The model you did not build and the supply chain behind it.
34documents on this topic
23organizations represented
4issues named
11sourced citations
0sourced statistics
The state of it
One of 7 topics within Governance & oversight.
34 documents from 23 organizations address the model you did not build. The useful finding is that the research has largely stopped talking about lock-in as a model problem and started treating it as an architecture problem.
Databricks makes the sharpest version of the argument: the switching cost has moved off the model and into the harness around it. Once developers' tooling is bound to one model family, the harness itself becomes the lock-in, and the ability to move spend to a cheaper or better model disappears regardless of how open the weights are. Palantir arrives at the same place from the opposite direction, arguing for model agnosticism and what it calls model liquidity as an attribute you build into your systems now, before you need it.
The weaker area is diligence. Vendor security requirements in this research are mostly generic IT controls with AI language attached; almost nothing specifies what to verify about a model provider that differs from what you would ask any SaaS vendor.
The issues, by agreement
How many independent organizations name each issue as a problem. An issue is only as real as the number of separate publishers that identify it, so the count is the ranking. Bars are organizations, not documents. Where the count reads ours, no publisher here states the issue and the analysis is our own.
The chart above counts positions; this shows whose they are. Read down a column for what one organization holds across the whole topic, and across a row for who lines up on one issue. Where a cell carries more than one position, the strongest is shown and the rest are in the tooltip.
Ddisputes itQqualifies itNnames it as a problemPproposes a fix
Third-party & vendor risk: 4 issues against the 7 organizations cited on them. The number under each name is how many of these issues it is cited on.
A dot means this organization is not cited on that issue. It does not mean they are silent on it: an organization is cited where its document takes a position we could locate, and the absence of a citation is the absence of a finding, not a finding of absence. Who is represented lists everyone working on this topic, including those not cited above.
Where they disagree
No contradictions recorded on this topic yet.
The issues in full
Each issue carries the organizations that name it, the numbers behind it, and the remedies proposed - with the concrete steps under each. Every citation points at a section of a named document, so any count here can be checked.
Issue 012 organizations name it2026 evidence
The switching cost has moved from the model to the harness around it
Lock-in is no longer about weights or API compatibility. It sits in the tooling, integrations and developer workflow built around one model family - which means open weights do not, by themselves, buy you portability.
This reframing is the most practically useful thing in the third-party material. Databricks observes that when the harness a developer works in is tied to one provider, individual switching costs get high enough that the harness itself locks you to that model family, and spend can no longer follow the better price - which is precisely the flexibility that made open weights attractive. The remedy is architectural and has to be built before it is needed.
Put an abstraction between developers and the provider
Keep the developer experience while making the model underneath replaceable, so spend can move when price or capability moves.
Done when Production traffic runs through an abstraction that allows the model to be swapped by configuration, direct in-application model calls are inventoried, and one workload has run on a second provider for a week with what broke written down.
Inventory where model calls are made directly from application code rather than through a shared layer.0-30 daysCTO
Route production traffic through an abstraction that allows the model to be swapped by configuration.30-90 daysCTO
Prove it: run one workload on a second provider for a week and record what broke.90-180 daysCTO
Test model liquidity on a schedule
Portability that has never been exercised is an assumption. Measure the real cost of moving before a commercial negotiation depends on it.
Done when The highest-spend workload has a costed migration to an alternative provider, the exercise repeats annually, and the trend goes to the risk committee.
Pick the highest-spend workload and cost a full migration to an alternative provider.30-90 daysCIO
Repeat annually and report the trend to the risk committee - a rising number is the finding.ongoingCIO
The evidence — 3 documents
Organization
Document
Position
Boston Consulting GroupConsultancy · August 2026
Avoiding AI vendor lock-in riskOur reading Presents vendor lock-in as a strategy risk CEOs may not see coming, framed around ownership of the enterprise's accumulated intelligence rather than of any single tool.Do You Own Your Enterprise Cortex?
names it
DatabricksHyperscaler
Proven AI coding cost leversOur reading Locates lock-in below the contract: once a developer's tooling is expensive enough to leave, the harness ties spend to one model family whatever procurement negotiated.Harness and model flexibility
names it
PalantirEnterprise · July 2026
AI sovereignty is your alphaOur reading Argues for infrastructure that lowers barriers to switching between models and providers, and treats model agnosticism as a system attribute to develop before it is required.Infrastructure and model agnosticism
names it
Issue 022 organizations name it2026 evidence
There is no exit plan, and the data makes one harder every month
Contracts are signed without a documented route out, while accumulated context, fine-tuning and workflow history raise the cost of leaving continuously.
Write the exit plan before signing, not before leaving
Require a documented exit path - data export format, model artefacts, notice period, transition assistance - as a condition of contract.
Done when The AI vendor contract template requires export format, retention, deletion proof and transition support, existing high-spend contracts have been asked for the same at renewal with refusals recorded, and each contract names who keeps the exit path current.
Add exit requirements to the AI vendor contract template: export format, retention, deletion proof, transition support.0-30 daysProcurement
For existing high-spend contracts, request the same terms at the next renewal and record refusals.30-90 daysProcurement
Hold an owner for each contract accountable for keeping the exit path current.ongoingCIO
The evidence — 2 documents
Organization
Document
Position
Boston Consulting GroupConsultancy · August 2026
Avoiding AI vendor lock-in riskOur reading Argues the accumulating asset - the enterprise's own accrued intelligence - is what actually creates the dependency.The AI strategy risk CEOs may not see coming
names it
PalantirEnterprise · July 2026
AI sovereignty is your alphaOur reading Distinguishes tiers by whether control is contractual or technical, and treats exit leverage as something that must be designed rather than negotiated later.Contractual or public tier; exit leverage
names it
Issue 031 organization name it2026 evidence
Vendor diligence for AI is ordinary IT diligence with AI words added
Security questionnaires cover encryption, access and certification. Almost nothing asks what is specific to a model provider: training data provenance, retention of prompts, evaluation methodology, or what happens when the model is updated underneath you.
Add the questions that are actually about the model
Extend the vendor questionnaire with the handful of items that distinguish a model provider from any other SaaS supplier.
Done when The vendor questionnaire covers prompt and output retention, training use of customer data, update and deprecation notice, evaluation methodology and training-data provenance, notice is required before a model version change reaches production, and every refusal to answer is recorded as a finding.
Add: prompt and output retention, training use of customer data, model update and deprecation notice, evaluation methodology, and provenance of training data.0-30 daysProcurement
Require notice before a model version change affects production behaviour.30-90 daysProcurement
Treat a refusal to answer as a finding, and record it.ongoingRisk
Treat a downloaded model as untrusted code
Pretrained and open-source model artefacts enter through the same door as any dependency and warrant the same supply-chain controls.
Done when Open-source and pretrained model artefacts pass the same scanning gate as third-party code, and every model artefact in production has its source, version and hash on record.
Require open-source and pretrained model artefacts to pass the same scanning gate as third-party code.0-30 daysCISO
Record the source, version and hash of every model artefact in production.30-90 daysCIO
The evidence — 4 documents
Organization
Document
Position
Cloud Security AllianceInstitution · July 2026
AI security through the CISO lensOur reading Draws on three CISO summits to argue that point-in-time vendor checks cannot assure a dependency that changes weekly, and that vendor-run trust portals answer the seller's needs before the buyer's.Third-party risk management must evolve for an AI-dependent environment
names it
AccentureConsultancy · January 2025
AI agent identity managementOur reading Proposes provisioning, rotating and de-provisioning agent credentials on the same footing as human identity, extending diligence to what the vendor's agent can reach.AI agent identity management
proposes a fix
AnthropicFrontier lab · July 2026
Anthropic’s CISO guide to agentic AIOur reading Supplies the model-specific assessment a generic questionnaire lacks: what untrusted content the system ingests, what actions it can take and under whose identity, the blast radius if it is misaligned, and whether agent actions are distinguishable in your own telemetry.Four questions to assess agentic AI risk
proposes a fix
AWSHyperscaler · April 2026
Governance, risk and compliance for responsible AI in financial servicesOur reading Adds the dimension a flat questionnaire misses: run risk management in tiers so the more extensive scrutiny lands on the high-risk use cases, rather than holding every use case to one assessment.Tier the diligence to the use case, not the vendor
proposes a fix
Issue 041 organization name it1 qualifies it2026 evidence
Concentration risk is real and nobody has put a number on it
Organizations can say what they spend with a provider. Very few can say what fraction of revenue-critical processes would stop if that provider had an outage, changed its terms, or became unavailable in a jurisdiction.
Express the dependency as a share of revenue-critical processes
Spend is the wrong denominator. What matters is what stops.
Done when Each provider has a list of the revenue-critical processes that would degrade or stop without it, the exposure is reported as a share of revenue rather than of IT spend, and anything above the stated tolerance has a plan.
For each provider, list the revenue-critical processes that would degrade or stop without it.0-30 daysRisk
Express the exposure as a share of revenue, not a share of IT spend, and report it.30-90 daysCFO
Set a tolerance and a plan for anything above it.90-180 daysRisk
The evidence — 2 documents
Organization
Document
Position
PalantirEnterprise · July 2026
AI sovereignty is your alphaOur reading Ties the acceptable dependency to data classification, arguing high-value signal must compound in-house rather than in an external service.Tiering by data classification and control
names it
AccentureConsultancy · June 2025
State of cybersecurityOur reading Notes tariffs, trade restrictions and international tension accelerating third-party exposure, framing it as a moving rather than static measurement.Geopolitical acceleration of risk
qualifies it
Who is represented
This dossier is drawn from 24 organizations working on the subject, 7 of which are cited directly in the issues above.
Consultancy — 7
Accenture 2Boston Consulting Group 2Deloitte 3EY 3KPMG 2Booz Allen Hamilton 1Cognizant 1
Institution — 4
Cloud Security Alliance 3NIST 2World Economic Forum 2Association of Corporate Counsel 1