Artificial Intelligence & Machine Learning
,
Next-Generation Technologies & Secure Development
IBM Finds AI Vendor Disruptions Are Raising Costs and Operational Risk

As enterprises evolve their artificial intelligence projects from simple generative AI assistants to networks of AI agents that can reason, decide and take actions across core business functions, the stakes of getting AI wrong are getting higher.
See Also: Accelerate Vector Search for enterprise-scale AI with Elastic and NVIDIA
Earlier this year, CEOs said AI was already making 25% of corporate operational decisions but by 2030, they expect that figure to grow to 48%.
For CIOs, this creates an operational challenge. They need to have a clear picture of how and where AI is being used across the organization, but often wrangling that data is a challenge. According to a recent study from the IBM Institute for Business Value, 91% of senior executives said they don’t fully understand their organization’s dependencies across AI vendors, models and infrastructure. IBM surveyed 1,000 senior executives responsible for AI, data, technology or related enterprise capabilities from 17 industries across 16 geographies.
Executives also say that they feel stuck with their current vendors. Switching their primary AI vendor would be difficult for 71% of respondents, and 75% of those who attempted to make a vendor change in the past two years said the process was difficult, citing challenges with data portability, model re-validation, compliance requirements and technical lock-in.
“Vendor lock-in creates imbalance,” Conor Mlacak, CIO of Staples Canada, told IBM. “Once you’re locked in, you lose leverage.”
This lock-in creates a new kind of vendor dependency for enterprises, IBM found. Traditionally, when buying infrastructure or applications, enterprises signed contracts with vendors that had predictable terms and release and patching cycles.
With AI, this dependency extends to the model, which can be changed by an AI vendor on a non-structured release cycle, leading to potentially significant behavioral and cost changes. Service terms and safety controls can shift with little notice, and some models have been released and then withdrawn because of government regulation.
Changes cited by executives in the past 24 months include price increases, usage restrictions, model deprecations, changes to data-handling practices and performance degradation.
And organizations are eating the costs this volatility creates. Executives reported an average of six AI-related operational disruptions over the past two years, with vendor service issues cited as the top cause. A seven-day outage with a primary vendor would be a severe or critical problem for 81% of respondents. Anthropic’s Fable 5 model was recently unavailable for more than 18 days when the U.S. government hit the company with export controls on June 12.
CIOs are turning to AI sovereignty and flexible architectures to help control for this new uncertainty, and for those who succeed, the whole business can benefit. Organizations with the strongest control across their AI stacks protect 55% more operating profit from AI-driven disruption than organizations with weaker control.
The potential for costs to pile up helps CIOs make the financial case for this flexibility. When AI runs far from the data it’s using, organizations pay 2.8 times more in token processing. That can add up quickly. For example, for a $20 billion enterprise, that’s roughly $50 million annually in unnecessary spend.
That fix isn’t easy, according to IBM’s findings. Executives estimate it takes an average of 145 days to move AI training and operational data to a new environment, and 57% say replacing a core AI model would require significant decoupling or a full system rebuild. Despite all of that, 72% of executives say they’d accept a 20% cost increase to maintain multiple AI vendors for strategic flexibility.
IBM proposes a three-tiered rubric for technology leaders managing AI systems.
In the first tier, IBM puts mission-critical systems including fraud engines, proprietary decisioning platforms and core algorithms – areas where the cost of failure is greater than the cost of having options.
Tier two includes important but non-differentiating capabilities such as customer service AI, HR analytics and supply-chain optimization. Managed AI vendor dependency is acceptable here, but systems shouldn’t be left passive. Contractual data exit rights and continuous vendor monitoring should be standard.
Commodity services such as transcription, translation and routine automation sit in the third tier, where full AI sovereignty is an unnecessary cost. Dependency on a single vendor here should still be an intentional choice with deliberate governance.
IBM found that most organizations are already using multiple AI vendors, with 28% reporting they use four or more, but that this diversity is driven by organizational fragmentation, geography and legacy complexity rather than a deliberate strategy.
For CIOs looking to wrangle their AI systems, IBM recommends mapping your full dependency chain for every tier-one system, identifying and evaluating open-source options, and taking inventory of areas where you have identified lock-in. In the next two to four months, teams should standardize data portability formats, test actual extraction from vendor environments, validate model-swap pipelines and build provider failover into infrastructure where possible.
For every tier-one system, IT should have tested alternatives for data, models and runtime, along with migration strategies that they can implement in the event of a disruption.
Sergio Sánchez Gallego, CTIO, Telefónica España, told IBM that having modular flexibility is key to navigating the rapid shifts in the AI landscape. “Our architecture must be flexible enough to evolv, allowing us to swap components or adopt new technologies without starting from scratch,” he said.
