Enterprises are deploying AI agents faster than their governance structures can adapt, according to a report from AWS's Reimagine 2026 initiative. The findings draw on confidential interviews with 154 executives across 128 organizations, plus a survey of European businesses. More than half of those surveyed use AI, but only 24% have a documented approach to responsible AI use, and just 10% have a data governance strategy.

Slow, legacy review processes are a key problem. Processes designed for six-month IT programs are being applied to work that takes days, which pushes teams to bypass approval. One leader described shadow AI as shadow IT at ten times the scale. Organizations also worry about data leakage through third-party tools, and privacy concerns arise when AI mines employee emails and meeting notes. Houston Methodist found it took a year of experience before staff trusted that the system only surfaced group-level patterns and left personal content alone.

Some organizations are building governance into systems. Bradesco uses a classification tree to sort AI projects by risk, and the report advises limiting agent autonomy initially, like probation for a new hire. Security limits should be set outside the agent, since agents can misinterpret embedded rules. Regulatory differences across jurisdictions complicate matters, as Standard Bank's CTO noted.

Wide usage does not guarantee results. One organization appeared 88% adopted, but produced better work in fewer than one in 5,000 sessions. And without a plan for reallocating saved time, productivity gains may not benefit the company. The report also highlights a growing junior talent gap, as AI removes the repetitive work that once built judgment in early-career employees.