A Veeam-commissioned Censuswide survey of 1,000 IT, data, and security decision-makers at organizations with 500+ employees across the UK, Germany, France, and MEA finds 70% say automated AI workflows interact with sensitive corporate data without full oversight — and 67% say employees are creating autonomous AI workflows IT cannot fully track.
Germany is hotter still (81% / 79%). In the UK, 75% lack adequate oversight of AI agents on sensitive data. 41% of EMEA organizations are building local or sovereign models specifically to combat shadow AI. 32% say accountability pressure is causing C-suite conflict, and 40% of executives worry about personal liability. Fieldwork ran April 21–27, 2026.
This sits next to yesterday's GTIG story, not opposite it: adversaries are already using agentic tooling at cloud speed, while boards are discovering employees stood up the same class of automation without a named owner.
The first move is still inventory — what agents exist, what data they can reach, who approved them — then a sanctioned path that is faster than the shadow one. Ban-only policies just push the work onto personal accounts you can't see.