TALKING POINT
ESCAPING THE SHADOW AI TRAP
Ismail Ibrahim, General Manager, CEMEA, SUSE, tells us how enterprises can scale AI without cloud bill implosions.
Across the UAE and Saudi Arabia, the question boardrooms ask about AI has changed. It is no longer“ should we adopt it?” but“ how do we scale it without losing control of our data, our costs, or our compliance position?” That question is urgent for good reason: IDC reports that Saudi Arabia and the UAE recorded the strongest AI infrastructure growth anywhere in the world in the final quarter of 2025, driven by government-backed sovereign AI programmes. The ambition is real. So is the exposure it creates.
The reason is a problem I call the shadow AI trap. Marketing teams pipe customer data into public generative AI tools; developers wire proprietary code into third-party models; finance teams stand up AI pilots with little regard for where that data resides or who else can see it. Each decision is rational in isolation. Collectively, they create two compounding risks that CIOs and CISOs across the Gulf are now being asked to explain to their boards, and increasingly, to their regulators.
Data residency is no longer a compliance checkbox in this region; it is a strategic asset. Saudi Arabia’ s Personal Data Protection Law has been fully enforceable since September 2024, and treats cross-border remote access to data as a
Ismail Ibrahim, General Manager, CEMEA, SUSE transfer in its own right. The UAE’ s own federal data protection framework sets comparable expectations. Shadow AI usage quietly undermines an organisation’ s ability to meet either standard: when employees route sensitive data through unsanctioned AI tools outside the enterprise’ s control, organizations lose the ability to demonstrate where that data went and who accessed it. SUSE’ s own global research bears this out: in the study Navigating Digital Resilience among 309 enterprise IT leaders in five countries, 98 % called digital sovereignty a top priority, yet only 52 % were actually taking steps to achieve it. That gap between ambition and action is precisely where shadow AI takes hold.
The second risk is financial, and it is arriving faster than most finance teams expected. AI workloads are compute-intensive by nature, and when provisioned piecemeal, department by department, on open-ended consumption pricing, the cost curve stops looking like a line item and starts looking like a liability. Industry research puts wasted cloud spend at its highest level in five years, driven largely by AI workloads that are harder to forecast and rightsize. Once workloads and data sit inside a single provider’ s ecosystem, the enterprise has effectively signed up for whatever pricing and architectural decisions that provider makes next. That is vendor lock-in by default, not by strategy.
Escaping this trap does not mean slowing AI adoption down. Gulf enterprises do not have that luxury, and nor should they want it. It means CIOs and CISOs getting ahead of shadow AI by giving the business a sanctioned, well-governed path to move fast, rather than leaving people to route around IT.
That starts with open, standards-based infrastructure. An AI platform built on open source foundations and portable architecture allows an enterprise to run AI workloads onpremises, in a private cloud, in a sovereign national cloud, or across a hybrid mix, and to move them again later without re-architecting from scratch.
That portability turns sovereignty from a constraint into a design choice, keeping regulated data within national borders while still giving developers the self-service speed they currently seek from unsanctioned tools. In practice, it means giving developers a stable, standardised digital floor, a factory floor that everything else securely sits on, so they never feel forced to bypass IT just to move at the speed the business demands. •
18
INTELLIGENT CIO MIDDLE EAST www. intelligentcio. com