Healthcare leaders responsible for security and artificial intelligence strategy have a big challenge with unsanctioned use of AI tools, according to a new survey from Imprivata.
The rapid spread of AI across hospitals and health systems is also testing whether existing identity, access and oversight models can keep up with the need to manage agentic AI responsibly, say researchers in the report, “The Agentic AI Trust Gap: Why Healthcare Needs Identity-Led Governance,” published Sept. 15.
Researchers at Vanson Bourne and access management security firm Imprivata said their new survey findings show the significant governance challenges as AI gains momentum across healthcare and AI agents’ capabilities evolve.
Unsanctioned AI, also known as shadow AI, is a particular challenge. An agentic tool may rely on public AI platforms and could potentially share proprietary code and patient data outside of provider network security perimeters.
The new report, based on a survey of 250 U.S.-based healthcare leaders, shows that while evidence of shadow AI is growing across enterprises, even sanctioned use of agentic AI is moving faster than many organizations’ ability to monitor agent activity.
Twenty-eight percent of the healthcare leaders surveyed reported they already have agentic AI in production, and another 44% say they are piloting AI agents.
What’s more, 88% said they expect AI agents to operate with some degree of autonomy across operational and clinical workflows. While 86% said they are “fairly confident” they can fully control and govern AI agent actions today, 72% of respondents admitted that some AI tools or agents are deployed without formal IT approval.
Based on responses, operational AI is leading adoption by healthcare organizations. But more than half (57%) of participants ranked security as a top-three concern, citing excessive or unnecessary access by agents that interact with clinical systems as a primary governance risk.
AI agents may access multiple patient care and research systems and retrieve sensitive data and then implement API activity and execute workflows.
These capabilities make it “harder for organizations to maintain visibility, accountability and control,” wrote Dr. Sean Kelly, Imprivata’s chief medical and growth officer and senior vice president of healthcare customer strategy, in the report’s executive summary.
While healthcare should continue to move forward with AI, organizations need clear governance around how AI agents are provisioned and managed, he said.
“An AI agent should be treated as a governable digital identity, with access appropriate to its role, clear limits on what it can do, and a record of its activity that can be monitored and audited,” said Kelly.
Health systems take different approaches to agent identity, the researchers noted in the report, but as agentic AI becomes more autonomous, organizations must place “equal emphasis” on permissions and authorized activities.
“Our hospital previously experienced an anomaly where AI autonomously exported patient information in batches,” said one participating senior manager from a 500-to-749-bed hospital system in the report.
“We were only able to quickly pinpoint the risk thanks to audit logs,” the manager added. “Therefore, we only dare to expand the deployment of AI once our monitoring system is mature.”
Healthcare organizations must learn when they can safely hand decisions to AI, where clinicians need to remain in control and what happens when AI guardrails fail, say most healthcare IT leaders and, notably, patients.
The new survey aligns with previous findings that overall, AI is being used more often at the point of care, the researchers said.
But as healthcare organizations worry about falling behind in AI adoption, their AI strategies are nascent. They are building governance around AI tools as they implement them.
Leaky shadow AI is another problem healthcare leaders are talking about regularly, according to Garry Edwards, vice president of sales for EMEA at Wolters Kluwer Health.
“AI tools are finding their way into clinical settings faster than most organisations can govern them,” he said in a social media post last month.
While not all AI tools should be governed in the same way, every use of AI should be treated as an innovation to be evaluated, according to Lily Liu, digital health division director at Western Health.
The unauthorized or unsanctioned use of AI tools by provider employees poses security and other risks, Liu said during an educational session at the HIMSS26 APAC conference in August.
She said about 800 of the Australian health system’s staff were using unapproved AI.
To address unauthorized AI usage, health organizations should regularly update their AI governance policies as technology evolves, Liu advised before describing a five-step assurance process that determines whether a proposed AI use case is appropriate.
“As AI agents act on behalf of clinicians and staff, organizations need to understand what those systems can access, what they’re authorized to do and how their activity can be monitored and reviewed,” said Kelly. Healthcare IT News















Leave a Reply