Shadow AI Goes Autonomous: The Governance Gap Behind Healthcare's Agentic Boom
Autonomous AI agents are moving into clinical workflows faster than hospitals can govern them. The identity boundary, risk tier, and stop rules every health system should define first.
The shift from AI that answers to AI that acts has already happened inside health systems. Prompt-and-response assistants are being replaced by autonomous agents that plan, reason across multiple steps, and touch real clinical and operational systems. The question is not whether these agents are arriving. It is whether the hospitals adopting them have anything in place to govern who governs them.
A national survey published in September 2026, conducted by the research firm Vanson Bourne on behalf of the identity-security company Imprivata, asked 250 U.S. healthcare leaders responsible for identity security and AI strategy how agentic AI is actually being deployed. The answer is a study in confidence outpacing control.
Nearly three in four organizations, 72 percent, report that AI tools or agents are deployed without formal IT approval at least occasionally. More than a third, 37 percent, describe their approach to giving AI agents access as ad hoc or unapproved. Yet 86 percent of the same leaders say they are confident they can fully control and govern an agent's actions, and 88 percent expect agents to operate with at least some degree of autonomy. Only 17 percent believe their existing identity and access management, or IAM, frameworks are sufficient without adaptation.
Those two numbers cannot both be true at once. A health system cannot run unapproved agents while being certain it can govern them. The gap between them is the real story, and it has a name the industry is already using: shadow AI.
Agents are not chatbots
Why this gap matters more than earlier AI hype is structural. A chatbot produces text a clinician reviews before acting. An agent is different. It executes actions: traversing systems, moving data, triggering workflows, completing multi-step tasks on behalf of a user. When an agent has excessive permissions, operates outside its intended scope, or takes a high-risk action without oversight, the consequences can land directly on care delivery.
The survey quantifies how real this already is. Agentic AI is live in production at 28 percent of organizations, with another 44 percent piloting and 21 percent planning deployment within the next twelve months. AI agents currently touch 33 percent of clinical workflows and 37 percent of operational workflows, numbers the respondents expect to reach 41 percent and 46 percent within twelve to eighteen months.
A peer-reviewed paper in Nature Medicine, published in 2026, makes a distinction that cuts to the heart of this. The authors separate operational trust from decisional trust. An agent may be well governed at the infrastructure level, but that alone does not make it safe to rely on. Clinicians still need to know which outputs can be handled autonomously inside a governed workflow and which must be deferred for human review. Evaluation, the authors argue, has to move past diagnostic accuracy toward reliability and trustworthiness, a theme this site has also tracked in the post-market validation gap. In short: a technically correct model can still cause harm if the surrounding system routes its output the wrong way.
Who is accountable when an agent acts
This is where the sovereignty question enters. For years the instinct in healthcare has been to add a human to the loop and call the problem solved. A named human in the loop is not the same as a human who has the time, authority, and information to overrule a machine, a point this site has made before about how nominal oversight does not guarantee judgment.
The survey shows health systems are already reaching for tiered, risk-adjusted oversight rather than a blanket answer. Just over half, 53 percent, require mandatory human review for high-risk clinical actions. Forty percent require human sign-off for high-risk operational actions. A smaller share, 26 percent, relies on spot audits or exception-based reviews, and 25 percent permit fully autonomous execution within bounded parameters. Those are legitimate design choices, but they only work if the boundary between autonomous and human-reviewed is explicit, enforced, and visible.
The governance principle is the same one behind clinician decision rights in clinical AI: oversight must match the level of risk. An agent that flags a billing anomaly is not the same as an agent that doses a medication or writes a discharge. The more autonomy a system is granted, the more the safeguards must be able to detect and contain problems before they become patient-safety events.
Where the patient fits in
Most coverage of agentic AI frames it as an operational problem: identity, permissions, audit. It is those things, but it is also a patient-care problem, because autonomous agents are already moving into the clinical workflows that touch patients directly.
Consider what the survey's projected growth implies. If agents expand from 33 percent to 41 percent of clinical workflows, more of the actions that shape a patient's diagnosis, scheduling, and care coordination will run without a human looking at each step. A patient does not experience this as "agentic AI in production." A patient experiences it as a prior authorization that resolved without anyone explaining why, or a care plan that arrived from a system no one can fully describe.
Patient sovereignty means the people whose care is affected by an autonomous system retain a meaningful say and a meaningful explanation. That does not require every agent decision to pause for a human signature, which would erase the very efficiency agents exist to deliver. It requires that patients can learn, in plain terms, when an automated system played a role in a decision that affects them, and that they can ask a human to review it without penalty.
The identity and audit components of agent governance are what make that review possible. A system that cannot say which agent took an action, on whose authority, and why, cannot offer a patient a real explanation either. Transparency to the patient and accountability inside the system are the same property seen from two sides.
A practical floor for agent governance
Governance does not have to be a committee that meets quarterly and approves nothing. For agents specifically, a usable floor has several concrete components that health-system leaders can ask for today.
Every agent needs an identity. Just as a clinician logs in as themselves, an agent should act under a distinct, auditable digital identity, not a shared or borrowed human credential. When an action is taken, the record should show which agent took it, on whose behalf, and under what policy.
Every agent needs boundaries. Permissions should be scoped to the task, granted in the least-privilege way, and revoked when the use case ends. An agent provisioned for a documentation pilot should not retain access across unrelated systems after the pilot closes.
Every agent needs a risk tier. Classify each agent by the clinical or operational risk of its actions, and map the oversight level to that tier. High-risk clinical actions get mandatory human review. Low-risk, high-volume operational tasks can run under bounded autonomy with audit.
Every agent needs an audit trail. Because agents act continuously, the ability to reconstruct what happened, why, and with what authorization is the difference between a governable system and a black box nobody can explain after something goes wrong.
Every agent needs a stop rule. Define in advance the conditions under which an agent is paused, quarantined, or disabled. A stop rule written before a sentinel event is governance. One written after is damage control.
The opportunity is real, and so is the risk
None of this is an argument against agentic AI. The technology addresses genuine, ongoing problems: staffing deficits, documentation backlog, administrative burden that pulls clinicians away from patients. Used well, a governed agent could reduce exactly the friction that has driven so much clinician frustration.
The reason to act now is that the deployment is already happening faster than the governance can catch up, which is the pattern the survey captures with unusual clarity. The organizations that define agent identity, boundary, risk tier, audit, and stop rules now will be the ones that can scale agentic AI without scaling shadow AI alongside it. The ones that do not will discover, after the fact, that confidence in control was never the same thing as control.
The question that should follow every proposed agent deployment is not "what can it do." It is "who is responsible for what it does, and can we prove it after the fact." Ask that before the first agent goes live, and the answer becomes the architecture. Ask it only after something goes wrong, and the answer becomes a lawsuit and, for the patient on the receiving end of a decision no human can explain, a permanent erosion of trust.
Sources: Industry survey reported by HIT Consultant: Imprivata and Vanson Bourne, "The Agentic AI Trust Gap" (September 2026); Healthcare Dive coverage of the survey (September 2026); and "On-premise medical AI agents for reliable clinical decision-making," Nature Medicine (2026).