Seven out of ten EMEA organizations acknowledge that unsupervised, automated AI workflows affect sensitive business data. Two-thirds observe employees building autonomous workflows that IT cannot fully track.
This is according to a study by Veeam. AI agents appear to be entering organizations faster than governance can keep up. Of the EMEA organizations surveyed, 70 percent say that automated AI workflows sometimes handle sensitive business data without supervision. Another 67 percent report that employees are setting up autonomous workflows on their own that remain outside IT’s purview.
Germany stands out. There, 81 percent of executives admit that workflows access sensitive data unchecked, and 79 percent see “shadow workflows” emerging that IT teams cannot track. In the United Kingdom, 75 percent say they lack sufficient insight into how AI agents handle sensitive data.
Executives are feeling the pressure
According to the study, AI governance is shifting from the technical back office to the boardroom. Fifty-eight percent of organizations are now subject to new legislation regarding corporate responsibility. At 12 percent of these organizations, individual responsibilities remain unclear.
Executive teams are noticing this. 40 percent of executives are concerned about personal liability, 39 percent are seeing increased oversight from the board of directors, and 37 percent are experiencing more stress. For 32 percent, this has led to tensions with other executive team members. Yet there is also a silver lining. 45 percent report better alignment among leadership teams and greater focus on cyber resilience.
Proprietary models against shadow AI
Organizations are investing, however. In EMEA, 41 percent are building their own local or sovereign AI models to combat shadow AI. 49 percent are opting for a hybrid approach: local models for sensitive data and public models for more general tasks. The situation is different in the Middle East and Africa, where 41 percent rely on public AI providers for all applications.
Opinions are divided on the EU AI Act. 83 percent expect a positive impact on cyber resilience, but 62 percent view “gray areas” as a compliance risk, and 63 percent fear unintended operational or legal consequences. In the United Kingdom and Germany, those percentages are higher at 74.4 percent and 73.6 percent, respectively.