Two risks are sitting in most organisations right now, and they are owned by different people.
The first is dependency, which belongs to procurement: what happens if the supplier fails, withdraws or reprices. The second is capability, which belongs loosely to HR, or operations, or nobody: what happens to your own people's skills as more of the work moves to the machine.
The product of the two belongs to nobody at all. Which is why nobody has priced it, and the product is where the risk actually lives.
Consider what the AI supply chain looks like from a desk in Dublin, or Frankfurt, or Singapore. The frontier models that matter are built by a handful of firms, mostly American. They run on accelerator chips designed substantially by one company and fabricated overwhelmingly by a single manufacturer in Taiwan. I take no view here on how cross-strait relations resolve; the point is narrower. A concentration like that, found in any other supply chain, would sit at the top of the risk register on its own.
Access is mediated by commercial terms that change at renewal and trade policy that can change overnight. If that sounds abstract, look at the metabolism of the rules. In January 2025 the United States published a framework sorting the world's countries into tiers with different rights of access to American AI technology. Four months later it was rescinded, before it had ever taken effect. No position here on the merits of either move. The point is that the rules governing who may use the most capable systems changed twice inside a year, and there is no reason to believe they have stopped.
On its own, all of that is a procurement problem, and procurement has known answers. A second provider. An open-weight model you can run yourself. An abstraction layer. Contractual notice periods. Unglamorous, well understood, solvable.
Deskilling on its own is also solvable, if less fashionably: keep people in the substance of the work rather than nominally above it, and maintain the practice that judgment depends on.
Multiply the two and you get something neither playbook covers. An organisation whose core workflows require a specific external model, and whose people can no longer perform the underlying task without it, has no fallback at any price. The outage arrives, or the export restriction, or the tenfold price rise, and the firm discovers that the human capability it optimised away was not a redundancy. It was the business continuity plan.
It takes no geopolitics to see the shape of that. In July 2024 one faulty update from a single security vendor disabled roughly eight and a half million machines in a morning, grounding flights, cancelling surgeries and stopping broadcasters mid-transmission. That had nothing to do with AI and everything to do with what happens when many organisations depend on one supplier and have no rehearsed way of working without it. Sit with the thought of an equivalent morning striking the model your drafting, analysis and client response now quietly route through.
The likelier version is duller. Models are retired on the provider's schedule rather than yours, and a replacement model is not the same model. Workflows validated against one system's behaviour degrade quietly when the system underneath them changes, which is a compliance problem as much as a quality one. Nobody sends a notice saying your controls are now unevidenced.
Financial regulators saw this coming. The EU's Digital Operational Resilience Act has applied since January 2025 because supervisors concluded that dependence on a few critical technology providers had become systemic. It obliges firms to map critical third-party dependencies, assess concentration, and maintain tested exit strategies. Very few firms I meet have classified their model provider as a critical third party. On any honest reading of how these tools are now used, it is becoming exactly that, and supervisors will reach that conclusion before most risk registers do.
Business continuity planning in most organisations still asks about data centres and backup power. The dependency that matters now is cognitive, and it is being deepened one efficiency gain at a time.
Something to try this week. Pick one revenue-critical workflow and run it for a day as though the model were gone. Not a tabletop exercise. Actually unplug it, with the people who do the work, and time them.
You will learn three things by the afternoon. How long the work takes without it. What your degraded mode actually is, rather than what the policy claims. And whether anyone in the room still knows how to do it at all.
That third answer is the one to act on.