Ahluwalia, product manager for synthetic data and AI compliance at Perforce Delphix. “But agents don’t wait for data to pass through checkpoints, so compliance can’t be thought of as a gate anymore. Instead, it has to be enforced every single time there’s a handoff of data.”
Recent regulatory changes are raising the stakes. More than 20 US states have passed comprehensive consumer privacy legislation and their number keeps climbing. In the EU, the first enterprise obligations under the AI Act became enforceable last month, with noncompliance carrying penalties up to 3 percent of annual turnover. These regulations join a global patchwork of data protection laws that now cover nearly 80% of the world’s economies and any enterprise handling sensitive data must be prepared to navigate these fast-changing rules.
When confidence is assumed, not earned
The high confidence levels and frequent exceptions might seem to contradict each other, but Ahluwalia explains that not all confidence is the same—there’s confidence that’s assumed and confidence that’s earned.
“If there’s a policy and you ask someone whether the data is secure and they point you to the policy, that’s assumed confidence,” he says. “Confidence becomes earned when you have evidence that the policy is being applied. Earned confidence is expressed in an audit trail—when you have evidence you can show to any auditor that documents exactly how a given copy of the data was secured.”
Assumed confidence is easy to maintain, because exceptions rarely seem dangerous if they’re just one-off exceptions. The governed path is slow and enterprises want their data to move as fast as their AI workflow does. Thus, their development team asks to bypass it, just this once and the request gets approved. In isolation, these workarounds are acceptable. But in agentic development, where data is pulled from multiple systems at once, the risks mount.
A zip code left unmasked in one dataset and an age left unmasked in another may each look harmless alone. Combined, they may single out an individual. Agents widen the exposure further. Because they act autonomously, reaching across systems and calling other tools, they can surface a risky correlation no human would have thought of—or memorize it and reproduce it downstream, magnifying the blast radius of a small exception.
How AI changed what “usable” means
The traditional approach to data masking worked well for years. Replacing real values with format-matched fakes allows developers to test and build software using realistic data without exposing sensitive information since tests only required data of the right type in the right fields.
AI models have different needs. They’re trained to understand patterns and the relationships within datasets. Mask an age with a random valid-looking number and software will pass tests, but an AI model will end up learning a statistical property that isn’t real, resulting in wrong predictive behavior.
“A lot of the tools out there do a great job of securing data structurally,” Ahluwalia says. “But none of them were designed to preserve the data’s statistical properties. That’s the hard problem—keeping it usable for AI.”
This is why survey participants named protecting unstructured data as their top AI/ML adoption challenge and why referential integrity—keeping data accurately correlated across systems—is a primary concern. Without relationship preservation and realism, this bad data can be useless and even dangerous for AI workflows, testing and application development.
What real AI-readiness looks like
Ahluwalia distinguishes organizations that are genuinely ready for agentic development from those whose leaders are merely confident: real readiness begins with knowing exactly where sensitive data lives—across every system, not just the AI pipeline. Training data doesn’t originate in the pipeline. It flows into it from the source systems that feed it.
“People focus on the model training pipeline, but that data has lived in the same systems for years,” he says. “If you secure the pipeline and leave an opening upstream, it’s like you’re fixing the door while leaving a window open at the back of your house.”
Closing that back window means protecting data everywhere it lives. Start by discovering where sensitive data resides and how it flows. Secure it automatically with masking real data or generate realistic synthetic data to use instead of the real data. Deliver it fast through virtualization. And maintain an audit trail, so that your confidence need never be assumed again. Perforce Delphix brings these capabilities together in a single platform.
Earned confidence doesn’t come from a policy document. It comes from having audit-ready evidence on hand—and with it, you won’t have to choose between innovation and compliance. And your data practices will finally deserve the confidence you might already have.
Interested in learning more? Access the full AI and data privacy report here.






