Veeam research: companies struggle with unmanaged AI agents Veeam research reveals that 70% of EMEA organizations acknowledge automated AI workflows sometimes handle sensitive corporate data without supervision, and 67% report employees setting up AI workflows outside IT oversight. The study highlights growing concern over 'shadow agents' and fragmented AI governance amid regulatory pressure from the EU AI Act, with 58% of organizations now falling under new corporate responsibility legislation. Research from Veeam shows that organizations in EMEA are dealing with ‘shadow agents’ and a lack of oversight regarding AI workflows. Organizations in EMEA are experiencing increasing challenges due to the rise of autonomously operating AI agents within their business processes. According to research by Veeam, the lack of oversight and control over these ‘shadow agents’ is leading to growing concern in both IT departments and boardrooms. Companies are faced with a fragmented approach to AI governance, where regulation and personal liability are central. Shadow agents 70 percent of organizations in EMEA acknowledge that automated AI workflows sometimes handle sensitive corporate data without supervision. Additionally, 67 percent indicate that employees set up AI workflows themselves that remain outside the view of IT. Furthermore, another recent study by WatchGuard https://itdaily.com/news/software/64-percent-of-employees-use-ai-tools-without-permission/ Technologies shows that 64 percent of employees use AI tools without supervision. These so-called ‘shadow agents’ pose a direct threat to data protection and compliance, as they can bypass security measures and leave sensitive information unprotected. The problems are not equally distributed everywhere. In Germany specifically, 81 percent of executives admit that unmanaged AI workflows interact with critical data, while in the United Kingdom, 75 percent have insufficient visibility into how AI agents handle sensitive data. Despite attempts to build in more control, shadow agents are spreading faster than governance can follow. Regulatory pressure The introduction of stricter regulations, including the new EU AI Act https://itdaily.be/blogs/business/eu-ai-act-beheersing-van-ai/ , is leading to increased attention to AI governance at the executive level. For instance, 58 percent of organizations now fall under new legislation regarding corporate responsibility. Yet, the division of roles remains unclear: twelve percent of organizations do not know exactly where individual responsibilities lie. This uncertainty is causing stress among executives. 40 percent are concerned about personal liability, 39 percent note increased oversight by the board of directors, and 32 percent experience tensions within the executive team. At the same time, there is more alignment and focus on cyber resilience, which according to Veeam can contribute to better data management. Differences in approach Companies in the EMEA region are responding differently to the challenges. For example, 41 percent of organizations are building their own local or sovereign AI models to gain more control over shadow AI. Additionally, 49 percent opt for a hybrid approach: local models for sensitive data and public models for less critical applications. In the Middle East and Africa, however, 41 percent of organizations rely entirely on public AI providers. This difference is related to the impact of EU regulations, which primarily prompt European companies toward stricter control. Nevertheless, the research shows that supervising thousands of autonomous agents is difficult to scale, making fundamental questions regarding data management and security increasingly important.