A new survey exposes a critical security and compliance gap as nearly three-quarters of health systems deploy AI tools without proper authorization or oversight.

Healthcare organizations are racing to capitalize on artificial intelligence's potential to streamline operations and improve patient care, but a growing governance crisis threatens to undermine those ambitions. New research from Imprivata reveals that 72% of U.S. health systems are actively running AI applications that lack formal approval or oversight mechanisms—a phenomenon researchers call "shadow AI" that poses significant risks to patient safety, data security, and regulatory compliance.
The findings, derived from a survey of 250 healthcare leaders across major health systems, integrated delivery networks, and academic medical centers, paint a picture of an industry struggling to balance innovation velocity with responsible deployment. This widespread unauthorized AI adoption reflects a deeper organizational challenge: the gap between clinical and technical teams eager to implement AI solutions and governance structures designed to ensure those tools meet security, privacy, and efficacy standards.
The timing is particularly significant as autonomous AI agents—systems capable of making decisions and taking actions with minimal human intervention—are beginning to enter clinical workflows. Unlike traditional clinical decision support tools that flag recommendations for physician review, autonomous agents operate with greater independence, amplifying the consequences of inadequate oversight. A shadow AI deployment managing patient scheduling or medication alerts without proper validation could cascade into patient safety incidents before anyone realizes the system exists.
From a regulatory perspective, this shadow adoption creates compliance exposure. CMS, the FDA, and state medical boards are increasingly scrutinizing AI deployment in healthcare settings. Organizations running unapproved AI systems may face enforcement action, reputational damage, or liability if adverse events occur. The lack of formal approval trails also complicates the audit documentation these regulators expect to see.
Beyond compliance, shadow AI deployment reflects control and visibility failures that extend into cybersecurity territory. Unauthorized systems often lack the security hardening, monitoring, and incident response integration that vetted platforms receive. Healthcare data breaches already cost the industry billions annually; unsanctioned AI applications represent additional attack surface that security teams cannot adequately defend.
This phenomenon doesn't emerge from negligence alone. Clinical departments and operational teams often face slow formal procurement processes that lag behind technology availability. When a clinician discovers an AI tool that could improve their workflow efficiency, the temptation to deploy it immediately—often through trial licenses or department budgets—can override governance concerns, particularly in under-resourced departments.
Additionally, many health systems still lack centralized AI governance frameworks. Without clear policies defining how AI tools should be evaluated, approved, and monitored, well-intentioned teams simply don't know what approval process to follow. This governance vacuum naturally leads to shadow adoption as the path of least resistance.
For healthcare IT leaders and vendors, these findings signal an urgent opportunity. Health systems desperately need lightweight governance frameworks that don't sacrifice agility for compliance. This means developing approval workflows that operate at technology speed rather than traditional procurement pace, creating visibility tools that identify shadow AI applications, and building governance platforms that integrate security, compliance, and clinical validation assessments.
Vendors who can package AI governance as an enabler rather than a constraint—helping organizations move faster while maintaining control—will find receptive audiences among executives facing mounting pressure to both innovate and manage risk. The 72% figure represents not just a problem, but a massive market signal that the healthcare industry is ready to solve shadow AI through better tools and processes.
Reporting basis: hitconsultant.net. Analysis by the HTC editorial desk.