
Ismail Ibrahim, General Manager, CEMEA at SUSE, examines how “shadow AI” is taking hold across UAE and Saudi hospitals, as clinicians and researchers bypass sanctioned IT channels under pressure of GPU shortages and procurement delays. He analyses the governance and data-sovereignty risks this creates for patient information, and sets out how open, portable infrastructure could give health systems a safer, faster route to clinical AI adoption.
Across UAE and Saudi hospitals, AI is moving from pilot projects into daily clinical practice.
Diagnostic imaging, radiology triage, patient-flow prediction and clinical decision support are no longer future ambitions; they are being rolled out now, backed by national strategies that place healthcare at the centre of both countries’ AI agendas. The ambition is well placed. But the infrastructure underneath is coming under a pressure that boards and regulators are only beginning to reckon with.
I call it the shadow AI trap, and in healthcare it carries a sharper edge than in almost any other sector. When clinicians, researchers or IT teams can’t get the compute or tools they need through sanctioned channels, they find workarounds. For example, a radiologist under pressure to speed up reporting may turn to a public AI tool to help interpret a scan, or a research team may feed patient data into a third-party model to accelerate a study. Each decision is understandable on its own terms. Collectively, they create risks that go well beyond a typical enterprise IT concern, because the data involved is patient health information, not marketing copy or sales projections.
Risk one: patient data, without an audit trail
The first risk is one of governance. When clinical or research staff route scans, records or diagnostic data through AI tools that sit outside IT’s control, the hospital loses the ability to show where that data went, who else can see it, and how long it is retained. That is a serious problem anywhere, but in a hospital setting it touches the core of clinical governance and patient trust, not just a compliance checklist.
The regulatory backdrop makes this even more pressing. Saudi Arabia’s Personal Data Protection Law has been fully enforceable since September 2024 and treats cross-border remote access to data as a transfer in its own right, a standard with obvious implications for any health system moving patient data through an overseas AI platform.
The UAE’s federal data protection frameworksets comparable expectations. Combined with the UAE’s Health Data Law (Federal Law No. 2 of 2019), healthcare providers across the region face strict mandates regarding where patient data resides and who can access it.
Our research suggests many organizations know this gap exists, but haven’t closed it. In SUSE’s global study, Navigating Digital Resilience, 98% of enterprise IT leaders called digital sovereignty a top priority, yet only 52% were actually taking steps to achieve it. That is a wide gap between stated intent and operational reality, and it is precisely the space in which shadow AI takes hold. In a hospital, that gap sits between a strategy document and a patient’s scan.
Risk two: compute shortages are already slowing everyday IT
The second pressure is more practical, and it’s hitting health system IT teams broadly, not just their AI projects. GPU shortages and procurement delays have become a genuine bottleneck. In a separate SUSE survey of 110 IT practitioners, 71% said they were frustrated by the knock-on impact of these shortages on day-to-day IT work, and nearly a third reported delays of four months or more to routine projects as a result.
For a hospital IT team, a lengthy delay can mean deferred upgrades to systems that clinical departments are relying on, or pressure to find a faster route around procurement, which is exactly the condition under which shadow AI usage grows. These delays don’t just stall IT projects, they directly impact time-to-diagnosis and clinical throughput, creating immense pressure to find faster routes around sanctioned IT. When the sanctioned path is slow, people find another one. The fix is not to accept that trade-off, but to remove the bottleneck that creates it. The capacity is often already there
Here is the part that should reframe the conversation for many hospital CIOs: the answer isn’t always more hardware. The same SUSE research found that 79% of organizations are running below 75% of their existing infrastructure capacity. In other words, many health systems already have meaningful headroom sitting inside their own data centers, capacity that could support more AI workloads in-house rather than pushing clinicians and researchers toward unsanctioned tools.
That matters enormously for healthcare budgets under pressure. Rather than an immediate capital outlay on new GPUs, hospitals may get further, faster, by improving how they use what they already have. It’s a more disciplined starting point, and one that keeps patient data inside infrastructure the hospital actually governs.
Consistent with this, 80% of IT leaders in our research agreed that portable, efficient software is a better investment than the latest hardware. For a health system, that translates into a very practical question for any AI initiative: before buying more compute, has the existing estate been used properly?
Building the sovereign, cost-predictable path
None of this means slowing AI adoption in healthcare. Diagnostic and clinical AI tools are delivering real benefit to patients across the region, and that momentum should continue. What it means is giving clinicians and researchers a sanctioned, well-governed way to move quickly, so they’re never tempted to route around IT just to get their work done.
That starts with open, standards-based infrastructure. An AI platform built on open-source foundations and a portable architecture lets a hospital run workloads on-premises, in a private cloud, in a sovereign national cloud, or across a hybrid mix, and to move them again later without re-architecting from the ground up. For a health system, that portability is what keeps regulated patient data within the right borders and the right governance boundary, while still giving clinical and research teams the self-service speed they’re currently seeking elsewhere.
It also means building cost visibility into the platform itself, rather than discovering the true cost of an AI initiative after the invoice lands, and treating freedom from vendor lock-in as a governance principle rather than a procurement nicety. That principle matters even more as regional health information exchanges, such as Malaffi in Abu Dhabi, Nabidh in Dubai and Seha Virtual Hospital in Saudi Arabia, connect more providers and more patient data across shared platforms. For a hospital, the ability to choose, and later change, where a workload runs is itself a form of risk management, protecting continuity of care as much as budget.
Ahead of the agentic era in clinical care
As agentic AI systems move from pilot to production in clinical settings, autonomous tools that can act on patient data directly, the stakes attached to this foundation will only grow. These systems need an infrastructure layer that enforces where data is processed and what it costs by design, not by policy memo after the fact.
Shadow AI thrives in the gap between clinical ambition and the infrastructure meant to support it. Close that gap with an open, sovereign and cost-predictable foundation, and hospital IT and security leaders can spend less time chasing unsanctioned tools, and more time supporting the AI-enabled care their clinicians and patients are asking for.




