Every IT team now faces many forks in the road: run AI on GPUs or CPUs, on premises or in the cloud. The answer is splitting into a hybrid patchwork that exposes new risks that require simplication and reliance on trusted advisors, according to HyperFRAME Research analyst Ron Westfall.
In a video interview with The Forecast recorded at the April 2026 .NEXT event in Chicago, Westfell explained why building IT stacks for AI is complex, not to mention the growing challenges of managing Shadow AI and data sovereignty. He explained why IT leaders increasingly rely on teamwork with vendors and trusted advisors.
Organizations are no longer choosing between on-premises and cloud. They are running both, sorting workloads by legal mandate, data sensitivity and performance needs. That hybridization is driving a wave of decisions about the AI stack, data sovereignty and who organizations trust to guide them through it.
The pressure is already measurable. The 2026 Nutanix Enterprise Cloud Index found that 79% of IT leaders encounter unauthorized AI applications or agents deployed by employees outside IT, and nearly nine in 10 consider those unsanctioned deployments a serious business risk. The same report shows data sovereignty is now a must-have for 79% of respondents, even as 62% still run containerized applications in the public cloud, a gap the report calls "sovereignty debt."
Shadow AI is the unsanctioned use of AI tools by employees, partners or other users outside IT oversight, creating risks to data security, intellectual property and network integrity. It is the AI-era descendant of Shadow IT, and it is spreading fast.
Westfall said the two phenomena are inseparable. "Shadow AI is really joined at the hip with Shadow IT," he said. Employees bring their own AI tools into the workplace, and that creates uncertainty about what is happening across the network and the underlying infrastructure.
The danger is exposure. When employees feed proprietary data into public LLMs without oversight, intellectual property can leak. Westfall said that decision-makers at the CXO level need to anticipate Shadow AI scenarios before they occur.
"We need to anticipate Shadow AI scenarios so we can minimize the possibility of our vital information, our IP, being exposed to a public LLM implementation," Westfall said.
The fix, he said, is orchestrated data sovereignty. Organizations need tools that let employees use AI while keeping sensitive data protected. Whoever can deliver that capability will have a competitive edge. "This is something that I think will be a game changer," Westfall said, "who can deliver in that specific regard."
The short answer is not yet, but the currents are moving. Bifurcation is already visible. Mainland China favors LLMs developed domestically, a pattern that mirrors earlier fragmentation in social media and cloud platforms.
Westfall said he does not expect hard legal mandates requiring specific LLMs. Instead, organizations will gravitate toward models they trust and customize.
"Organizations are becoming more comfortable with existing LLMs and customizing them versus attempting to natively build their own small language model, which was a hot topic a year ago," he said.
That shift carries an implication. Building a proprietary small language model was once the frontier. Now it is a shrinking slice of the market. Optionality and flexibility will define LLM strategy for the foreseeable future, Westfall said, as organizations prioritize customization over building from scratch.
Sovereign AI is tightly coupled with sovereign data, and both put governance and guardrails at the center of enterprise strategy. The demands are not theoretical. Governments are writing them into law.
Westfall pointed to the EU as the region taking the first concrete steps. Regulations such as the Digital Operational Resilience Act (DORA) require organizations and service providers to ensure data is not violated through noncompliance with governmental mandates.
"In the EU, we're actually seeing the best first steps being taken that could end up being best practices for other parts of the world to emulate," Westfall said.
The work is still early. Organizations need to develop the knowledge and guardrails to ensure sovereign AI adheres to fundamental principles. But the precedent is forming, and the EU is helping set it.
As the AI stack grows more complex, the need for a trusted advisor is sharpening across enterprises and service providers alike. The role has existed for years, but AI is resetting expectations.
Generative AI and agentic AI capabilities are new territory, Westfall said. "AI is a new kid on the block in many ways when it comes to gen AI and agentic AI capabilities," he said. "It's a new level set. It's a brave new world in many ways."
That novelty puts more weight on finding a trusted advisor who can streamline the tools needed to make AI work. The AI stack carries intricacies that previous network implementations did not, Westfall said, and organizations want to minimize complexity before it becomes overwhelming.
Westafell advises IT teams to use common interfaces, common control planes and agile software integration rather than hardware lock-in. Those priorities are reshaping how organizations choose partners, Westfall said, and they put more emphasis on "establishing who your trusted advisor can be to really be successful at your AI implementation."
Video transcript:
Ron Westfall: Do we use a GPU centric approach or a CPU centric approach or a combination? And it's also about how do we optimize the workloads in terms of do we keep the workloads on the premises or do we keep them on the cloud? And I think what we're seeing is a great deal of hybridization. So many organizations are, okay, we'll use on-premise for a specific set of workloads, especially ones that have legal mandates attached to them and other legal requirements as well as prioritization by the organization that we want to keep this data onsite. But also we're seeing increasingly use of cloud for specific capabilities and use cases, certainly when it comes to public interfacing, I would say logs and things of that nature. And so it's evolving. And I think it's also the AI stack is just driving more awareness of how the network has to work with the other layers of the stack. That includes the data layer, the cloud layer, the orchestration layer. And so this is something that is challenging, but I think it's also driving some really important decisions as to how an organization's business can thrive by using AI as a tool, as an underlying capability. And so I think this is something that is driving almost all of our conversations, certainly here at Nutanix Next. And I think we're getting some very important messages and takeaways specifically related to how AI can be best used to improve business outcomes.
Ken Kaplan: We've heard of shadow IT. Now we're hearing Shadow AI.
Ron Westfall: Yes.
Ken Kaplan: I mean, can you just tell me what Shadow AI is and why it's a problem or how it's being addressed?
Ron Westfall: I think that's a very important question and it's certainly been a takeaway here at this event. And I think Shadow AI is really joined at the hip of Shadow IT. They're birds at the same feather. And what is distinct is that Shadow AI is employees or other users or partners bringing their own AI tools and that can create some uncertainties as to what's going on with the overall network and also the underlying infrastructure. And so what I think is definitely going to be important is having that data sovereignty in place and having the decision makers, certainly at the CXO level saying like, "Hey, we need to anticipate shadow AI scenarios so we can minimize the possibility of our vital information, our IP, be exposed to a public LLM implementation." And so I think those are steps that are definitely going to be, I would say, adapted by working with a trusted advisor. You just have to know how to approach this initially and then have solutions in place such as having that orchestrated data sovereignty capabilities that give you the confidence like, okay, we can use these AI tools, but our vital IP will be protected in the process. So this is something that I think will be a game changer is who can deliver in that specific regard.
Ken Kaplan: Do you foresee a time when some parts of the world will only allow certain models to be used? And what kind of challenge is that for the IT team?
Ron Westfall: Yeah, I think that's something that we're watching, that there's some concern about fragmentation. I think we've already seen bifurcation on a very fundamental level that is mainland China and its policies do favor of LLMs that are originated from China. And as a result, this is something that is applied really in many additional areas already. So we've already seen it, for example, with the social media platforms and we've already seen that with cloud platforms. And so that is already in play to a very important extent. The question is, will there be more, I would say, mandates for specific LLMs? I don't think that's going to be an actual legal type requirement, but I think you'll see more organizations favoring certain LLMs. And I think what we're actually are seeing is that organizations are becoming more comfortable with existing LLMs and customizing them versus attempting to natively build their own small language model, which was a hot topic say a year ago. But I think there will be some of that, but there'll just be an increasingly smaller percentage of how organizations are going to use LLMs and optionality and having flexibility will be an ongoing, I would say, aspect for the foreseeable future in that regard.
Ken Kaplan: What happens with sovereign AI? So how is a company that needs to have a strategy for being sovereign with its data?
Ron Westfall: Yes. Yeah. I think it also is tightly coupled with the other sovereign issues, including sovereign data. And I think it does shine a spotlight on the importance of governance and also having guardrails in place. And I think what we're seeing is on a worldwide basis that there is more prioritization and okay, we have to have data that will fulfill, for example, governmental mandates. And it's interesting that in the EU, we're actually seeing the best first steps being taken that could actually end up being best practices for other parts of the world to emulate. We had this conversation yesterday on this very topic. And so I think what we're going to see are more requirements such as DORA and the EU region where the organizations and the service providers have to make sure that the data is not going to be violated because they're not adhering to, for example, governmental mandates.But also I think it's just developing the knowledge and the guardrails to make sure that sovereign AI will adhere to those fundamental principles. And I think this is something that we're in the early stages of, and it's interesting that the EU region is actually, I think, helping to set the precedent on how this could be best handled.
Ken Kaplan: This need to work with vendors or really have a partnership with them, you see that intensifying?
Ron Westfall: Yeah, I think it's across the board. It's certainly on the enterprise side and also say on the service provider side, public service agencies and so forth. And I think what's a bit distinct is that the trust advisor role has been there, but I think when industries mature, it's more of a lead integrator responsibility as organizations become more knowledgeable about what they need to do to, for example, implement a hybrid cloud implementation. And so AI is a new kid on the block in many ways when it comes to gen AI and agentic AI capabilities. And so as a result, it's really a new level set. It's a brave new world in many ways. So that really does, I would say, put more prioritization on having a trusted advisor that can work with the organization to really help them through, certainly, the beginning stages. And I think what is underpinning that, what's critical, is that I touched on that because of the AI stack and that it's distinct from previous network implementations, is that it does have some added, I would say, intricacies and you want to minimize it so it doesn't become overwhelmingly complex.
And so that's where you really do need a trusted advisor that can help streamline and simplify many of the tools that are needed to make this work. And so I think that's important to have, for example, common interfaces, having common control planes, having the ability to do software integration on an agile basis and not be tied down so much on hardware selection processes as a result. And so I think these are some different things that are driving the decision making out there and thus really does put more emphasis on establishing who your trusted advisor can be to really be successful at your AI implementation.
Related:
Jason Lopez is executive producer of Tech Barometer, the podcast outlet for The Forecast. He’s the founder of Connected Social Media. Previously, he was executive producer at PodTech and a reporter at NPR.
Ken Kaplan contributed to this story. He is Editor in Chief for The Forecast by Nutanix. Find him on X @kenekaplan and LinkedIn.
© 2026 Nutanix, Inc. All rights reserved. For additional information and important legal disclaimers, please go here.