Healthcare’s agentic AI rollout outpaces governance: survey

- 72% of AI leaders say tools are deployed without IT approval at times.
- More than 85% say they can fully govern autonomous AI agents.
- More than a quarter have already implemented agentic AI.
- Vanson Bourne ran the survey on behalf of Imprivata.
MASSACHUSETTS, UNITED STATES — Healthcare organizations are deploying agentic artificial intelligence (AI) faster than they are building the controls to govern it, with 72% of AI leaders admitting that tools go live without information technology (IT) approval at least occasionally.
More than 85% of the same leaders say they are confident they have visibility into AI agent activity and can fully control an autonomous agent’s actions.
Confidence in AI governance outruns reality
The findings come from a survey by digital identity security firm Imprivata, conducted on its behalf by market research firm Vanson Bourne, according to Healthcare Dive.
More than a quarter of leaders have already implemented agentic AI, another 44% are piloting it or running proof-of-concept projects, and 21% plan to implement it within the next year.
Healthcare Dive noted that the sector has invested heavily in agentic AI for back office uses such as prior authorization and revenue cycle management (RCM) automation.
More than half of respondents ranked security among their top concerns when adopting agentic AI.
“If an agent has excessive permissions, operates outside its intended scope, or takes a high-risk action without appropriate oversight, the consequences can directly impact care delivery,” said Dr. Sean Kelly, chief medical and growth officer and senior vice president of customer strategy at Imprivata.
Shadow AI and fragmented oversight still persist
Shadow AI, when employees use tools their organizations have not authorized, remains rampant despite leaders’ confidence, Healthcare Dive reported.
A separate Wolters Kluwer survey found 40% of medical workers and administrators were aware of colleagues using unauthorized AI tools, and nearly 20% had used an unsanctioned tool themselves.
Imprivata’s survey shows fragmented approaches, with IT departments centrally managing some agents, security teams managing others and some organizations reporting ad hoc or unapproved deployments.
Oversight also varies widely depending on whether an agent is deployed in an administrative, operational or clinical setting.
“Oversight must match the level of clinical risk. Agents need clearly defined identities, permissions, and boundaries, with human review for higher-risk activities and an audit trail for accountability,” Kelly said.
For hospital leaders, the governance gap reaches the back office, where any outside medical coding or RCM partner working alongside AI agents would need the same defined identities, permissions and audit trails Kelly describes.
Health systems comparing the top U.S. healthcare outsourcing companies can make agent permissions and audit trails part of vendor due diligence, alongside the human review that clinical and billing work still requires.
Related news
- AI agents outnumber humans, governance lags: report · 3 Sep
- R1 to acquire Humata for AI prior-auth automation · 27 Aug
- AI can elevate, not replace, health workers: report · 25 Aug
Disclosure: Outsource Accelerator uses AI tools in the backend of its editorial workflow. Every article is reviewed and verified by a human editor before publication.
Stay ahead in healthcare outsourcing. Join thousands of healthcare and business leaders who rely on Outsource Accelerator for the news, trends, and expert insights shaping medical BPO and the future of care delivery. Subscribe to our free newsletter and never miss an update.

Independent




