The Hidden Risk of Single-Model Dependency Across the Enterprise
Relying on a single foundation model for forecasts, customer support, and code creates a single point of operational failure.
Critical suppliers are a board topic when they are a factory, a cloud region, or a payments network. They are a footnote when they are a model. That classification is out of date. A provider that sits inside the forecast commentary, the customer channel, the software build, and the staff’s daily drafting is no longer a tool. It is a dependency. If its prices change, its terms change, its safety filter changes, or its service degrades, the operating rhythm degrades with it. Calling this a partnership does not diversify it.
McKinsey’s 2025 survey shows why the dependency accumulates quietly: use is already normal — 88 percent of organisations in at least one function — while enterprise scaling is not. Teams adopt whatever is easiest, often the same famous model, because nobody has been asked to design for exit. Microsoft’s Work Trend Index adds personal concentration: 78 percent of AI users bring their own tools, which in practice means a very small number of consumer brands. The enterprise standardises by accident on the same names the staff already opened.
What concentration actually threatens
Terms. A vendor that reserves the right to train on inputs, retain prompts, or change subprocessors can turn a renewal into a data-protection event. The ICO’s AI guidance is a reminder that purpose and security duties sit with the controller, not with the brand of the model. If you cannot leave, you cannot renegotiate those duties. You can only accept them.
Behaviour. Models change without a release note your operators would recognise as a change. A filter tightens and a legitimate workflow starts failing. A filter loosens and a customer-facing assistant becomes more willing to speculate. The Bard demo showed how a single public error moves a market. An internal error moves a forecast or a promise. If you have no second model that can run the same job, you cannot even tell whether the failure is yours or theirs.
Price. Seat-plus-usage contracts feel smooth until usage is the business. A concentrated vendor can price the increment because switching means revalidating every job. Procurement scored the demo. The switching cost was never scored. ISO/IEC 42001 will not choose your second supplier. It will at least force you to name the suppliers you have and the impact if they fail.
Claims. If your market story is “we run on X,” you have coupled your disclosure to X’s reputation. The SEC’s AI-washing cases were about false claims of capability. A true claim of total dependence is a different risk: when X has an outage or a scandal, your operational status and your narrative move together.
| What moves | What you feel first | Why you cannot leave in the notice period | What to have already stored |
|---|---|---|---|
| Terms: training on inputs, retention, subprocessors | A data-protection question at renewal | Purpose and security sit with you, not with the brand | The agreement, the region, and a path that does not accept the new default |
| Behaviour: a filter tightens or loosens | A workflow fails, or a customer-facing answer speculates | You cannot tell a vendor change from your own bug | A second model that can run the same job against the same sources |
| Price: usage becomes the business | The increment is priced because switching means revalidating every job | The demo was scored. The exit was not | Time-to-cutover from a drill, not a hope |
| Claims: “we run on X” | An outage or a scandal moves your operations and your story together | The disclosure is coupled to someone else’s reputation | A description of the job that does not depend on the logo |
A resilience test that fits on one page
List the jobs that would miss a customer commitment, a close, or a release if the primary model were unavailable for five days. For each, name the fallback: a second model, a human procedure, or a degraded service you are willing to announce. If the fallback is “wait,” you have accepted a single point of failure. Write that down where the board can see it. Hidden acceptance is how concentration becomes a surprise.
For the jobs that write or promise, the fallback has to include the control, not only the prose. A second model that is more willing to invent a discount is not resilience. It is a second Air Canada. The policy, the approval, and the log should be yours. The model should be replaceable underneath them. Companies that embed the rule in a vendor’s proprietary instruction will discover, at renewal, that the rule is not portable.
Test the exit once a year the way you test a restore. Take one real job. Run it on the alternative. Compare the output against the same sources. Time the cutover. The first test will be humbling. That is the point. A test you have not run is a hope, and hopes are what IBM’s access-control findings suggest companies have been operating on: systems in production without the controls that would make them substitutable or even inspectable.
| Job that would miss a commitment, a close, or a release | Fallback if the primary model is dark for five days | Control that must travel with it | If the cell says “wait” |
|---|---|---|---|
| Name the job a customer would recognise | A second model, a human procedure, or a degraded service you will announce | The policy, the approval, and the log stay yours. The model is underneath | You have accepted a single point of failure. Put it in the board pack |
| A job that writes or promises | The alternative must be able to refuse a discount the policy does not allow | A second model that invents a remedy is a second spokesperson, not a fallback | Do not call it resilience |
| One job you will actually cut over this year | Time the cutover. Compare outputs against the same sources | Prompts and policy as files you hold, not settings in a console | A test you have not run is a hope |
The renewal you should be able to walk away from
Concentration is not a philosophical worry about markets. It is the renewal conversation in which you cannot leave. You discover it when a price change, a retention change, or an outage arrives with notice, and the list of exposed jobs is assembled by asking around. Sales says the assistant only drafts. The draft is the proposal. Support says they can fall back to macros. The macros were generated and never filed. Engineering says the coding tool is optional. The last release was reviewed by people who used it to explain code they did not write. Optional became structural while the contract still said convenience.
A company that can walk away has already done the dull work. The prompts and the policy text exist as files you own, not only as settings in a vendor console. The evaluation set — a few dozen real tasks with the answer you would accept — is saved, so “the other model is worse” is a comparison rather than a mood. Credentials are per job, so cutover is not a security project you start during the notice period. Access control is the control most often missing when AI systems show up in breach reports. It is also the control that makes an exit possible. You cannot move a job whose identity you cannot name.
Run the alternative twice a year on the five jobs you would miss in a week. Record time-to-cutover and the share of outputs a person rejected. Those are the concentration metrics. A second model that refuses more often is not automatically a failure. Some refusals are the policy, finally enforced. The promise, on either model, is still yours. Portability includes the refusal.
Do not confuse an enterprise agreement with a reduction in concentration if staff still do the sensitive work in personal accounts. Bring-your-own use is the norm among AI users. That is a second dependency, often on the same small set of brands, with worse logs. An exit plan that ignores it will discover, in the crisis, that the work was never on the contract you are trying to leave.
The board question is the one you already ask of payroll, identity, and payments: what is the worst week, and what do we do on the Monday? If the answer is the vendor’s status page, you do not have a supplier. You have a single point of operation. Fund the alternative before you need it. Needing it is a bad time to discover you cannot.
| What people will say in the notice period | What has actually become structural | What “able to walk away” requires |
|---|---|---|
| “It only drafts” | The draft is the proposal | The proposal template and the rule live in files you own |
| “We can fall back to macros” | The macros were generated and never filed | A filed procedure someone other than the vendor can run |
| “The coding tool is optional” | The last release was reviewed by people who used it to explain code they did not write | An evaluation set of real tasks, with the answer you would accept |
| “We have an enterprise agreement” | Sensitive work is still on personal accounts, often the same brands | The work has moved onto the contract, or the exit plan is fiction |
A drill with a date on it
Twice a year, cut the five jobs you would miss in a bad week over to an alternative, using prompts, policy text, and evaluation cases you store yourselves. Write down how long it took and what a person rejected. If you cannot start the drill because the prompts live only in the vendor’s console, that fact is the finding. Fix the finding before the renewal, not during a price dispute. An identity you can name and revoke is part of the drill. So is the personal-account path: if the sensitive work never moved onto the contract, leaving the contract will not move the work. Report the drill to the board in two numbers. Logo count is not one of them. If the drill did not happen, report that. Absence is the concentration.
| Report this | Not this |
|---|---|
| Time to cut the five jobs over | How many model logos are on the architecture slide |
| Share of outputs a person rejected on the alternative | A mood that “the other model is worse” |
| Whether prompts and policy were already files you hold | A finding discovered during the price dispute |
| Whether the sensitive work was on the contract at all | An enterprise agreement that staff do not use for the sensitive work |
| “The drill did not happen,” if it did not | Silence. Absence is the concentration |
A call to chief strategy and technology officers
Treat the model provider as critical infrastructure when the jobs are critical, and as a commodity when they are not. Most companies have it backwards: commodity treatment of a critical dependency, and strategic language for a chatbot that drafts internal notes.
Name the five jobs you would not want to run on a single provider. Build the fallback before the renewal conversation, not during it. The negotiation you want is the one you can walk away from. Concentration is what happens when you no longer can, and have decided not to notice.
References
- McKinsey, The State of AI: Global Survey 2025
- Microsoft and LinkedIn, 2024 Work Trend Index
- ICO, guidance on AI and data protection
- Reuters, Alphabet shares and the Bard demo
- ISO/IEC 42001
- U.S. SEC press release 2024-36
- CBC News, Air Canada chatbot liability
- IBM newsroom, 30 July 2025
- NIST AI Risk Management Framework
About Nimbus
Nimbus is a Collaborative AI Operating System built around four core pillars that bring human teams and autonomous AI together into a single, unified workspace.
Communication: Keep context tied to the job. Unify emails, meeting recordings, transcripts, and operational files directly within active projects—ending knowledge silos buried in private inboxes, scattered Slack threads, or unrecorded calls.
Collaboration: Work alongside AI in real time. Bring people and AI agents onto the exact same brief, visual canvas, or initiative. Query company-wide data, invite agents into live calls, and co-create in one shared space—eliminating the split between human group chats and isolated AI sidebars.
Automation: Put routine workflows on autopilot. Connect more than 2,000 enterprise tools and standardize repetitive operations. Background loops run on schedules or data triggers with full execution logs, ensuring operational knowledge is shared across the team rather than trapped in one person’s head.
Governance: Deploy AI with absolute control. Enforce strict role-based access controls across workspaces. AI agents can analyze, summarize, and draft—but no live system changes or external communications occur without explicit, verified human sign-off.
One provider, many jobs
What is model concentration?
One provider drafting the forecasts, the customer replies, and the code. The company describes it as a partnership. It is a single point of failure.
Why treat it like a supplier risk?
Because an outage, a price change, or a policy change now stops more than one function at once.
What is the practical control?
A routing policy and a record of which model did which job, so a second provider is a switch, not a rewrite.
See what governed AI looks like on your stack.
Connect your tools, run a workstream, and keep every decision on your ledger. Start on Free.