Boards aren’t arguing about AI anymore. They’re arguing about who’s liable for it.

For many organisations, artificial intelligence has arrived long before a formal AI strategy has been developed.

Seventy percent of EMEA organisations admit their autonomous AI workflows are already touching sensitive corporate data without full oversight. Sixty-seven percent have employees building autonomous AI workflows that IT can’t fully track. And nearly a third say rising regulatory pressure is already creating open tension among executives.

Those numbers come from new research Veeam Software released in September 2026, based on a survey of 1,000 enterprise IT, data and security decision-makers across the UK, Germany, France, and the Middle East and Africa, all at organisations with more than 500 employees. Read together, they describe something more specific than “AI adoption is fast.” They describe a governance gap that has already reached the boardroom, and a group of executives who are starting to feel personally exposed by it.

The shift from a technology problem to a personal one

The most telling numbers in the survey aren’t about the technology at all. They’re about the people responsible for it.

Fifty-eight percent of the organisations surveyed said they now fall under new corporate accountability laws. Forty percent of respondents said they’re personally worried about liability or consequences from deploying autonomous AI systems. Thirty-nine percent reported greater board-level scrutiny, and thirty-seven percent said the increased accountability had contributed to real personal stress.

That’s a meaningful shift in framing. For most of the last few years, AI governance conversations centred on the organisation, its risk exposure, its regulatory obligations, its reputational stakes. This data suggests the conversation has moved a level down, to named individuals now asking whether they, personally, could be held responsible for a system they don’t fully understand and can’t fully see.

Tim Pfaelzer, Veeam’s GM and SVP for EMEA, put the underlying problem plainly: trying to control thousands of autonomous agents one by one simply doesn’t scale.

Shadow AI isn’t shadow IT with a new name

It’s worth being precise about what the survey is actually describing, because “shadow AI” gets used loosely. This isn’t primarily about someone pasting a client list into a public chatbot, the problem organisations have spent the last two years training staff to avoid.

It’s autonomous workflows, agents that take actions, chain tasks together, and interact with corporate data on an ongoing basis, often built by employees who never set out to create a governance risk. Nobody sat down and wrote a “how do we govern this” document, because nobody sat down and formally decided to build it at all. It simply got connected, the way a chatbot might quietly get linked to a CRM.

That’s precisely the pattern that breaks conventional oversight. You can write a policy that says “AI tools must be approved before deployment.” You cannot easily write a policy that catches an agent a well-meaning employee built last Tuesday to save themselves two hours a week, one that’s now quietly pulling from a system it was never assessed against.

Why the response is architectural, not just procedural

Organisations are already responding, and the survey’s most interesting finding may be how. Forty-one percent of EMEA organisations are now building local or sovereign AI models specifically to contain shadow AI risk. A further 49% are running a hybrid approach, sovereign or local models for sensitive workloads, global models for everything else.

That’s a genuinely significant shift in how organisations think about AI infrastructure, and it’s a sensible one. But it solves a narrower problem than the one the rest of the survey describes. Where a model runs doesn’t answer who’s accountable for what it touches, whether that use case was assessed before it went live, or whether the organisation could show a regulator, or a board, or an auditor, exactly which data an agent had access to and why.

Infrastructure decisions and governance evidence are two different problems, solved by two different disciplines. Organisations that only solve the first one are choosing where the shadow AI risk lives, not whether it exists.

What this looks like from where we sit

Everything in this survey maps directly onto the convergence we keep coming back to across every jurisdiction we track: privacy governance and AI governance aren’t two separate compliance problems anymore. They’re the same evidence requirement, applied to a system that increasingly makes its own decisions about what data it touches next.

South Africa is part of this survey’s footprint too, and King V’s Principle 10 already places data, information and technology governance, AI explicitly included, on the board’s own desk, with a requirement to state whether governance outcomes were actually achieved, not just attempted. A board that can’t currently answer “which of our AI workflows touch sensitive data, and who approved that” isn’t meeting that bar today, regardless of how the underlying models are hosted.

The 32% of executives already reporting boardroom tension over this aren’t imagining the exposure. They’re the first ones to notice that the gap between “we have an AI policy” and “we can show exactly what our AI systems are doing right now” is where the actual risk sits, and that gap doesn’t close because a model moved to sovereign infrastructure.

The practical question underneath the anxiety

Strip the stress and the boardroom tension away, and the survey leaves one operational question every organisation using AI at any scale needs to be able to answer, on demand, not eventually:

Do you know which autonomous AI workflows are currently running in your organisation, what data each one can access, who approved it, and when it was last reviewed?

If the honest answer involves the word “roughly,” that’s the gap. Not a shortage of policy, a shortage of continuously current, evidenced answers to a question regulators, boards and auditors are all now asking in slightly different words.

Talk to our team about closing it before the next board meeting asks the question first.

Russell Raizenberg – PrivIQ, Head of Customer Success

Stay ahead of what's changing.

Book a meeting, explore the platform, or take the free assessment to see where your programme stands.