Trending Topics

Shadow AI was only the warning – autonomous agents turn data leakage into boardroom liability
Only two years ago, Shadow AI simply meant an employee pasting a spreadsheet into an unapproved chatbot to try to simplify a task and get things done faster. That was concerning enough. Today, autonomous AI agents have raised the stakes because they can retrieve data, transform it, and trigger actions across connected systems with little human intervention.
Veeam’s EMEA research puts numbers to the problem. Of 1,000 IT, data, and security decision-makers surveyed, 70% said automated AI workflows interact with sensitive corporate data without full oversight. Another 67% reported employee-created autonomous workflows that IT cannot fully track.

The issue is not merely shadow AI. It is shadow agency.
An agent can do more damage
An unapproved chatbot can expose information through careless copy-and-paste. An agent with access to business systems can act on that information: update a record, pass data elsewhere, or initiate a workflow.
Our guide to shadow AI identifies privacy, security and compliance risks. Agents add another question: what authority has the organisation given them?
That concern has reached AI’s developers. Anthropic CEO Dario Amodei recently called for slower frontier-model development so safety work can catch up. OpenAI’s Sam Altman backed the call, while Elon Musk also endorsed it. Their warnings concern more powerful systems than the everyday workflows in Veeam’s survey. Still, the principle travels: capability should not outrun oversight.
Governance starts below the model
Veeam found that 40% of respondents worried about personal liability. It is easy to see why an untracked agent with broad access would trouble a board.
The response is not simply to ban AI.
Organisations need to know which agents exist, what data they can reach and which actions they can take. Least-privilege access, approval for consequential actions, audit trails and a way to stop or reverse faulty workflows should follow.
As we have argued previously, businesses should understand a process before asking an agent to automate it.
An agent is a delegated actor.
Delegation without accountability is how a data-control problem becomes a boardroom one.
