Nearly three quarters of healthcare organizations have AI tools or agents running without formal IT approval, according to a survey of 250 US healthcare leaders responsible for identity security or AI strategy.
Identity vendor Imprivata commissioned the polling, which Vanson Bourne carried out. It found 83% of organizations running AI in more than one department, and few able to show who signed off on each deployment.
Confidence is running ahead of control. Respondents told researchers they expect to govern AI agents successfully, yet the spread of tools is outpacing the identity, access and oversight models hospitals rely on.
Agents change the access problem
Traditional governance assumes a human logging in. Autonomous agents act on their own, reaching into records and systems with credentials that may never have been reviewed. Each one is effectively a new identity that needs an owner, a defined scope and an audit trail.
Hospitals have been slow to build that scaffolding. Clinical AI often arrives as a pilot that never goes through security review, and staff adopt consumer tools when approved options are unavailable.
Why it matters
Regulators are beginning to ask for inventories of deployed AI, but few health systems can produce one. A tool that cannot be listed cannot be governed, and one running without approval can quietly touch protected health data.
Imprivata’s argument is that identity, not policy documents, is the practical layer where agentic AI gets constrained.
