Unmanaged AI 'Shadow Agents' Pose Data Security and Governance Risks in EMEA Enterprises

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Veeam research reveals that 70% of EMEA organizations have automated AI workflows accessing sensitive data without full oversight, and 67% report employees creating autonomous AI workflows beyond IT control. This lack of governance raises risks of data exposure, compliance breaches, and executive liability across the region.[AI generated]

Why's our monitor labelling this an incident or hazard?

The article explicitly involves AI systems in the form of autonomous AI workflows ('shadow agents') interacting with sensitive corporate data without full oversight, which is a clear AI system involvement. The event stems from the use and governance challenges of these AI systems. Although no direct or indirect harm has yet occurred or is reported, the article outlines credible risks of data exposure, compliance breaches, and legal liabilities that could plausibly lead to harms such as violations of rights, harm to property (data), and organizational disruption. The focus is on potential future harms and governance challenges rather than a realized incident or a response to a past incident. Hence, the classification as an AI Hazard is appropriate.[AI generated]
AI principles
Privacy & data governanceAccountability

Industries
Digital securityBusiness processes and support services

Affected stakeholders
Business

Harm types
Human or fundamental rightsEconomic/PropertyReputational

Business function:
Other

AI system task:
Goal-driven organisation


Articles about this incident or hazard