
Across the UAE and Saudi Arabia, AI is moving from pilot projects into daily clinical practice. Diagnostic imaging, radiology triage, patient-flow prediction, and clinical decision support are no longer future ambitions. They’re being rolled out now, backed by national strategies that place healthcare at the center of both countries’ AI agendas.
The infrastructure underneath is coming under pressure that boards and regulators are only beginning to address. Ismail Ibrahim, General Manager, CEMEA at SUSE, calls it the shadow AI trap.
What is shadow AI?
When clinicians, researchers, or IT teams lack the necessary compute or tools through official channels, they find workarounds. For instance, a radiologist under pressure to speed up reporting may use a public AI tool to interpret a scan, or a research team may input patient data into a third-party model to accelerate a study.
Each decision is understandable individually. Collectively, they create risks beyond typical enterprise IT concerns, as the data involved is patient health information, not marketing copy or sales projections.
The risks of shadow AI in healthcare
The primary risk is governance. When clinical or research staff use AI tools outside IT’s control, the hospital loses track of where data goes, who accesses it, and how long it is retained.
This is a serious issue in any setting, but in healthcare, it directly impacts clinical governance and patient trust, not just compliance.
Regulatory requirements make this more urgent. Saudi Arabia’s Personal Data Protection Law, fully enforceable since September 2024, treats cross-border remote access to data as a transfer, with significant implications for health systems using overseas AI platforms.
The UAE’s federal data protection framework and Health Data Law (Federal Law No. 2 of 2019) impose strict mandates on patient data residency and access, creating a challenging environment for healthcare providers.
SUSE’s global study, Handling Digital Resilience, revealed that while 98% of enterprise IT leaders prioritize digital sovereignty, only 52% are actively working towards it. This gap between intent and action is where shadow AI flourishes. In healthcare, this gap exists between strategic plans and patient care.
Another pressing issue is the practical challenge faced by health system IT teams: GPU shortages and procurement delays. A SUSE survey of 110 IT practitioners found that 71% are frustrated by the impact of these shortages on daily work, with nearly a third experiencing delays of four months or more for routine projects.
For hospital IT teams, such delays can postpone critical system upgrades, leading to pressure to bypass procurement processes. This environment supports the growth of shadow AI usage.
These delays not only hinder IT projects but also affect time-to-diagnosis and clinical efficiency, prompting staff to seek faster alternatives outside sanctioned IT channels.
Read Also: Brain White Matter Model Maps Growth From Childhood to Old
The solution is not to accept this trade-off but to eliminate the bottleneck. Often, the capacity already exists within organizations.
The solution: open, portable infrastructure
More hardware isn’t always the answer. The same SUSE research shows that 79% of organizations operate below 75% of their infrastructure capacity. Many health systems have untapped resources in their data centers, which could support more AI workloads internally, reducing the need for unsanctioned tools.
This is key for budget-constrained healthcare organizations. Optimizing existing resources can be more effective and cost-efficient than investing in new GPUs, keeping patient data within governed infrastructure.
The research highlights that 80% of IT leaders prefer portable, efficient software over new hardware. For healthcare, this raises a practical question: is existing infrastructure being fully utilized before considering new purchases?
This approach doesn’t hinder AI adoption in healthcare. Diagnostic and clinical AI tools are benefiting patients across the region, and this progress should continue.
The goal is to provide clinicians and researchers with a sanctioned, governed pathway to work efficiently, eliminating the need to bypass IT for quick solutions.
Open, standards-based infrastructure is key. An AI platform built on open-source and portable architecture allows hospitals to run workloads on-premises, in private or sovereign clouds, or in hybrid environments, with flexibility to adapt later.
This portability ensures patient data remains within regulatory boundaries while offering clinical and research teams the speed they need, reducing the temptation to use unsanctioned tools.
Cost transparency and avoiding vendor lock-in are also essential. Integrating cost visibility into the platform prevents unexpected expenses, and treating vendor independence as a governance principle ensures long-term flexibility.
As regional health information exchanges like Malaffi in Abu Dhabi, Nabidh in Dubai, and Seha Virtual Hospital in Saudi Arabia expand, the ability to choose and change workload locations becomes critical for risk management and continuity of care.
Shadow AI emerges when clinical needs outpace infrastructure capabilities. By implementing an open, sovereign, and cost-predictable foundation, hospital IT and security leaders can focus on supporting AI-enabled care rather than managing unsanctioned tools.
Hospitals can better serve clinicians and patients by closing the gap between ambition and infrastructure.
Leave a Reply