Boards are discovering that the same governance gaps that produced shadow IT are reappearing, faster, around AI agents. Veeam’s September 2026 survey of EMEA enterprises puts numbers to a problem that compliance teams have been raising quietly for months.
Seventy-five per cent of enterprises have no clear oversight of the AI agents handling their sensitive data, according to research published today by Veeam, the data and AI trust company. A separate but related finding puts the figure for unmonitored AI workflows even higher: 70% of organisations admit that automated AI processes are touching sensitive corporate data without full visibility into what those processes are doing or what they have changed.
The governance gap is running into a regulatory wall. Fifty-eight per cent of surveyed enterprises now find themselves subject to new corporate accountability laws that impose personal legal responsibility on senior executives for cyber resilience and data compliance. One in eight (12%) say the allocation of individual responsibilities under those laws remains unclear inside their own organisations. Forty per cent of leaders say they personally fear legal consequences from AI non-compliance.
The pressure is translating into boardroom friction. Nearly a third of organisations (32%) say regulatory scrutiny is already generating tension or conflict among executives — a sign that AI governance has left the technical back-office and become a live leadership problem.
The root cause is structural. Sixty-seven per cent of IT departments report that employees are standing up autonomous AI workflows that IT cannot track. The patterns mirror the early years of shadow IT, when business units deployed cloud applications without procurement involvement, except the speed of iteration with AI tooling is considerably faster and the data exposure potentially more consequential. Where shadow IT leaked documents, shadow agents can rewrite them.
In response, enterprises are splitting their bets. Forty-one per cent are building local or sovereign AI models specifically to keep sensitive data under tighter control. Forty-nine per cent are deploying hybrid models that isolate sensitive workloads from general-purpose AI infrastructure. Neither strategy fully addresses the governance problem on its own; both are reactive to the oversight failure rather than preventative.
The research was conducted by Veeam ahead of its planned position as a data and AI trust vendor. Veeam commissioned the survey of EMEA IT and business leaders; the full methodology and sample size were not released with the findings.
To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter