While absolute technological sovereignty in the AI era is impossible, organisations must protect their operational resilience by mapping hidden infrastructure dependencies and building multi-provider flexibility.
Key Insights
- The rapid adoption of generative AI has replaced independent enterprise infrastructure with a highly centralised supply chain governed by a handful of mega-vendors and foreign jurisdictions.
- Current enterprise risk management frameworks fail to address these geopolitical and market threats, leaving businesses fully exposed to sudden vendor lockouts or hardware shortages.
- To safeguard core operations, leaders must shift from passive AI consumption to strategic diversification by deploying multi-model architectures that guarantee flexibility during a crisis.
Organisations spent a decade painstakingly building operational walls. Between 2014 and 2024, businesses implemented data localisation policies, mandated vendor diversification, and invested heavily in private cloud infrastructure to ensure total control over their technology.
Then, generative AI arrived. In under two years, mass enterprise adoption dismantled that carefully built independence. The rapid integration of AI has quietly centralised global tech power, creating a critical vulnerability for enterprises worldwide. While boards celebrate efficiency gains, a handful of mega-corporations now hold unprecedented authority over the models themselves, the compute that runs them, and the physical silicon.
This blind spot demands immediate attention. Speaking at the IERP® Global Conference 2026, NOF Consulting’s Global Threat Intelligence Strategist, Reece Soukoroff, argued that reclaiming true operational resilience requires leaders to confront who controls their infrastructure, mapping these hidden dependencies before external pressures paralyse core operations.
The Silent Surrender of Operational Resilience
How did this decade of hard-won sovereignty unravel so quickly? Reece framed the shift starkly, noting that businesses did not deliberately choose dependency; rather, the speed of adopting third-party solutions easily outpaced the slow process of building them in-house.
Organisations stopped pricing out the cost of building their own systems because signing a vendor contract and deploying an AI tool across a company took days instead of years. Today, the technological landscape is dangerously concentrated.
Notably, since 2022, 79% of global AI investment has flowed directly into the United States. Instead of relying on a diversified web of vendors, enterprises now depend on a highly centralised supply chain.
When a global operation sits under one primary jurisdiction, it creates a catastrophic single point of failure. If a market squeeze or geopolitical sanction hits that chokepoint, businesses lose access overnight and the illusion of control shatters.
Locating the Choke Points in Artificial Intelligence
True control over AI dissolves at three underlying choke points: foundational models, computational power, and hardware infrastructure. Reece illustrated this by mapping the architecture of Microsoft 365 Copilot.
When an organisation buys a Copilot licence, leaders assume full authority over its deployment. However, that single purchase silently introduces a rigid stack of external dependencies. The tool relies on OpenAI’s foundational models, which run on Microsoft Azure’s cloud infrastructure, powered by NVIDIA silicon, and manufactured by TSMC in Taiwan.
“You have five layers, and you only approve one of them,” Reece explained. “Every layer above that fab sits under one single jurisdiction. The moment you choose your tools, you’re also choosing your jurisdiction.”
This concentrated supply chain creates a false sense of security. Many boards mistakenly equate fine-tuning an open-source model on local servers with complete technological independence.
Yet, this setup is merely sovereignty-adjacent. If the underlying hardware belongs to external vendors subject to foreign sanctions or market shortages, true sovereignty remains out of reach. Ultimately, an organisation cannot claim authority over its operations if it relies on infrastructure it cannot replace.
The Geopolitical Threat to AI Operations
When mega-vendors face market shifts or geopolitical sanctions, these underlying dependencies become immediate threats to an enterprise’s AI security. Businesses frequently assume they govern their technology stack, yet sweeping vendor policy updates or unexpected export controls can grind operations to a halt.
If a government abruptly suspends model access for foreign nationals, or deep-pocketed hyperscalers buy out top-tier computational hardware years in advance, dependent companies face sudden operational failure without any transition period.
Reece captured this vulnerability perfectly. “Control isn’t something that gets taken from you in a single dramatic moment,” he explained. “The organisations affected never had control to begin with because they didn’t actually own the infrastructure. They just hadn’t been tested yet, so they thought that they did.”
Updating Enterprise Risk Management for the AI Era
Currently, traditional risk management frameworks offer little protection against these shocks. While the European Union Artificial Intelligence Act and National Institute of Standards and Technology (NIST) guidelines rigorously evaluate how an algorithm behaves, they overlook infrastructure governance and cross-border vulnerabiliites.
While organisations cannot completely eliminate third-party reliance, surviving sudden market shocks requires leaders to actively audit their technology stacks. This involves tracing every application down to its underlying foundational model, cloud provider, and hardware jurisdiction.
Once businesses map these hidden exposures, they must construct fallback strategies before a crisis hits. Relying on a single vendor creates a massive operational risk. Instead, deploying a multi-model, multi-provider architecture ensures essential functions continue running even if a primary vendor pulls the plug or suffers compute scarcity.
While unconditional technological independence remains out of reach for most, strategic diversification provides a powerful safety net when the rules of engagement shift. Reece shared: “You don’t get sovereignty, you get flexibility. If you can replace something, if you can have a different operation take over if something goes wrong, that saves you in the worst of times.”
Safeguarding Your Artificial Intelligence Operations
Understanding who dictates technological sovereignty is only the first step. Organisations must transition from being passive consumers of AI to conscious participants in their technology supply chains. The sovereignty decade may have unraveled, but that does not mean enterprise risk management should be abandoned to hyperscalers and foreign jurisdictions.
Rather than chasing the illusion of absolute independence, boards must focus their energy on building business agility. This means demanding transparency in vendor contracts, actively mapping hidden infrastructure bottlenecks, and treating geopolitical exposure as a core business metric rather than a theoretical edge case. The goal is to ensure that when a global supply squeeze or policy shift inevitably happens, your core operations remain intact.As Reece concluded, the future belongs to those who plan for disruption. “You may never own the hardware, or you may never build the next frontier model, but you can still decide deliberately exactly how dependent you’re willing to be and on whom.”






















