AI
Aug 12, 2026
Cloudflare Launches AEO Visibility Dashboard to Measure Whether AI Assistants Recommend Brands
AI


Nutanix research finds healthcare, financial services and public-sector organizations facing growing risks from shadow AI, data sovereignty and infrastructure gaps.
[For more news, click here]
An employee puts confidential information into an AI tool that the IT department never approved. A healthcare provider wants to use AI closer to the point of care but has to keep patient data protected. A government agency sees an opportunity to use AI to improve public services, only to find that its existing infrastructure is not ready for the workload.
These are becoming real operational questions for organizations moving AI from experimentation into everyday use and in industries where sensitive information is involved, the margin for error is much smaller.
New research from Nutanix shows the challenge faced by healthcare, financial services and public sector organizations as AI adoption accelerates. The company’s eighth annual Enterprise Cloud Index found that these highly regulated sectors are dealing with a combination of shadow AI, data sovereignty concerns, compliance requirements and infrastructure gaps.
What Shadow AI is, and Why it is Now a Governance Problem
Shadow AI refers to employees or business units using AI tools without approval or oversight from IT and security teams, the immediate appeal is easy to understand. Employees can find a tool that solves a problem and start using it without waiting for an organization’s formal technology process. The risk is what happens to the information being entered into those systems.
The growing use of AI outside formal IT oversight may be one of the biggest headaches for organizations trying to keep control of their technology environments.
Nutanix data shows that 83% of healthcare organizations consider unauthorized shadow AI tools a critical business and data risk. In financial services, 86% of executives believe unmanaged shadow AI tools introduce severe business risk. Among government and education IT leaders, 91% say unvetted AI usage creates severe mission and security risks.
The figures point to a common problem across very different industries: employees and individual teams are increasingly shaping how AI enters an organization, creating a governance challenge that IT departments cannot solve simply by blocking access.
Why Data Sovereignty is Now Part of the AI Decision
For healthcare and financial services in particular, the question is not only whether an AI application works. It is also where the underlying data is stored, processed, and managed.
Among healthcare providers, 72% of IT leaders cite data sovereignty as a top infrastructure priority. That concern comes as healthcare organizations prepare for greater use of AI in clinical and administrative workflows, including generative, agentic AI and predictive analytics.
Financial institutions face a similar balancing act as they explore AI for customer service, personalization, and other operations. The sector is also operating under strict requirements around data protection, making decisions about cloud and hybrid infrastructure more complicated.
This is where AI adoption begins to overlap with infrastructure strategy. Organizations need enough flexibility to support new workloads while maintaining control over sensitive data and where those workloads run.
"As we expand facilities and scale modern applications, our underlying infrastructure must deliver localized performance and resilience without compromising patient data privacy. Healthcare organizations are feeling increasing pressure to support AI workloads while ensuring governance, security, and operational consistency across the environment. To enable AI safely at the point of care, organizations must break down silos, align technology and clinical workflows, and maintain clear control over how sensitive data is managed. Utilizing a hybrid approach, anchored by Nutanix, can help lean IT teams simplify operations while balancing innovation, compliance, and performance." - Benjamin Urquhart, Chief Technology Officer, Five Horizons Health Services
Infrastructure Gaps Could Slow the Next Stage of AI Adoption
Some organizations are also discovering that their infrastructure was not built with complex AI workloads in mind.
For public-sector organizations, that creates a difficult balancing act. Government agencies and education institutions are already exploring AI for uses ranging from benefits eligibility to fraud detection, but they must do so while protecting public data and working within existing infrastructure and workforce constraints.
Healthcare faces a similar challenge as AI moves closer to the point of care. The infrastructure supporting those systems must account for performance and resilience without losing sight of patient privacy and regulatory requirements.
AI Governance in the Middle East and Africa
The same tension is emerging across the Middle East and Africa, where organizations in regulated industries are looking to AI to improve services and operations while data sovereignty and governance remain central concerns.
“Data sovereignty, security, and governance are becoming essential foundations for AI adoption, particularly in healthcare, financial services, and the public sector,” said Mohammad Abulhouf, Vice President & GM, Middle East & Africa, Nutanix.
What Regulated Organizations Should be Asking Now
For regulated organizations, the question is no longer whether AI has a place in the business. That decision is increasingly being made through everyday use. The harder question is whether governance, data controls, and infrastructure can keep pace.
The opportunity is significant but realizing it will require organizations to move forward without compromising trust, security, or control. Nutanix’s findings suggest that those that get this balance right will be better placed not only to adopt AI, but to make it a lasting and valuable part of how they serve patients, customers, and the public.
Related Articles