Third-party & vendor risk

The model you did not build and the supply chain behind it.

34documents on this topic
23organizations represented
4issues named
11sourced citations
0sourced statistics

The state of it

One of 7 topics within Governance & oversight.

34 documents from 23 organizations address the model you did not build. The useful finding is that the research has largely stopped talking about lock-in as a model problem and started treating it as an architecture problem.

Databricks makes the sharpest version of the argument: the switching cost has moved off the model and into the harness around it. Once developers' tooling is bound to one model family, the harness itself becomes the lock-in, and the ability to move spend to a cheaper or better model disappears regardless of how open the weights are. Palantir arrives at the same place from the opposite direction, arguing for model agnosticism and what it calls model liquidity as an attribute you build into your systems now, before you need it.

The weaker area is diligence. Vendor security requirements in this research are mostly generic IT controls with AI language attached; almost nothing specifies what to verify about a model provider that differs from what you would ask any SaaS vendor.

The issues, by agreement

How many independent organizations name each issue as a problem. An issue is only as real as the number of separate publishers that identify it, so the count is the ranking. Bars are organizations, not documents. Where the count reads ours, no publisher here states the issue and the analysis is our own.

Who takes which position

The chart above counts positions; this shows whose they are. Read down a column for what one organization holds across the whole topic, and across a row for who lines up on one issue. Where a cell carries more than one position, the strongest is shown and the rest are in the tooltip.

Ddisputes it Qqualifies it Nnames it as a problem Pproposes a fix
Third-party & vendor risk: 4 issues against the 7 organizations cited on them. The number under each name is how many of these issues it is cited on.
Issue Palantir · 3 Accenture · 2 Boston Consulting Group · 2 AWS · 1 Anthropic · 1 Cloud Security Alliance · 1 Databricks · 1
The switching cost has moved from the model to the harness around it N · N · · · N
There is no exit plan, and the data makes one harder every month N · N · · · ·
Vendor diligence for AI is ordinary IT diligence with AI words added · P · P P N ·
Concentration risk is real and nobody has put a number on it N Q · · · · ·

A dot means this organization is not cited on that issue. It does not mean they are silent on it: an organization is cited where its document takes a position we could locate, and the absence of a citation is the absence of a finding, not a finding of absence. Who is represented lists everyone working on this topic, including those not cited above.

Where they disagree

No contradictions recorded on this topic yet.

The issues in full

Each issue carries the organizations that name it, the numbers behind it, and the remedies proposed - with the concrete steps under each. Every citation points at a section of a named document, so any count here can be checked.

Issue 012 organizations name it2026 evidence

The switching cost has moved from the model to the harness around it

Lock-in is no longer about weights or API compatibility. It sits in the tooling, integrations and developer workflow built around one model family - which means open weights do not, by themselves, buy you portability.

This reframing is the most practically useful thing in the third-party material. Databricks observes that when the harness a developer works in is tied to one provider, individual switching costs get high enough that the harness itself locks you to that model family, and spend can no longer follow the better price - which is precisely the flexibility that made open weights attractive. The remedy is architectural and has to be built before it is needed.

How to fix it — 2 approaches, 5 steps

Put an abstraction between developers and the provider

Keep the developer experience while making the model underneath replaceable, so spend can move when price or capability moves.

Done when Production traffic runs through an abstraction that allows the model to be swapped by configuration, direct in-application model calls are inventoried, and one workload has run on a second provider for a week with what broke written down.

  1. Inventory where model calls are made directly from application code rather than through a shared layer.0-30 daysCTO
  2. Route production traffic through an abstraction that allows the model to be swapped by configuration.30-90 daysCTO
  3. Prove it: run one workload on a second provider for a week and record what broke.90-180 daysCTO

Test model liquidity on a schedule

Portability that has never been exercised is an assumption. Measure the real cost of moving before a commercial negotiation depends on it.

Done when The highest-spend workload has a costed migration to an alternative provider, the exercise repeats annually, and the trend goes to the risk committee.

  1. Pick the highest-spend workload and cost a full migration to an alternative provider.30-90 daysCIO
  2. Repeat annually and report the trend to the risk committee - a rising number is the finding.ongoingCIO
The evidence — 3 documents
OrganizationDocumentPosition
Boston Consulting GroupConsultancy · August 2026Avoiding AI vendor lock-in riskOur reading Presents vendor lock-in as a strategy risk CEOs may not see coming, framed around ownership of the enterprise's accumulated intelligence rather than of any single tool.Do You Own Your Enterprise Cortex?names it
DatabricksHyperscalerProven AI coding cost leversOur reading Locates lock-in below the contract: once a developer's tooling is expensive enough to leave, the harness ties spend to one model family whatever procurement negotiated.Harness and model flexibilitynames it
PalantirEnterprise · July 2026AI sovereignty is your alphaOur reading Argues for infrastructure that lowers barriers to switching between models and providers, and treats model agnosticism as a system attribute to develop before it is required.Infrastructure and model agnosticismnames it

Issue 022 organizations name it2026 evidence

There is no exit plan, and the data makes one harder every month

Contracts are signed without a documented route out, while accumulated context, fine-tuning and workflow history raise the cost of leaving continuously.

How to fix it — 1 approach, 3 steps

Write the exit plan before signing, not before leaving

Require a documented exit path - data export format, model artefacts, notice period, transition assistance - as a condition of contract.

Done when The AI vendor contract template requires export format, retention, deletion proof and transition support, existing high-spend contracts have been asked for the same at renewal with refusals recorded, and each contract names who keeps the exit path current.

  1. Add exit requirements to the AI vendor contract template: export format, retention, deletion proof, transition support.0-30 daysProcurement
  2. For existing high-spend contracts, request the same terms at the next renewal and record refusals.30-90 daysProcurement
  3. Hold an owner for each contract accountable for keeping the exit path current.ongoingCIO
The evidence — 2 documents
OrganizationDocumentPosition
Boston Consulting GroupConsultancy · August 2026Avoiding AI vendor lock-in riskOur reading Argues the accumulating asset - the enterprise's own accrued intelligence - is what actually creates the dependency.The AI strategy risk CEOs may not see comingnames it
PalantirEnterprise · July 2026AI sovereignty is your alphaOur reading Distinguishes tiers by whether control is contractual or technical, and treats exit leverage as something that must be designed rather than negotiated later.Contractual or public tier; exit leveragenames it

Issue 031 organization name it2026 evidence

Vendor diligence for AI is ordinary IT diligence with AI words added

Security questionnaires cover encryption, access and certification. Almost nothing asks what is specific to a model provider: training data provenance, retention of prompts, evaluation methodology, or what happens when the model is updated underneath you.

How to fix it — 2 approaches, 5 steps

Add the questions that are actually about the model

Extend the vendor questionnaire with the handful of items that distinguish a model provider from any other SaaS supplier.

Done when The vendor questionnaire covers prompt and output retention, training use of customer data, update and deprecation notice, evaluation methodology and training-data provenance, notice is required before a model version change reaches production, and every refusal to answer is recorded as a finding.

  1. Add: prompt and output retention, training use of customer data, model update and deprecation notice, evaluation methodology, and provenance of training data.0-30 daysProcurement
  2. Require notice before a model version change affects production behaviour.30-90 daysProcurement
  3. Treat a refusal to answer as a finding, and record it.ongoingRisk

Treat a downloaded model as untrusted code

Pretrained and open-source model artefacts enter through the same door as any dependency and warrant the same supply-chain controls.

Done when Open-source and pretrained model artefacts pass the same scanning gate as third-party code, and every model artefact in production has its source, version and hash on record.

  1. Require open-source and pretrained model artefacts to pass the same scanning gate as third-party code.0-30 daysCISO
  2. Record the source, version and hash of every model artefact in production.30-90 daysCIO
The evidence — 4 documents
OrganizationDocumentPosition
Cloud Security AllianceInstitution · July 2026AI security through the CISO lensOur reading Draws on three CISO summits to argue that point-in-time vendor checks cannot assure a dependency that changes weekly, and that vendor-run trust portals answer the seller's needs before the buyer's.Third-party risk management must evolve for an AI-dependent environmentnames it
AccentureConsultancy · January 2025AI agent identity managementOur reading Proposes provisioning, rotating and de-provisioning agent credentials on the same footing as human identity, extending diligence to what the vendor's agent can reach.AI agent identity managementproposes a fix
AnthropicFrontier lab · July 2026Anthropic’s CISO guide to agentic AIOur reading Supplies the model-specific assessment a generic questionnaire lacks: what untrusted content the system ingests, what actions it can take and under whose identity, the blast radius if it is misaligned, and whether agent actions are distinguishable in your own telemetry.Four questions to assess agentic AI riskproposes a fix
AWSHyperscaler · April 2026Governance, risk and compliance for responsible AI in financial servicesOur reading Adds the dimension a flat questionnaire misses: run risk management in tiers so the more extensive scrutiny lands on the high-risk use cases, rather than holding every use case to one assessment.Tier the diligence to the use case, not the vendorproposes a fix

Issue 041 organization name it1 qualifies it2026 evidence

Concentration risk is real and nobody has put a number on it

Organizations can say what they spend with a provider. Very few can say what fraction of revenue-critical processes would stop if that provider had an outage, changed its terms, or became unavailable in a jurisdiction.

How to fix it — 1 approach, 3 steps

Express the dependency as a share of revenue-critical processes

Spend is the wrong denominator. What matters is what stops.

Done when Each provider has a list of the revenue-critical processes that would degrade or stop without it, the exposure is reported as a share of revenue rather than of IT spend, and anything above the stated tolerance has a plan.

  1. For each provider, list the revenue-critical processes that would degrade or stop without it.0-30 daysRisk
  2. Express the exposure as a share of revenue, not a share of IT spend, and report it.30-90 daysCFO
  3. Set a tolerance and a plan for anything above it.90-180 daysRisk
The evidence — 2 documents
OrganizationDocumentPosition
PalantirEnterprise · July 2026AI sovereignty is your alphaOur reading Ties the acceptable dependency to data classification, arguing high-value signal must compound in-house rather than in an external service.Tiering by data classification and controlnames it
AccentureConsultancy · June 2025State of cybersecurityOur reading Notes tariffs, trade restrictions and international tension accelerating third-party exposure, framing it as a moving rather than static measurement.Geopolitical acceleration of riskqualifies it

Who is represented

This dossier is drawn from 24 organizations working on the subject, 7 of which are cited directly in the issues above.

Consultancy — 7

Accenture 2 Boston Consulting Group 2 Deloitte 3 EY 3 KPMG 2 Booz Allen Hamilton 1 Cognizant 1

Institution — 4

Cloud Security Alliance 3 NIST 2 World Economic Forum 2 Association of Corporate Counsel 1

Academic — 1

Carnegie Mellon SEI 1

Hyperscaler — 5

AWS 2 Databricks 1 Google Cloud 1 IBM 1 Microsoft 1

Frontier lab — 1

Anthropic 1

Enterprise — 2

Palantir 1 Uber 1

Vendor — 3

IntuitionLabs 2 Andreessen Horowitz 1 Palo Alto Networks 1

Other — 1

CISA 1