Videos

Shadow AI and Sovereignty Reshape Enterprise AI Infrastructure

Analyst Ron Westfall breaks down why Shadow AI, sovereign data and LLM fragmentation are forcing IT leaders to rethink where and how they run AI.
  • Key Play:Enterprise AI
  • Nutanix-Newsroom:Article, Video
  • Products:Nutanix Cloud Platform (NCP), Nutanix Enterprise AI (NAI)

September 17, 2026

Every IT team now faces many forks in the road: run AI on GPUs or CPUs, on premises or in the cloud. The answer is splitting into a hybrid patchwork that exposes new risks that require simplication and reliance on trusted advisors, according to HyperFRAME Research analyst Ron Westfall.

In a video interview with The Forecast recorded at the April 2026 .NEXT event in Chicago, Westfell explained why building IT stacks for AI is complex, not to mention the growing challenges of managing Shadow AI and data sovereignty. He explained why IT leaders increasingly rely on teamwork with vendors and trusted advisors.

Organizations are no longer choosing between on-premises and cloud. They are running both, sorting workloads by legal mandate, data sensitivity and performance needs. That hybridization is driving a wave of decisions about the AI stack, data sovereignty and who organizations trust to guide them through it.

The pressure is already measurable. The 2026 Nutanix Enterprise Cloud Index found that 79% of IT leaders encounter unauthorized AI applications or agents deployed by employees outside IT, and nearly nine in 10 consider those unsanctioned deployments a serious business risk. The same report shows data sovereignty is now a must-have for 79% of respondents, even as 62% still run containerized applications in the public cloud, a gap the report calls "sovereignty debt."

What Is Shadow AI and Why Is It a Problem?

Shadow AI is the unsanctioned use of AI tools by employees, partners or other users outside IT oversight, creating risks to data security, intellectual property and network integrity. It is the AI-era descendant of Shadow IT, and it is spreading fast.

Westfall said the two phenomena are inseparable. "Shadow AI is really joined at the hip with Shadow IT," he said. Employees bring their own AI tools into the workplace, and that creates uncertainty about what is happening across the network and the underlying infrastructure.

RELATED Deploying Enterprise AI is a Team Sport
Building IT stacks for AI is complex, not to mention the growing challenges of managing Shadow AI and data sovereignty. HyperFRAME Research analyst Ron Westfall explains why IT leaders increasingly rely on teamwork with vendors and trusted advisors.
  • Article:News
  • Nutanix-Newsroom:Article
  • Products:Nutanix Enterprise AI (NAI)

July 21, 2026

The danger is exposure. When employees feed proprietary data into public LLMs without oversight, intellectual property can leak. Westfall said that decision-makers at the CXO level need to anticipate Shadow AI scenarios before they occur.

"We need to anticipate Shadow AI scenarios so we can minimize the possibility of our vital information, our IP, being exposed to a public LLM implementation," Westfall said.

The fix, he said, is orchestrated data sovereignty. Organizations need tools that let employees use AI while keeping sensitive data protected. Whoever can deliver that capability will have a competitive edge. "This is something that I think will be a game changer," Westfall said, "who can deliver in that specific regard."

Will Geopolitical Fragmentation Force Enterprises to Favor Certain LLMs?

The short answer is not yet, but the currents are moving. Bifurcation is already visible. Mainland China favors LLMs developed domestically, a pattern that mirrors earlier fragmentation in social media and cloud platforms.

Westfall said he does not expect hard legal mandates requiring specific LLMs. Instead, organizations will gravitate toward models they trust and customize. 

"Organizations are becoming more comfortable with existing LLMs and customizing them versus attempting to natively build their own small language model, which was a hot topic a year ago," he said.

That shift carries an implication. Building a proprietary small language model was once the frontier. Now it is a shrinking slice of the market. Optionality and flexibility will define LLM strategy for the foreseeable future, Westfall said, as organizations prioritize customization over building from scratch.

How Does Sovereign AI Shape Enterprise Data Strategy?

Sovereign AI is tightly coupled with sovereign data, and both put governance and guardrails at the center of enterprise strategy. The demands are not theoretical. Governments are writing them into law.

Westfall pointed to the EU as the region taking the first concrete steps. Regulations such as the Digital Operational Resilience Act (DORA) require organizations and service providers to ensure data is not violated through noncompliance with governmental mandates. 

RELATED The EU AI Act Delay Is No Stoplight for CIOs
With fines reaching €35 million and an AI-use compliance framework that applies globally, experts say digital leaders must treat the December 2027 enforcement extension with alacrity.
  • Article:News
  • Key Play:Enterprise AI
  • Nutanix-Newsroom:Article

July 15, 2026

"In the EU, we're actually seeing the best first steps being taken that could end up being best practices for other parts of the world to emulate," Westfall said.

The work is still early. Organizations need to develop the knowledge and guardrails to ensure sovereign AI adheres to fundamental principles. But the precedent is forming, and the EU is helping set it.

Why Is the Trusted Advisor Role Intensifying?

As the AI stack grows more complex, the need for a trusted advisor is sharpening across enterprises and service providers alike. The role has existed for years, but AI is resetting expectations.

Generative AI and agentic AI capabilities are new territory, Westfall said. "AI is a new kid on the block in many ways when it comes to gen AI and agentic AI capabilities," he said. "It's a new level set. It's a brave new world in many ways."

That novelty puts more weight on finding a trusted advisor who can streamline the tools needed to make AI work. The AI stack carries intricacies that previous network implementations did not, Westfall said, and organizations want to minimize complexity before it becomes overwhelming.

Westafell advises IT teams to use common interfaces, common control planes and agile software integration rather than hardware lock-in. Those priorities are reshaping how organizations choose partners, Westfall said, and they put more emphasis on "establishing who your trusted advisor can be to really be successful at your AI implementation."

Video transcript:

Ron Westfall: Do we use a GPU centric approach or a CPU centric approach or a combination? And it's also about how do we optimize the workloads in terms of do we keep the workloads on the premises or do we keep them on the cloud? And I think what we're seeing is a great deal of hybridization. So many organizations are, okay, we'll use on-premise for a specific set of workloads, especially ones that have legal mandates attached to them and other legal requirements as well as prioritization by the organization that we want to keep this data onsite. But also we're seeing increasingly use of cloud for specific capabilities and use cases, certainly when it comes to public interfacing, I would say logs and things of that nature. And so it's evolving. And I think it's also the AI stack is just driving more awareness of how the network has to work with the other layers of the stack. That includes the data layer, the cloud layer, the orchestration layer. And so this is something that is challenging, but I think it's also driving some really important decisions as to how an organization's business can thrive by using AI as a tool, as an underlying capability. And so I think this is something that is driving almost all of our conversations, certainly here at Nutanix Next. And I think we're getting some very important messages and takeaways specifically related to how AI can be best used to improve business outcomes.

Ken Kaplan: We've heard of shadow IT. Now we're hearing Shadow AI.

Ron Westfall: Yes.

RELATED Data Storage Steers AI Strategies
In this video interview, HyperFrame Analyst Don Gentile explains how data storage is shifting from passive to active participant in AI, raising a defining question: bring compute to the data, or data to the compute? He says months of supply chain pressure is pushing enterprises to squeeze more from existing infrastructure and lean on private cloud and neo-clouds.
  • Nutanix-Newsroom:Article, Video
  • Products:Nutanix Cloud Infrastructure (NCI), Nutanix Kubernetes Platform (NKP), Nutanix Unified Storage (NUS)

August 13, 2026

Ken Kaplan: I mean, can you just tell me what Shadow AI is and why it's a problem or how it's being addressed?

Ron Westfall: I think that's a very important question and it's certainly been a takeaway here at this event. And I think Shadow AI is really joined at the hip of Shadow IT. They're birds at the same feather. And what is distinct is that Shadow AI is employees or other users or partners bringing their own AI tools and that can create some uncertainties as to what's going on with the overall network and also the underlying infrastructure. And so what I think is definitely going to be important is having that data sovereignty in place and having the decision makers, certainly at the CXO level saying like, "Hey, we need to anticipate shadow AI scenarios so we can minimize the possibility of our vital information, our IP, be exposed to a public LLM implementation." And so I think those are steps that are definitely going to be, I would say, adapted by working with a trusted advisor. You just have to know how to approach this initially and then have solutions in place such as having that orchestrated data sovereignty capabilities that give you the confidence like, okay, we can use these AI tools, but our vital IP will be protected in the process. So this is something that I think will be a game changer is who can deliver in that specific regard.

Ken Kaplan: Do you foresee a time when some parts of the world will only allow certain models to be used? And what kind of challenge is that for the IT team?

Ron Westfall: Yeah, I think that's something that we're watching, that there's some concern about fragmentation. I think we've already seen bifurcation on a very fundamental level that is mainland China and its policies do favor of LLMs that are originated from China. And as a result, this is something that is applied really in many additional areas already. So we've already seen it, for example, with the social media platforms and we've already seen that with cloud platforms. And so that is already in play to a very important extent. The question is, will there be more, I would say, mandates for specific LLMs? I don't think that's going to be an actual legal type requirement, but I think you'll see more organizations favoring certain LLMs. And I think what we're actually are seeing is that organizations are becoming more comfortable with existing LLMs and customizing them versus attempting to natively build their own small language model, which was a hot topic say a year ago. But I think there will be some of that, but there'll just be an increasingly smaller percentage of how organizations are going to use LLMs and optionality and having flexibility will be an ongoing, I would say, aspect for the foreseeable future in that regard.

RELATED How AI Dramatically Disrupts IT Operations Unlike Anything Before
Enterprises are only in the first inning of a fundamental infrastructure overhaul driven by AI, explains HyperFRAME Research CEO Steven Dickens in this video interview.
  • Key Play:Enterprise AI
  • Nutanix-Newsroom:Article, Video

July 16, 2026

Ken Kaplan: What happens with sovereign AI? So how is a company that needs to have a strategy for being sovereign with its data?

Ron Westfall: Yes. Yeah. I think it also is tightly coupled with the other sovereign issues, including sovereign data. And I think it does shine a spotlight on the importance of governance and also having guardrails in place. And I think what we're seeing is on a worldwide basis that there is more prioritization and okay, we have to have data that will fulfill, for example, governmental mandates. And it's interesting that in the EU, we're actually seeing the best first steps being taken that could actually end up being best practices for other parts of the world to emulate. We had this conversation yesterday on this very topic. And so I think what we're going to see are more requirements such as DORA and the EU region where the organizations and the service providers have to make sure that the data is not going to be violated because they're not adhering to, for example, governmental mandates.But also I think it's just developing the knowledge and the guardrails to make sure that sovereign AI will adhere to those fundamental principles. And I think this is something that we're in the early stages of, and it's interesting that the EU region is actually, I think, helping to set the precedent on how this could be best handled.

Ken Kaplan: This need to work with vendors or really have a partnership with them, you see that intensifying?

Ron Westfall: Yeah, I think it's across the board. It's certainly on the enterprise side and also say on the service provider side, public service agencies and so forth. And I think what's a bit distinct is that the trust advisor role has been there, but I think when industries mature, it's more of a lead integrator responsibility as organizations become more knowledgeable about what they need to do to, for example, implement a hybrid cloud implementation. And so AI is a new kid on the block in many ways when it comes to gen AI and agentic AI capabilities. And so as a result, it's really a new level set. It's a brave new world in many ways. So that really does, I would say, put more prioritization on having a trusted advisor that can work with the organization to really help them through, certainly, the beginning stages. And I think what is underpinning that, what's critical, is that I touched on that because of the AI stack and that it's distinct from previous network implementations, is that it does have some added, I would say, intricacies and you want to minimize it so it doesn't become overwhelmingly complex.

And so that's where you really do need a trusted advisor that can help streamline and simplify many of the tools that are needed to make this work. And so I think that's important to have, for example, common interfaces, having common control planes, having the ability to do software integration on an agile basis and not be tied down so much on hardware selection processes as a result. And so I think these are some different things that are driving the decision making out there and thus really does put more emphasis on establishing who your trusted advisor can be to really be successful at your AI implementation.

Related:

Jason Lopez is executive producer of Tech Barometer, the podcast outlet for The Forecast. He’s the founder of Connected Social Media. Previously, he was executive producer at PodTech and a reporter at NPR.

Ken Kaplan contributed to this story. He is Editor in Chief for The Forecast by Nutanix. Find him on X @kenekaplan and LinkedIn.

© 2026 Nutanix, Inc. All rights reserved. For additional information and important legal disclaimers, please go here.

Key takeaways:

  • Enterprises are hybridizing AI workloads across on-premises and cloud to balance legal mandates with public-facing capabilities, said Ron Westfall, vice president and practice leader, Infrastructure and Networking at HyperFRAME Research.
  • Shadow AI exposes enterprise IP to public LLMs, making orchestrated data sovereignty a competitive differentiator, Westfall said.
  • The EU is setting early precedents for sovereign AI governance that could become global best practices, with regulations such as DORA leading the way.

Related Articles