A new survey from digital healthcare security firm Imprivata shows that while 83% of healthcare organizations have deployed some form of AI, only 28% have put agentic AI to use, with governance and security concerns cited as the primary brake on scaled adoption. The findings arrive as the combined healthcare AI market races toward a projected $57.4 billion by 2029, according to GlobalData.
The survey gathered responses from management across small and large healthcare organizations, including single and specialty hospitals, health systems, and academic medical centers. Agentic AI - designed to work autonomously to perform tasks - is closing the implementation gap, however: 44% of respondents are running proof-of-concept projects, and another 21% plan to introduce the technology within a year. Over three-quarters said agentic AI will have a transformative or significant impact on clinical and operational workflows.
That faith runs headlong into a fragmented reality. 72% reported that AI tools or agents are deployed without formal IT approval "at least occasionally." Nearly eight in 10 identified security, model identity, or governance issues as one of the most significant barriers to scaling agentic AI. 57% flagged excessive access permissions as a top concern, while 49.6% pointed to potential compliance or regulatory violations.
What effective governance looks like
Imprivata's guidance centers on defined rules around agent identity and what information an AI is authorized to access. The company stresses continuous monitoring tailored to risk level - agents performing higher-risk activities require more guardrails, including human approval or step-up authentication. All AI tools must be logged, monitored, and controlled regardless of origin, with activity that remains explainable during an audit.
The survey points to specific areas where human review is most critical. These cluster in higher-risk clinical workflows where agents can access electronic health records, retrieve patient health information, and support clinical decision-making that directly influences patient care. Accountability must span multiple teams, from executive leadership to operational departments, cybersecurity, IT, clinical leadership, and legal.
Closing the gap between pilots and production
The data suggests healthcare organizations are actively working to bridge the trust gap. The 44% running proof-of-concept projects with agentic AI signals that governance frameworks are being built alongside the technology, not after deployment. For teams building internal expertise, structured AI for Healthcare Courses can help clinical and operational staff understand both the capabilities and the compliance requirements of autonomous systems.
As agentic AI moves deeper into healthcare workflows, the organizations that pair deployment with airtight governance stand to relieve administrative burden, improve resource usage, and strengthen operational resilience. The alternative - tools appearing outside formal processes - introduces exactly the security and compliance risks that the survey respondents fear most.
Why this matters for healthcare professionals
For clinical and operational leaders, the survey makes one point clear: agentic AI is arriving whether formal governance is ready or not. The 72% "shadow AI" figure means clinicians and staff are already using autonomous tools that may lack proper access controls or audit trails. Understanding how AI Agents & Automation Courses function - and what guardrails they require - is no longer a future concern. It is a current patient safety and compliance issue that demands cross-disciplinary accountability now.
Your membership also unlocks: