Shadow AI and data sovereignty threaten regulated sectors globally

Nutanix survey data reveals healthcare, finance, and public sector face the sharpest AI governance deficits of any industry.

A brightly lit, modern control room features a long, curved desk with multiple monitors displaying blue-green digital data, several office chairs, illuminated floor lines, and a large world map on a screen at the back.

Healthcare systems, financial institutions, and government agencies are accelerating AI adoption at precisely the moment their infrastructure is least equipped to govern it safely. That is the headline finding from Nutanix's eighth annual Enterprise Cloud Index (ECI), which surveyed 1,600 cloud and IT executives across 14 countries in November 2025. The regulated-industry deep-dive, published this week, exposes a governance gap that is no longer theoretical: shadow AI and data sovereignty failures are, the company says, transforming standard organisational silos into active compliance vulnerabilities.

The three sectors represent the most data-sensitive corners of the modern economy, and the numbers are striking. In financial services, 86% of surveyed executives believe unmanaged shadow AI tools introduce severe business risk, yet data-protection anxieties restrict public cloud use to just 62% of organisations, even as 79% rate data sovereignty as a high priority. In healthcare, 83% view unauthorised AI tools as a critical risk, and 72% cite data sovereignty as a top infrastructure concern. Public sector leadership is most alarmed of all: 91% agree that unvetted AI usage creates severe mission and security risks, and 73% of public sector infrastructure is currently unready to run complex AI workloads on-premises.

The shadow AI problem is a governance design failure

Shadow AI, where employees or business units deploy AI tools outside approved IT oversight, is a symptom of a structural mismatch rather than a rogue-behaviour problem. Organisations in healthcare, financial services, and government are under simultaneous pressure to modernise quickly and to comply with some of the most stringent data-handling regimes in any industry. GDPR, HIPAA, FCA conduct rules, and sovereign-data mandates all constrain where workloads can run and how data can move. When central IT teams cannot provision approved AI tools fast enough, end-users reach for whatever is available. The result is an uncontrolled proliferation of consumer-grade AI services handling regulated data.

The Nutanix data points to containerisation and hybrid multicloud architectures as the prevailing technical response. In financial services, 90% of IT leaders report that AI is meaningfully accelerating container adoption. In the public sector, 87% expect their reliance on application containerisation to grow over the next three years. Containers allow workloads to run locally or at the edge, preserving data residency and reducing cloud-latency risk for time-sensitive applications such as point-of-sale anomaly detection or, in healthcare, bedside diagnostics.

Cross-sector capital and regulatory implications

The governance deficit described here is not merely a technology procurement story. It carries direct implications for the capital flows and regulatory architecture that frame these three sectors. For investors, the survey data validates a structural tailwind for hybrid infrastructure vendors and enterprise AI-governance platforms. The compliance burden in healthcare and financial services is a durable moat: the organisations cannot simply migrate everything to a hyperscale public cloud and accept the data-sovereignty risk, which means demand for on-premises and edge-compute solutions remains structural rather than cyclical.

From a regulatory standpoint, the EU AI Act, which began applying compliance obligations to high-risk AI systems in 2025, will intensify the pressure on precisely these verticals. Healthcare and financial services are explicitly listed as high-risk deployment contexts under the Act's Annex III categories. For government agencies, evolving digital-sovereignty frameworks across France, Germany, and the Gulf Cooperation Council are already mandating that public-sector AI workloads remain on nationally controlled infrastructure. The Nutanix findings suggest that the infrastructure to comply with those mandates is, for the majority of organisations surveyed, not yet in place.

The forward-looking AI applications organisations expect to deploy compound the urgency. Healthcare respondents anticipate adoption of generative AI (62%), agentic AI (57%), and predictive analytics (55%) within three years. Agentic systems, which make autonomous decisions across workflows, carry materially higher governance requirements than conventional software and represent the sharpest edge of the compliance gap these findings describe. Cross-sector leaders weighing AI infrastructure budgets should treat the regulatory clock, not the technology readiness curve, as the primary constraint.