Curie Brief
Turn on cookies to sign in
Signing in saves your progress to your Curie account. We can only do that with cookies on — turn them on to continue.

Hospitals are racing to adopt agentic AI, but governance isn't keeping up. A new Imprivata survey finds that 72% of healthcare organizations deploy AI tools without formal IT approval at least some of the time — even as leaders claim confidence in their oversight. Experts warn that unsupervised AI agents could expose patient data, alter medical records, or act outside a clinician's intent.
Healthcare organizations are embracing agentic AI — systems that can make complex, multi-step decisions with minimal human input — at a rapid clip, but their governance frameworks are struggling to keep pace. A new survey by Vanson Bourne on behalf of digital identity firm Imprivata found that more than a quarter of health systems already have agentic AI in production, with another 44% piloting projects. The vast majority expect it to have a transformative impact on clinical and operational workflows.
The confidence, however, doesn't match the reality on the ground. Despite 85% of leaders claiming full visibility and control over AI agent activity, 72% admit these tools are deployed without IT approval at least occasionally — a classic case of "shadow AI." A separate Wolters Kluwer survey reinforced the concern, finding that 40% of medical workers were aware of colleagues using unauthorized AI tools, while nearly 20% had used an unsanctioned tool themselves.
The stakes are significant: agentic AI can autonomously access EHRs, alter medication records, and act under a clinician's authority — all at machine speed — meaning a single error can cascade before anyone notices.
By the Numbers:
Why it matters: Without clear governance — defined agent identities, permissions, audit trails, and human review for high-risk actions — healthcare systems are operating with significant blind spots. Patient safety, data privacy, and care delivery are all on the line.