RDIV / ANSWER AI-005 · SOVEREIGN INTELLIGENCE
What Is AI Vendor Dependency?
AI vendor dependency becomes a governance risk when institutions cannot independently inspect, replace, migrate, suspend, or continue critical functions.
Fix the object first.
Vendor dependency is a spectrum. At one end, a provider supplies a replaceable component. At the other, the provider controls a tightly coupled stack of model, data interfaces, workflows, logs, security controls, and institutional knowledge that cannot be replaced without operational collapse.
The visible label is not the whole system.
Lock-in changes bargaining power, continuity risk, and oversight. It can also hollow out internal expertise until the customer cannot independently evaluate what it buys.
Trace the burden.
- OMB M-25-22 explicitly tells federal agencies to pay attention to vendor sourcing, data portability, and long-term interoperability to avoid costly single-vendor dependencies.
- Vendor use can be efficient and beneficial when exit, audit, and continuity are preserved.
- Perfect portability may be impossible where providers offer genuinely differentiated capabilities.
- The acceptable dependency threshold depends on mission consequence and recovery time.
Where the work adds something.
RDIV reframes vendor lock-in as a command problem: dependency is critical when the formal authority cannot realistically inspect, contest, suspend, replace, or continue the function without the provider.