Imagine a bank that uses AI to detect fraud, authenticate customers and investigate suspicious transactions. Typically, those AI systems won't be entirely owned and operated in-house by the bank. Like most organizations, the bank would be relying on a host of external technologies and suppliers for the underlying AI models, the cloud infrastructure, APIs, security services, orchestration software, data platforms and more. If any one of these 'AI dependencies' changes, like a model becoming due for retirement, prices rising or new regulations requiring data to be stored in specific geographic jurisdictions, the organization will be forced to modify or replace a part of its AI set up to stop its operations being impacted. Depending on the scale and complexity of the task, what began as a change to an external system could become a business risk.
This situation - the fact that enterprises could find themselves at risk from a complex network of AI dependencies - is the subject of the IBM Institute of Business Value's latest report, The Calculus of AI Sovereignty. Based on a global survey of 1,000 senior executives responsible for AI, data, technology, or related enterprise capabilities, the report discusses how businesses can reduce this risk by building greater AI sovereignty. Importantly, it emphasizes that sovereignty should be strengthened selectively, where it matters most.
Greater AI penetration is a double-edged sword
The authors begin by acknowledging that generative AI is now well and truly out of the pilot-trial phase, with many organizations deploying it in live applications. For example, with AI agents increasingly being integrated into core business processes, CEOs expect nearly half of their operational decisions to be made by AI by 2030.
This increasing AI penetration is, however, a double-edged sword. While organizations can reap the productivity benefits of AI, they also face a greater business risk if their access to AI systems is disrupted.
As AI becomes more established within core operations, companies become increasingly dependent on the wider 'AI supply chain', which includes the models, infrastructure, platforms, and services that help deliver AI capabilities where and when they are needed.
AI dependencies are volatile
Rather than remaining constant, these dependencies are becoming increasingly "volatile". For example, vendors can "change pricing, discontinue models, alter APIs, or change licensing terms with relatively little notice". At the same time, regulators are showing an increasing willingness to change the rules in areas such as data residency (where data has to be geographically located), model transparency and AI accountability, for example.
Over the past 24 months, according to executives questioned for the report, there have been various changes in AI dependencies that have caused significant and unexpected shifts across the AI ecosystem. They include price increases, usage restrictions, model deprecations, changes to privacy and data-handling terms and new geographic access limitations.
To make matters worse, only 9% of executives feel they have an "excellent understanding" of their own AI dependencies.
Vendor lock-in magnifies the risk. Relying on a single vendor for any aspect of their AI gives organizations less flexibility in how they can respond to changes. According to the report:
- 71% of executives admit that switching their primary AI vendor today would be difficult
- 75% say they have tried switching AI vendors and found the process difficult
- 57% say replacing a core AI model would require significant system rebuilding
The answer? Greater sovereignty
The way to address this challenge is to build greater AI sovereignty. Organizations need to retain enough control over AI systems to continue operating without disruption as technologies, vendors, or regulations change. According to the report, "AI sovereignty preserves the organization's ability to move data, swap models, and shift workloads across hybrid cloud environments when AI dependencies shift, whether those shifts are technical, commercial, or regulatory".
Crucially, the report does not suggest that businesses need to have complete AI sovereignty. Few organizations could realistically afford to own and control every model, platform and piece of infrastructure that support AI within their operations. Instead, the authors recommend what they call "selective sovereignty": enterprises should aim for selective control, prioritizing areas where business value or operational risk justifies the investment.
Not every AI workload needs the same level of sovereignty. Companies should ask: In which parts of the organization do we need greater control over AI? How much control do we need? And how much are we willing to pay for that control? They can then classify AI systems into tiers, applying different sovereignty requirements to each.
How to build 'selective' sovereignty
For those AI systems deemed to require greater sovereignty, organizations should aim to reduce dependence on any single system or AI vendor, making it as easy as possible to migrate to an alternative supplier or technology if it becomes necessary.
The report recommends building AI environments around open-source technologies, open standards, interoperable technologies and portable architectures, rather than proprietary systems that tie organizations to a single vendor or system.
Businesses should be able to move or replace AI models, data and workloads with minimal disruption. For example, if a model is retired, prices increase or regulations require AI workloads to move to a different environment, organizations with portable architectures and working in open standards should be able to make those changes without significant overhauls or delays.
Another aspect of reducing AI dependency is adopting a multi-vendor strategy, although the authors point out that using multiple vendors is not in itself enough to deliver sovereignty. To reap the benefits of sovereignty, an enterprise needs to manage those vendors through common policies, security standards, and orchestration and governance systems. This enables it to manage all vendors as a strategic portfolio, optimizing for where it requires greater or lower levels of adaptability, resilience and control.
The upside: AI sovereignty delivers competitive advantage
Enabling strong AI sovereignty in the business processes and systems where it matters most will become essential as AI takes on more operational responsibilities. It's easy to view sovereignty as a purely "defensive" strategy that protects organizations against disruption. But the report argues that it also delivers an "upside" by creating a competitive advantage. Companies with greater AI sovereignty can embrace AI capabilities faster, expand into new markets without being slowed by regulatory requirements, have more negotiating power with suppliers and are more likely to succeed in an unpredictable AI landscape.


