New research from Veeam, a company focused on data and AI trust, has unveiled a significant ‘shadow agent’ crisis affecting enterprises across the EMEA region. The study reveals that 70% of organizations acknowledge that automated AI workflows are engaging with sensitive corporate data without adequate oversight. Additionally, 67% of respondents reported that employees are creating autonomous AI workflows that IT departments cannot fully monitor.
The findings underscore a pressing challenge for businesses as they strive to operationalise AI while ensuring that the data driving these technologies remains secure and trustworthy. Without proper governance and visibility, companies risk exposing sensitive information, increasing compliance risks, and jeopardising the foundational trust necessary for scaling AI initiatives effectively.
As regulatory pressures mount, the governance of AI is shifting from technical teams to executive leadership. Approximately 32% of organizations indicated that this pressure is causing conflicts among executives, highlighting the growing importance of AI governance at the board level.
Tim Pfaelzer, General Manager and Senior Vice President for EMEA at Veeam, noted that the increasing complexity of compliance obligations is placing significant responsibility on C-suite executives. The research indicates that 58% of surveyed enterprises are now subject to new corporate accountability laws, with 12% of respondents expressing uncertainty about individual responsibilities.
This heightened accountability is impacting executive teams in various ways: 40% are concerned about personal liability, 39% report increased scrutiny from boards, and 37% experience heightened stress or anxiety. However, 45% of leaders believe that this accountability has fostered better alignment and focus within their teams.
The research also highlights a fragmented approach to AI governance across the region. In Germany, 81% of leaders admitted that automated workflows are interacting with sensitive data without oversight, while 79% reported the creation of untrackable “shadow workflows.” The UK faces similar challenges, with 75% of organizations lacking adequate oversight of AI agents.
Despite significant investments in controlled AI environments, 41% of organizations across EMEA are developing local or sovereign AI models to combat shadow AI. Nearly half are adopting a hybrid approach, utilising both local and global models for different tasks. In contrast, 41% of organizations in the MEA region rely solely on global AI providers, indicating a divergence in governance strategies influenced by the EU regulatory landscape.
Pfaelzer remarked that organizations in EMEA are still grappling with governance in this new era of autonomous agents. He emphasised that the industry needs to shift its focus from controlling individual agents to securing and understanding the data that these agents rely on.
Adding to the complexity is the EU AI Act, which is beginning to take effect with compliance deadlines extending to 2028. While 83% of leaders believe the Act will positively impact organizations, 62% are concerned about ambiguities that could pose compliance risks, particularly in the UK and Germany, where concerns are notably high.
Follow our Tech news coverage for related developments.

