New research finds unmanaged AI workflows, unclear accountability and rising executive liability concerns are pushing AI governance into the boardroom
A growing “shadow agent” problem is emerging as enterprises accelerate their adoption of AI faster than governance frameworks can keep pace, according to new research from Veeam.
The study found that 70% of organisations admit automated AI workflows are interacting with sensitive corporate data without full oversight. Meanwhile, 67% said employees are creating autonomous AI workflows that IT teams cannot fully track, highlighting a widening gap between AI adoption and enterprise control.

The challenge is also moving beyond the IT department. Rising regulatory pressure and corporate accountability are making AI governance a boardroom issue, with 40% of respondents concerned about personal liability and 39% reporting increased board-level scrutiny. More than one-third said the growing responsibility has increased personal stress or executive conflict.
“Trying to control thousands of autonomous agents one-by-one simply doesn’t scale. To make AI safe at the enterprise level, organizations need to secure, govern and understand the data those agents depend on,” said Tim Pfaelzer, General Manager and Senior Vice President for EMEA at Veeam.

Veeam’s findings suggest that the rapid rise of agentic AI is forcing organisations to rethink traditional approaches to governance. Rather than attempting to monitor every individual AI agent, enterprises increasingly need stronger controls around the data, identities and systems that agents access.
The research also revealed growing investment in sovereign and hybrid AI environments. Forty-one percent of organisations are building local or sovereign AI models to address Shadow AI concerns, while 49% are adopting hybrid approaches that use local models for sensitive data and global AI platforms for broader workloads.

The findings underline a critical message for CIOs and CISOs: AI governance is no longer simply about controlling technology. As autonomous agents gain access to sensitive enterprise information, trusted data, visibility and clear executive accountability are becoming fundamental requirements for scaling AI safely.
