A new survey shows healthcare leaders are struggling to keep track of artificial intelligence tools being used inside their organizations. The report was published on September 15 by access management firm Imprivata and research group Vanson Bourne.
It is titled "The Agentic AI Trust Gap: Why Healthcare Needs Identity-Led Governance." The survey polled 250 healthcare leaders based in the United States.
The findings highlight a growing gap between how fast AI is spreading and how well organizations can monitor it. This includes both approved tools and unapproved ones, often called shadow AI.
Shadow AI refers to AI tools used by staff without formal sign-off from an IT department. These tools can rely on public AI platforms, which raises the risk of sharing patient data outside a hospital's network.
The survey found that 28% of healthcare leaders already have agentic AI running in production settings. Another 44% said they are currently piloting AI agents within their organizations.
Most leaders, 88%, expect AI agents to work with some level of independence across both clinical and administrative tasks. Despite this, 86% said they feel fairly confident they can control and manage what these agents do.
That confidence contrasts with another finding. 72% of respondents admitted that some AI tools at their organization are being used without formal IT approval.
Security Concerns Rise as Agents Gain Access
More than half of the leaders surveyed, 57%, ranked security among their top three concerns tied to AI. Many pointed to agents having more system access than necessary as the main issue.
AI agents can reach into multiple patient care and research systems at once. From there, they may retrieve sensitive data and carry out tasks automatically.
Dr. Sean Kelly, Imprivata's chief medical and growth officer, said this level of access makes it harder for organizations to track what agents are doing. He said hospitals need clear rules about what each agent is allowed to do.
Kelly recommends treating every AI agent like a digital identity. That means giving it only the access it needs for its role, along with a record of its activity that can be reviewed later.
Hospitals Report Real Incidents
Different hospital systems are handling this challenge in different ways. The report notes there is no single standard yet for managing AI agent identities.
One senior manager from a hospital system with 500 to 749 beds shared a specific incident. Their system had an AI tool that exported patient information in batches without approval.
The manager said the hospital was able to catch the issue quickly because of its audit logs. They added that further AI expansion at their hospital will wait until monitoring tools are more mature.
The survey's authors say healthcare leaders are still working out when to trust AI decisions and when clinicians need to stay in charge. This includes deciding what happens if an AI system's safeguards fail.
Garry Edwards, a vice president at Wolters Kluwer Health, said in a social media post last month that AI tools are spreading faster than most hospitals can manage them.
At Western Health in Australia, digital health director Lily Liu said around 800 staff members were found using AI tools that had not been approved. She spoke about the issue at the HIMSS26 APAC conference in August.
Liu recommends healthcare organizations update their AI governance policies on a regular basis. She also described a five-step process her organization uses to evaluate whether a new AI use case is appropriate before it is approved.