Healthcare technology leaders face a governance problem that begins after an AI agent is allowed to act. An Imprivata survey conducted by research company Vanson Bourne found that 88% of healthcare leaders expect AI agents to operate with some degree of autonomy, while tools can already enter organizations outside formal IT approval. The immediate challenge is adapting identity and access controls fast enough to keep autonomous activity visible, authorized and accountable.

Imprivata, an access management solution vendor, engaged Vanson Bourne to survey 250 U.S. healthcare leaders responsible for identity security and/or AI strategy. Because Imprivata sells access management solutions, it has a commercial stake in organizations treating agent identity and access as a governance requirement. Its findings should therefore be read as vendor-sponsored research, with the survey figures as the underlying evidence.

Agentic AI adoption stage in the Imprivata/Vanson Bourne survey Share of respondents
Deployed 28%
Conducting pilots or proofs of concept 44%
Expected deployment within the next year 21%

Healthcare is moving from approving AI to governing autonomous actors

Expected autonomy changes what approval has to accomplish. Once an agent can work across clinical and operational workflows with some independence, approving the underlying tool leaves further decisions about which identity represents the agent, which resources that identity can reach, what actions it may perform, and how the organization reviews those actions afterward. Governance consequently has to extend into the agent’s operation and cover the authority exercised after deployment.

That requirement is immediate because healthcare organizations already span deployment, pilot and planned-use stages. Teams have to create controls that work for agents in production while also fitting systems moving toward production. Controls that require extensive redesign for every new agent could become difficult to apply consistently as adoption expands, so identity and access decisions have to become part of deployment itself.

The expected payoff explains why agentic AI is moving quickly

The pressure to deploy comes from what healthcare leaders expect the technology to accomplish. Respondents to the Imprivata/Vanson Bourne survey estimated that agentic AI already participates in about a third of clinical operational workflows, while 79% expect it to have a “transformative” impact on clinical workflows and 73% expect the same for operational workflows. Those expectations place agentic AI across substantial parts of clinical and administrative work rather than within a narrow experimental use case.

The expected impact spans several kinds of benefit. Imprivata’s survey found substantial expectations across operational, clinical and governance outcomes. The security result matters because a majority of respondents see agentic AI as potentially improving the same governance environment that has to control the agents themselves.

Expected benefit from agentic AI in Imprivata’s survey Share of respondents
Operational, efficiency or productivity gains 90%
Clinical or patient-impact gains 70%
Security, governance or compliance benefits 60%

Expansion and tighter controls can advance together. A system can improve workflows and patient impact while still creating problems when its access or authority is poorly defined, because expected value does not determine whether a particular action is authorized. For healthcare technology leaders, the management problem is to preserve the expected gains while making each agent’s authority explicit.

Okoone experts
LET'S TALK!

A project in mind?
Schedule a 30-minute meeting with us.

Senior experts helping you move faster across product, engineering, cloud & AI.

Please enter a valid business email address.

Deployment is already outrunning formal approval and provisioning

The gap first appears when tools enter the organization. Imprivata’s survey found that 72% of respondents said agentic AI tools are occasionally implemented without IT approval. Tools introduced without IT leadership approval constitute “shadow AI,” so the finding describes organizations in which bypassing approval occurs at least occasionally; the percentage measures respondents reporting the practice.

Shadow AI becomes more consequential when software can act autonomously because approval alone cannot define how an agent participates in other systems. The survey found that 57% of healthcare leaders rank security among their top three concerns about deploying agentic AI. The concern connects the entry point to the operating model: once an autonomous tool reaches the environment, the organization needs controls over the identity and authority it uses there.

Provisioning exposes the control problem more precisely. Provisioning means giving an AI agent a unique digital identity and setting limits on its permissions, and 37% of respondents reported an ad-hoc or unapproved approach to that process. An agent can consequently reach use without the formal identity and permission decisions that determine what it can do, leaving the organization with a deployment that may be approved at one level while its operating authority remains weakly governed.

Approval and provisioning solve different parts of the same problem. IT approval determines whether a system may enter use, while provisioning establishes the identity and permitted reach through which an agent operates. For software that can act for a person, weak provisioning can leave uncertainty about which access belongs to the agent and which actions its authority permits, even where the organization supports the broader use of AI.

Formal leadership structures can coexist with this execution gap. Among respondents at organizations with a chief AI officer, 73% reported that agentic AI can be deployed without IT approval; among those at organizations with a CIO, 54% reported the same. The comparison supports a narrow conclusion: appointing an executive responsible for AI can coexist with shadow AI, because individual deployment and provisioning still depend on controls applied when people introduce or authorize agents.

The distinction separates organizational leadership from enforcement at the point of use. A chief AI officer can provide direction around AI strategy and governance, while individual agents still enter systems through deployment and provisioning processes. Technology and security leaders therefore have a second task after assigning executive ownership: connect that ownership to the identities and permissions under which agents actually operate.

Autonomy turns the governance gap into an identity-and-access problem

The consequences become clearer in healthcare because agents can encounter regulated information and perform actions for clinicians or staff. Imprivata’s survey found that half of surveyed leaders were concerned about potential compliance or regulatory violations, while 48% were concerned about unauthorized access to protected health information. Those concerns depend directly on authorization boundaries because an autonomous agent’s identity determines which resources and actions the organization can associate with it.

Sean Kelly, Imprivata’s chief medical and growth officer and senior vice president, customer strategy, healthcare, described the deployment pressure: “For many healthcare organizations, the conversation about agentic AI is focused on where it can have the greatest impact and how it can scale across the organization,” Kelly said. Because Imprivata sells access management solutions, Kelly and the company have a commercial interest in organizations treating identity controls as necessary infrastructure for that scale. His argument connects the survey’s adoption expectations to the access-management problem his company serves.

Kelly then described the controls he sees as necessary: “As AI agents act on behalf of clinicians and staff, organizations need to understand what those systems can access, what they’re authorized to do, and how their activity can be monitored and reviewed.” His formulation breaks the problem into operational steps: associate an agent with an identity, establish its permitted resources and actions, constrain its authority, observe its activity, and retain enough visibility to review what it did. Each step makes delegated authority more explicit.

Monitoring follows from that delegation because autonomy changes when human control occurs. When software performs actions on another person’s behalf, authorization has to establish acceptable action in advance, while monitoring and review provide evidence of how the delegated authority was exercised. Identity connects the two stages by giving the organization a consistent actor to authorize before an action and examine afterward.

That connection makes identity part of accountability. Compliance and protection of health information depend on knowing which actor had access, which actions that actor was permitted to take, and what it actually did. As autonomous agents take a larger role in clinical and operational work, software identities have to support those questions alongside the identities already used for people.

Most leaders expect adaptation of existing governance

The identity problem still leaves healthcare leaders expecting to build on their existing governance foundations. Imprivata’s survey found that 86% of respondents are confident that they have, or soon will have, visibility into AI-agent activity. That confidence matters because visibility is a prerequisite for monitoring and review, yet confidence in the outcome still leaves an architectural question about how identity and access management will produce it.

That architectural question divides respondents among several approaches. The largest group believes its current identity model can be the base with changes, while smaller groups favor dedicated agent identities inside existing frameworks or a separate identity class. The differences matter because each approach implies a different degree of change to identity architecture and control design.

View of AI-agent identity in Imprivata’s survey Share of leaders
Current approach is mostly sufficient but needs adaptation 48%
Agents need dedicated identities within existing frameworks 20%
Agents require a new identity class with distinct controls 12%

The split creates a practical tension between expected visibility and the mechanism used to achieve it. High confidence that agent activity will become visible does not settle how individual agents should be represented, authorized and observed within identity and access management. Technology leaders therefore have to turn that confidence into implementation choices about identity boundaries, permissions and review.

The distribution also makes adaptation the leading near-term approach among respondents. Existing identity foundations can provide a starting point when organizations define how an autonomous agent receives an identity, inherits or receives permissions, and leaves an activity record that can be reviewed. The substantive decision is how much those foundations must change to make delegated software activity visible and accountable as agent autonomy expands.

Key executive takeaways

  • Govern autonomous actors: Healthcare organizations are moving quickly from AI pilots to autonomous agents operating across clinical and operational workflows. Technology and security teams need controls that define each agent’s identity, authority and accountability throughout deployment.
  • Connect expected gains to governance: Healthcare leaders expect agentic AI to improve productivity, clinical outcomes and security, which will accelerate adoption. AI owners can preserve those gains by making access boundaries and delegated authority explicit as agents enter more workflows.
  • Close approval and provisioning gaps: Seventy-two percent of respondents report that agentic AI is occasionally implemented without IT approval, while 37% report ad-hoc or unapproved provisioning. IT and AI governance teams need deployment processes that connect approval to unique identities, defined permissions and enforceable access controls.
  • Make identity the basis for accountability: Autonomous agents acting for clinicians or staff create compliance and protected-health-information risks when their authority is unclear. Identity and security teams can establish accountability by assigning agent identities, limiting permissions and retaining activity records for monitoring and review.
  • Adapt identity architecture for AI agents: Nearly half of surveyed leaders expect existing identity approaches to work with adaptation, while others anticipate dedicated agent identities or distinct controls. IAM owners need to decide how agents will be represented, authorized and monitored before autonomy expands further.

Alexander Procter

October 2, 2026

9 Min

Okoone experts
LET'S TALK!

A project in mind?
Schedule a 30-minute meeting with us.

Senior experts helping you move faster across product, engineering, cloud & AI.

Please enter a valid business email address.