A new survey from digital healthcare security specialist Imprivata has revealed that, while artificial intelligence (AI) is now becoming commonplace in the healthcare workflow, scaled adoption of agentic models lags due to concerns around governance. 

In the survey, Imprivata collected opinions from management across several healthcare organisation types, small and large – including single and speciality hospitals, health systems and academic medical centres. 

Discover B2B Marketing That Performs

Combine business intelligence and editorial excellence to reach engaged professionals across 36 leading media platforms.

Find out more

83% of respondents noted they had deployed AI in some form into their workflow, while only 28% had put agentic forms of the technology to use. Unlike standard AI models, agentic AI is designed to work autonomously to perform tasks. However, respondents also highlighted that they are generally closing this implementation gap, as 44% are currently conducting proof-of-concept projects with agentic AI, while another 21% are looking to introduce the technology into their workflow within the next year. 

This comes as just over three-quarters of the participants say that agentic AI will have a transformative or significant impact on clinical and operational workflows. 

Despite this faith in agentic AI’s capacity, 72% report that AI tools or agents are deployed without formal IT approval “at least occasionally”, signalling that some tools are appearing outside of the formal governance process and the technology is often being adopted in a fragmented manner. 

This is despite just under eight in 10 participants identifying security, model identity or governance issues as one of the most significant barriers to scaling the use of agentic AI, while 57% and 49.6% rank excessive access permissions and potential compliance or regulatory violations as some of the top concerns when implementing such tools. 

Achieving effective AI governance and sound compliance 

To ensure that AI governance is effectively introduced, Imprivata says that there must be defined rules around agent identity and what information an AI is authorised to access. Furthermore, the company stresses the importance of active and continuous monitoring, which should be tailored depending on the level of risk a model poses to the system – meaning agents performing certain, higher-risk activities will likely require more guardrails in place, such as human approval or step-up authentication. 

While human-led governance remains key in ensuring agentic AI is acting as it should, respondents are increasingly looking to determine when human review is necessary. According to the survey, the primary areas of focus for enhanced human monitoring fall into higher-risk areas of the clinical workflow, where agents can potentially access electronic health records (EHRs), retrieve patient health information and support clinical decision-making that directly influences patient care. 

As high-risk governance remains a key consideration, Imprivata also raises the need for widespread accountability across multiple teams, which can extend all the way from executive leadership to operational departments, cybersecurity, IT, clinical leadership and legal. 

Though stronger safeguards are needed for higher-risk agents, Imprivata says that all AI tools must be logged, monitored and controlled, regardless of the origin, while their activity should be explainable during an audit. 

With agentic AI increasingly making its way into healthcare, its effective implementation backed by airtight governance and compliance procedures will allow providers to safely relieve administrative burden and improve usage of resources, while boosting operational resilience and the efficiency of healthcare delivery by clinicians. 

A GlobalData report found that among healthcare providers, pharmaceuticals, and medical devices, the combined AI market was valued at $11.9bn in 2024 and is expected to reach $57.4bn by 2029, representing a compound annual growth rate (CAGR) of about 37%.