Three Companies Now Run Your AI. Could You Leave Any of Them?
Three foundation model providers now control roughly 90% of enterprise AI spend, and only 6% of leaders believe they could switch their main one without disruption. In Europe, that dependency has stopped being a procurement preference and become a supervised risk. A consultant’s guide for leaders who bought capability and acquired a dependency they never priced.
The invoice arrives before the strategy does. In mid-2026 Microsoft, the company with the deepest AI distribution advantage in enterprise software, terminated its internal Claude Code licences after per-engineer bills reached 500 to 2,000 dollars a month, and redirected those engineers to its own tooling. Uber capped agentic coding spend at 1,500 dollars per employee per month. These are two of the most sophisticated technology buyers on earth, and both discovered the same thing at the same time: the price of the AI they had built into daily work was set by someone else, and it moved.
If that is happening to Microsoft, it is happening to you, and the difference is that Microsoft can build its own model and you cannot. Menlo Ventures’ December 2025 enterprise survey, as analysed by Brookings, found that three providers, Anthropic at roughly 40%, OpenAI at 27%, and Google at 21%, together control almost 90% of the 37 billion dollar enterprise LLM market. Brookings did not hedge the description. It called the market an oligopoly. The capability you spent two years embedding into customer support, code, underwriting, and document work now rests on a supplier base of three, and the terms are theirs to change.
The previous posts in this series looked inward: selecting use cases, capturing ROI, scaling agents, redesigning the org chart, the seniority cliff. This post looks at the supply side. Not what AI can do for you, but who you are now structurally dependent on to keep doing it, and what happens when that dependency meets a price rise, a deprecated model, or a European supervisor.
📊 The Numbers: Three providers control close to 90% of the 37 billion dollar enterprise LLM market (Menlo Ventures, via Brookings). Yet in Zapier’s 2026 enterprise survey, while 81% of leaders are concerned about vendor dependency, only 6% believe they could switch their primary provider without material operational disruption.
This is not the vendor risk your procurement team already manages
Enterprises have managed software vendor dependency for decades. This is a different animal, and treating it like the old one is the first mistake.
Classic vendor lock-in was contractual and data-format based. You could, with effort and a migration budget, move from one ERP to another. AI concentration operates across five layers at once and they compound: the model, the orchestration layer that coordinates agents, the data your workflows have accumulated inside the vendor’s environment, the governance evidence a European regulator will one day ask for, and the organisational knowledge your people have built around one provider’s quirks. An organisation that is 60% locked in at the model layer, 70% at orchestration, and 80% at data does not have an average switching cost. It has one that reflects all three dependencies intersecting at once. Lock-in here is multiplicative, not additive.
Underneath the concentration sits a harder economic fact. The binding constraint at the AI frontier is no longer capability. It is compute supply. The 2026 foundation model landscape from Information Matters found three top-tier vendors signalling compute-constrained operations in the first quarter of 2026, and noted that frontier pricing has stopped declining, with open-weight models now doing the price-decline work instead. When supply is scarce and demand is inelastic, because you have already rebuilt your workflows around the product, the pricing power sits entirely with the seller. Most enterprises walked into that position without naming it.
The switching cost you cannot see until you try to move
The gap between knowing this and doing anything about it is the real story, and it is stark.

Zapier’s 2026 enterprise survey found that 81% of leaders are concerned about AI vendor dependency, and 47% say a key business function would stop working if their primary vendor suffered an outage or changed its pricing. Only 6% believe they could switch their primary provider without material operational disruption. Read the three bars together and the awareness is nearly universal while the capacity to act is almost nonexistent. Enterprises have deployed AI far faster than they have built the architecture to exit it.
Two things make the exposure worse than the numbers suggest. The first is hidden concentration: a team that believes it runs a diversified multi-vendor estate often finds several nominally independent SaaS tools all running on the same underlying cloud, so one provider disruption takes down what looked like three separate systems. The second is model deprecation. Providers retire and replace model versions on their schedule, not yours, and a version change can silently alter a workflow you validated against the old one. The collapse of Builder.ai, once valued at 1.3 billion dollars and backed by Microsoft, showed the extreme case: customers tightly coupled to the single vendor were stranded when it disappeared, unable to access critical functions or data.
💡 Key Insight: The vendor does not have to fail to hurt you. A price change is enough, and 47% of enterprises say a key function would stop if it came. You did not buy a tool. You bought a dependency, and a dependency is priced by whoever holds the other end of it.
The vendor is quietly moving into your business
Concentration would be manageable if the concentrated suppliers stayed in their lane. They are not.
Brookings framed the deeper risk precisely in its 2026 analysis of what happens when AI companies compete with their customers. The providers you depend on for infrastructure are also building applications, agents, and products that overlap with what their enterprise customers sell. Post 9 in this series documented the AI-native competitor entering your market from outside. This is the same threat arriving from inside your own supply chain: the vendor whose model powers your product has both the capability and the usage data to build a version of it itself.
This is why the concentration matters strategically, not only operationally. The durable moat is shifting from the systems of record that SaaS incumbents owned to the systems of action that AI agents now execute. When your agents run on a provider’s proprietary orchestration layer, that provider accumulates the logic of how your business actually runs. You are not just a customer. You are a training signal, handing over the one asset, your operational know-how, that was supposed to be yours.
In Europe, concentration is no longer a preference. It is supervised.
Everywhere in the world, vendor concentration is a commercial judgment. In Europe, for a large and growing set of enterprises, it has become a legal obligation with a supervisor attached. This is the part US-written analysis almost entirely misses, and it is where the European lens stops being a differentiator and becomes the whole argument.
The Digital Operational Resilience Act, DORA, has applied across the EU since 17 January 2025. It requires financial entities to assess and manage concentration risk in their ICT supply, document a credible exit strategy for any provider supporting a critical or important function, and test that exit at least annually. Article 28 demands the concentration assessment and the ability to exit without undue disruption, Article 29 a pre-contract concentration assessment before signing, and Article 30 the exit and transition clauses that make the right to leave actually executable. A right-to-exit clause that no one could ever exercise is exactly what supervisors now probe.
The dependency this addresses is already documented. The European Banking Authority’s 2024 risk dashboard found over 70% of significant banks rely on at least one of the three hyperscalers, AWS, Microsoft Azure, or Google Cloud, for at least one critical function, with over 65% using at least two. On 18 November 2025 the European Supervisory Authorities designated the first 19 critical ICT third-party providers, a list including AWS, Microsoft Azure, Google Cloud, Oracle, IBM, SAP, and Deutsche Telekom, and the DORA Joint Oversight Forum began its first examinations across 2026 with binding recommendations expected. Since almost every production AI workload runs on precisely these designated hyperscalers, your AI vendor concentration and your regulated ICT concentration are now the same problem, viewed by the same supervisor.
⚠️ Watch Out: Your multi-vendor AI strategy may be three vendors running on one cloud. Under DORA that is not diversification, it is undocumented concentration, and an untested exit plan is what an examiner assumes is fiction. If your firm is in scope and your AI estate is not in your Register of Information with a tested exit, you are exposed on both the operational and the regulatory axis at once.
The sovereignty option is real, and it is oversold
The instinctive European answer is to buy European, and sovereignty has moved from ambition to procurement criterion faster than most incumbents realise. ISG’s 2026 research found European enterprises reclassifying sovereign cloud from a compliance safeguard to core infrastructure for AI workloads under EU jurisdiction. Mistral has become the most production-ready European model option and saw revenue surge simply for being an alternative to the US labs, with SAP and Mistral announcing a sovereign AI stack on SAP’s Business Technology Platform in November 2025. In April 2026 the Cohere and Aleph Alpha merger, backed by the German and Canadian governments and a Schwarz Group investment, set out to build a transatlantic sovereign alternative for regulated and public-sector buyers.
That is the genuine opportunity. Now the honest counterweight, because a consultant who sells only the upside is not worth hiring. Forrester’s 2026 European predictions concluded plainly that no European enterprise will shift entirely from the US hyperscalers in 2026, and that a wholesale move to local suppliers is impractical in the short to medium term. Sovereignty reduces one dependency by creating another, and a European provider under compute constraint has the same pricing power a US one does. The point is not to swap a US monoculture for a European one. It is to end the monoculture.
What the organisations getting this right do differently
The ones handling this well are not the ones who picked the perfect vendor. They are the ones who refused to depend absolutely on any single one, and built the option to move before they needed it.
-
Build the abstraction layer before the second vendor, not after. An abstraction layer separates your workflow logic from any one provider’s API, so a switch means changing the interface rather than rewriting every integration. Enterprises that build it into the first deployment add or switch providers with far less migration effort than those who wired everything directly to a single API. It has a small upfront cost and a large retroactive one.
-
Run a portfolio, not a marriage. Route the workload to the model that fits it, keep at least one credible secondary provider live in production rather than on a slide, and treat open-weight models as the pricing-discipline benchmark that stops a frontier vendor’s increases from being uncontestable.
-
Make the exit plan real by testing it. A fallback that has never been activated is not a fallback. Run the switch on a non-critical workload on a schedule, so that when a price rise or deprecation arrives, the migration is a rehearsed procedure and not a crisis. In DORA scope, this is not optional. It is the annual test.
-
Put concentration on the enterprise risk register with a named owner. Not in an architecture document. On the risk register, alongside supply-chain concentration and key-person dependency, with a reported metric: the share of critical AI workload resting on any single provider, and the tested time to switch it. Risks that are not owned and not measured do not get managed.
-
Negotiate from optionality. Every move above is also commercial leverage. A vendor that knows you can leave prices differently from one that knows you cannot, and the 6% who could switch are the only ones with real bargaining power at renewal.
✅ Leadership Action: Before the next renewal, commission a real exit test on your single highest-value AI workload. Not a clause, not a slide, an actual migration to an alternative provider on a non-critical instance. The exercise produces three things at once: the true switching cost, a rehearsed procedure, and, in DORA scope, the evidence a supervisor will ask for. If it cannot be done, that is the finding.
The leader’s 30-day move
A concrete sequence before the next AI contract renewal is signed.
-
Week 1. Map the true concentration. For every production AI workload, record the model provider, the orchestration platform, and the underlying cloud. Collapse the nominal vendor count to the real one. Most leaders discover their diversification is thinner than the procurement list suggests.
-
Week 2. For the three highest-value workloads, cost the exit. What would it actually take, in time and money, to move each to an alternative provider? The honest number is your switching cost, and it is almost always higher than assumed.
-
Week 3. Stand up one abstraction layer and bring one credible secondary provider into live production on a non-critical workload. One workflow, genuinely portable, tested end to end.
-
Week 4. Add AI vendor concentration to the enterprise risk register with a named executive owner and two reported metrics: single-provider share of critical workload, and tested time to switch. If your firm is in DORA scope, cross-reference your AI estate against your Register of Information and confirm each critical dependency has an exit that has actually been tested.
The consultant’s takeaway
Every enterprise that scaled AI in the last two years made a rational decision at each step: pick the best model, integrate it deeply, move fast, ship value. The sum of those steps is a position almost nobody chose deliberately: a business-critical capability resting on three suppliers, priced by them, deepening by the quarter, with an exit that 94% of leaders admit they could not execute cleanly. The efficiency was real and immediate. The dependency is real and compounding, and it was never priced into any business case.
For European leaders this is sharper than for most, and for once the regulation is an asset rather than a burden. DORA has already forced the financial sector to name its concentration, document its exits, and test them, which is precisely the discipline the economics demanded anyway. The firms treating that as a compliance chore will produce a binder. The firms treating it as an operating-model decision will end up with something more valuable: a genuine ability to move, and therefore a genuine ability to negotiate.
The next renewal will not turn on which model is best. It will turn on whether you could walk away from the one you have. The vendor already knows the answer to that question, and has been pricing you against it. The only thing left to decide is whether you know it too.