Nutanix research reveals that healthcare, financial services and public sector organizations face growing risks as AI adoption accelerates faster than infrastructure readiness and governance frameworks.
The artificial intelligence revolution is entering a more complex phase for some of the world’s most regulated industries. Healthcare providers, financial institutions and public sector organizations are rapidly moving AI from experimentation into real-world operations. Yet as adoption accelerates, organizations are discovering that the biggest challenge may not be the technology itself, but the infrastructure, governance and data controls required to deploy it safely.
New industry-specific findings from Nutanix’s eighth annual Enterprise Cloud Index (ECI) reveal a common tension across these sectors. Organizations want to take advantage of generative AI, agentic AI, predictive analytics and automation, while simultaneously protecting sensitive information, meeting regulatory requirements and maintaining control over where data is stored and processed.
The emergence of shadow AI is making that challenge more urgent. Employees and business units are increasingly using AI applications outside approved IT governance and security frameworks. In highly regulated industries, such behavior can expose patient records, financial information, citizen data and confidential corporate information to significant risks.
Nutanix’s research suggests that data sovereignty, security and governance are consequently moving from being infrastructure considerations to becoming central components of enterprise AI strategies.
“Organizations across every industry are working to move their AI projects from experimentation to delivering real business value, but the infrastructure requirements vary significantly depending on sector and workload,” said Thomas Cornely, EVP of Product Management at Nutanix. “The one consistent factor is a need for infrastructure and operating models that deliver flexibility, resiliency, and security to run both traditional and AI-powered applications at scale.”
“Data sovereignty, security, and governance are becoming essential foundations for AI adoption, particularly in healthcare, financial services, and the public sector.”
— Mohammad Abulhouf, Vice President & GM, Middle East & Africa, Nutanix
Healthcare: AI Innovation Meets Sensitive Patient Data
Healthcare faces perhaps the most sensitive AI infrastructure challenge. Hospitals and healthcare providers are exploring AI for clinical decision support, predictive analytics, administrative automation, patient engagement and operational optimization. But the data required to power these applications is among the most sensitive information organizations possess.
According to the Nutanix Healthcare ECI Report, 72% of healthcare IT leaders identify data sovereignty as a top infrastructure priority, while 83% view unauthorized shadow AI tools as a critical business and data risk.
The findings demonstrate why healthcare organizations cannot treat AI adoption simply as a software deployment exercise. Patient data must remain protected throughout its lifecycle, including when it is processed by AI systems or transferred between infrastructure environments.
Healthcare organizations are also preparing for increasingly sophisticated AI capabilities. Over the next three years, 62% expect to use generative AI, 57% expect to use agentic AI or autonomous agents, and 55% expect to deploy predictive analytics or machine learning models.
The rise of agentic AI could make governance even more complicated. Autonomous AI systems can potentially interact with applications, access information and initiate actions, making it essential for healthcare organizations to understand what data these systems can access and how their activities can be monitored and audited.
Application containerization is emerging as an important part of this modernization journey. Containers can provide portable and consistent environments for modern applications while helping organizations maintain control over where workloads run.
Benjamin Urquhart, Chief Technology Officer at Five Horizons Health Services, said healthcare organizations must modernize without compromising privacy.
“As we expand facilities and scale modern applications, our underlying infrastructure must deliver localized performance and resilience without compromising patient data privacy,” he said. “Healthcare organizations are feeling increasing pressure to support AI workloads while ensuring governance, security, and operational consistency across the environment.”
The message for healthcare CIOs is straightforward: AI strategy and infrastructure strategy can no longer be separated. Clinical innovation must move alongside security, compliance and data governance.
Financial Services: AI Growth Under Regulatory Constraints
Financial services has emerged as another major AI adoption center. Banks, lenders, insurers and other financial institutions are deploying AI across customer service, fraud detection, risk management, personalization, anomaly detection and operational processes.
Yet financial organizations must balance this innovation with stringent requirements governing financial and customer data.
The Nutanix Financial Services ECI Report found that 86% of financial sector executives believe unmanaged shadow AI tools introduce severe business risk. At the same time, 79% of financial services IT leaders identify data sovereignty as a high priority or must-have requirement.
These concerns are influencing infrastructure strategies. Public cloud use among financial services organizations stands at 62%, reflecting the continuing need to balance cloud flexibility with security, compliance and data protection.
AI is nevertheless accelerating modernization. Ninety percent of financial services IT leaders report that AI is meaningfully accelerating container adoption, highlighting the growing role of containerized environments in supporting modern workloads across hybrid infrastructure.
The use cases are becoming increasingly diverse. Financial institutions are exploring AI for branch personalization, customer support, point-of-sale anomaly detection and predictive ATM maintenance. Conversational and agentic AI are also expected to have a significant impact, with 62% of financial services IT leaders expecting these technologies to materially improve customer or employee experiences.
The key issue is therefore no longer whether financial institutions will use AI. It is how they can scale AI while maintaining the trust, resilience and regulatory controls expected of the sector.
Dr. Caleb Ondrusek, EVP Technology and Innovation at Fairway Home Mortgage, said organizations need to bridge the gap between AI ambition and operational reality.
“AI has the potential to transform how we support our families in the homebuying journey, but to truly deliver on that promise, we must bridge the gap between innovation and operational reality,” he said.
This balance will become increasingly important as AI moves deeper into customer-facing and mission-critical financial applications.
Public Sector: Modernization With Accountability
Government agencies and educational institutions face a different but equally complex challenge. They are under pressure to modernize citizen services, improve operational efficiency and use AI to deliver better outcomes, while simultaneously protecting public information.
According to the Nutanix Public Sector Report, 91% of government and education IT leaders believe unvetted AI usage creates severe mission and security risks.
Infrastructure readiness is another major concern. Seventy-three percent of public sector infrastructure is currently considered unready to run complex AI workloads on-premises.
This gap is particularly significant as governments explore AI for benefits eligibility, fraud detection, citizen services, education and administrative operations.
Application containerization is expected to play an increasing role. Eighty-seven percent of public sector technology leaders expect their reliance on application containerization to increase over the next three years.
But technology alone cannot address shadow AI. Government organizations must also establish clear policies, educate employees and provide secure AI environments that allow staff to innovate without bypassing governance.
Shane McDaniel, Chief Information Officer at the City of Seguin, Texas, describes shadow AI as a governance challenge.
“Enthusiasm without guardrails creates risk, and shadow AI isn’t just a security concern; it’s a governance gap,” he said.
The implication is that governments may need to move beyond simply restricting AI usage. Instead, they must create frameworks in which employees can use AI productively while ensuring sensitive information remains protected.
The Middle East’s AI Governance Imperative
The Nutanix findings have particular relevance for the Middle East and Africa, where governments and enterprises are making significant investments in AI, cloud modernization and digital transformation.
As AI moves into critical services, organizations are increasingly asking three fundamental questions: Where does the data reside? Who can access it? And where is the AI workload processed?
These questions are becoming particularly important in healthcare, banking, government and other regulated sectors, where data sovereignty requirements can influence infrastructure architecture.
Mohammad Abulhouf, Vice President & GM, Middle East & Africa, Nutanix, said organizations across the region are embracing AI to improve services, accelerate innovation and strengthen resilience.
“But as AI moves from experimentation into everyday operations, the conversation is shifting from what AI can do to how it can be deployed responsibly,” he said.
For Middle Eastern organizations developing sovereign cloud and national AI capabilities, this shift could prove decisive. Hybrid infrastructure can provide organizations with greater flexibility to determine which workloads remain on-premises or within sovereign environments and which can operate in public cloud platforms.
Breaking Down the Silos
Across healthcare, financial services and the public sector, one issue repeatedly emerges: organizational and technology silos.
AI projects often begin inside individual departments, while infrastructure, security, compliance and data teams operate separately. As AI applications begin accessing enterprise data and interacting with business systems, these silos can turn into significant governance vulnerabilities.
Organizations therefore need a unified approach to AI infrastructure. Hybrid and multicloud environments can provide flexibility, allowing workloads to be positioned according to security, performance, cost and sovereignty requirements.
Containerization can further support this model by providing a consistent application environment across different infrastructure platforms.
However, technology must be accompanied by governance. CIOs and CISOs need frameworks covering approved AI tools, data access, model usage, monitoring and accountability.
From Shadow AI to Governed AI
The growth of shadow AI should not simply be viewed as an employee security problem. It is also an indication that employees see value in AI tools and are willing to adopt them even when formal IT strategies have not caught up.
Organizations that respond only by blocking AI applications could push usage further underground. A more effective approach is to understand where AI is already being used, identify the information being shared with these tools and provide secure, approved alternatives.
For healthcare, that means enabling AI innovation while protecting patient information. For financial services, it means deploying intelligent applications without compromising customer trust or regulatory requirements. For government, it means using AI to improve public services while protecting citizen data.
The common objective is governed AI: AI that is innovative without becoming uncontrolled, distributed without becoming invisible and accessible without compromising data sovereignty.
Nutanix’s research indicates that the next phase of enterprise AI will be determined not only by the capabilities of AI models, but by the infrastructure underneath them.
As regulated organizations move from pilots to production-scale AI deployments, the winners are likely to be those that recognize that responsible AI is not simply a software or policy challenge.
It is an infrastructure challenge, a governance challenge and, ultimately, a trust challenge.
