Is AI provider concentration the next enterprise risk?

Two US interventions in one summer cut enterprises off from models they had built on. LaunchLemonade's Joe Leung argues AI needs a resilience standard.

One network cable unplugged from a rack of enterprise servers in a data centre

Within a few weeks this summer, two of the largest AI model providers had access to their frontier models interrupted by the US government. Anthropic suspended access to Fable 5 and Mythos 5 under a government directive in June, and OpenAI's wider rollout of GPT-5.6 was held for a security review before it reached the public in July.

For the enterprises that had built products and workflows on those models, the interruptions were not a policy story but an operational one. The contributed piece below argues that the dependency they exposed deserves the same treatment as any other single point of failure, and that most organisations have not yet given it that.

Joe Leung is chief technology officer and co-founder of LaunchLemonade, a governed AI agent platform for regulated industries. He was previously an executive director at JPMorgan Chase, where he led work on blockchain infrastructure and privacy systems, and before that served as a commissioned officer and aerospace engineer in the Royal Air Force. The article that follows sets out his opinion.

Enterprise AI has moved quickly from experimentation to critical infrastructure. Boardrooms worldwide now focus on how fast organisations can deploy AI across customer service, software development, operations, compliance and knowledge work, rather than debating whether they should adopt it at all.

AI is becoming more integrated into the processes that businesses rely on daily. Yet in this rapid adoption, one risk has attracted surprisingly little attention: concentration.

Most companies focus on cybersecurity, cloud resilience and supply chain risk. Few have paused to consider a fundamental question: what happens if the AI provider your business relies on suddenly changes the rules?

Recent events should raise concerns. Anthropic temporarily halted access to its Fable 5 and Mythos 5 models under a US government directive, later resuming access with added safeguards. It has been widely reported as the first time the US has used export controls to halt a commercial AI model already in widespread public use. Meanwhile, OpenAI's wider release of GPT-5.6 was held back for weeks of government review before clearance. That one was a security review rather than an export control, but the pattern holds: government now sits between a finished model and the market.

While these situations differ, they highlight the same underlying issue, especially given that they occurred almost simultaneously. Decisions made by AI providers, often influenced by governments and regulators, can have immediate and serious impacts on thousands of organisations. For businesses that have deeply integrated a single AI provider into their products and operations, these decisions can cause operational events, and they highlight the concentration risk businesses are facing right now.

The concentration risk nobody is pricing in

Every generation of technology creates its own version of systemic dependence. In past decades, organisations learned to avoid heavy reliance on a single data centre, telecommunications provider or cloud region. Businesses understood that they needed to eliminate single points of failure before they led to business failures. AI needs similar consideration.

Currently, much of the enterprise AI ecosystem relies on a small number of foundational model providers, such as Anthropic and OpenAI. Even organisations that think they use a variety of AI applications often find those applications depend on the same core models or cloud infrastructure. This creates hidden concentration risk. As Warren Buffett put it, only when the tide goes out do you discover who has been swimming naked.

A provider outage can disrupt critical business workflows. A pricing change can drastically alter operating costs overnight. Retiring a model can require costly redevelopment. Changes to API policies can disrupt production systems. Regulatory intervention can limit model availability in certain regions, as we saw with Mythos. None of these scenarios is hypothetical any more.

The key point is not simply whether one provider is superior to another. Every leading AI company is innovating rapidly and has its own strengths for certain tasks. The challenge is that enterprises are building strategic capabilities on services they cannot rely upon, and sometimes through no fault of the provider's own. Amazon has invested billions in Anthropic and Anthropic runs on AWS, yet the Wall Street Journal reported that Amazon researchers jailbroke Fable 5 and chief executive Andy Jassy flagged the findings to the US Treasury, which preceded the order barring non-US access. The control looks odd on its own terms: Anthropic says the same capability is available from weaker models, including its own Opus 4.8, OpenAI's GPT-5.5 and China's Kimi K2.7, so restricting one model changes little. This shifts the emphasis from selecting technology to ensuring operational resilience.

AI infrastructure needs resilience standards

When assessing suppliers for other critical systems such as financial infrastructure, communications or cloud hosting, organisations ask tough questions. What happens during an outage? How quickly can we recover? Can we move to another provider if needed? What are the contractual exit provisions? Too often, these questions are missing from AI strategies. Instead, organisations focus on whichever model performs best in benchmark tests or offers the latest features. Performance is important, but resilience is equally crucial once AI is integrated into operational processes.

An AI model should not become a permanent commitment. It should be a replaceable component. The former creates dependence, while the latter creates options.

Regulators are already looking beyond the model

This issue goes beyond operational best practice. It is increasingly becoming a governance concern. In financial services, healthcare, critical infrastructure and other regulated sectors, supervisory expectations are shifting. Regulators expect organisations to understand the dependencies created by third-party technology providers, assess concentration risk and show operational resilience and portability to avoid vendor lock-in. AI is inevitably being drawn into these discussions.

Organisations should anticipate increased scrutiny on questions such as which AI providers are essential for critical business processes, what happens if those providers become unavailable, how quickly services can be restored, whether fallback plans are in place and how quickly they can be implemented, and whether workloads can be moved without major redevelopment.

These questions are already asked about cloud infrastructure, outsourcing arrangements and operational resilience programmes. AI should not be treated differently just because it is the newest technology.

Designing for options rather than lock-in

The good news is that concentration risk is mainly an architectural challenge, not an unavoidable result of AI adoption. The organisations likely to be most resilient will not be those that can predict which AI provider will dominate the next decade. They will be those that do not make that prediction a requirement for success.

This begins by designing systems that separate business logic from model selection. Instead of tightly linking applications to one provider's APIs, organisations should implement abstraction layers that allow models to be substituted easily. Provider-independent routing allows businesses to choose different models based on cost, latency, capability or availability without needing to rebuild entire applications.

Maintaining portability is equally crucial. If switching providers takes months of redevelopment, extensive retraining or major operational disruption, then the organisation has already incurred technical debt in the form of dependency. A real exit strategy should be in place before it is needed. Resilience planning should also extend beyond technology. Organisations should regularly simulate provider outages, regulatory restrictions and pricing changes in the same way they conduct disaster recovery exercises or cyber resilience tests. These exercises often reveal assumptions that are not apparent during normal operations.

Competition will continue to reshape the market

The AI landscape is evolving rapidly. New foundational models are continually emerging. Open-source alternatives are becoming more capable. Specialist models are outperforming general-purpose systems in specific areas. Pricing is fluctuating as competition heats up.

This is precisely why flexibility is essential. Architectures built around options allow organisations to capitalise on innovation rather than being limited by past decisions. Businesses can adopt new models that create value while retaining the ability to revert or diversify if necessary. In fast-changing markets, adaptability is often more valuable than optimisation.

The next phase of enterprise AI

The first phase of enterprise AI focused on demonstrating the technology's capabilities. The second phase centres on making it reliable. History shows that technologies become truly transformative not when they become more powerful, but when organisations learn how to use them safely, dependably and at scale.

AI is reaching that stage. Business leaders should no longer ask only, "Which model performs best today?" They should also ask, "What happens if this provider has a bad week?" That question goes beyond technical resilience. It involves governance, operational continuity, regulatory compliance and long-term competitiveness.

The organisations that build flexibility into their AI architecture today will be better prepared to handle disruptions tomorrow. They will have the agility to embrace new technologies, adapt to regulatory changes and ensure continuity when the market shifts.

AI providers will keep innovating. Governments will continue to intervene where they deem it necessary. Market leaders will rise and fall. These forces are mostly beyond an enterprise's control. Architectural resilience is not. As AI becomes essential to business operations, provider concentration should be viewed as a strategic enterprise risk, not because disruption is certain, but because resilience has always defined the organisations that thrive through technological change.