Cited works

This note is cited on pages 44 and 76 of the report of the parliamentary mission on the alignment of artificial intelligence systems, submitted to the French Government on 29 July 2026. See the contribution and cited passages →

Cited passages

Report, page 44, note 101 — refers to page 10 of the note. The stack of ten technological layers on which every AI process in Europe rests, from hardware to cognitive frames.

Report, page 76, note 154 — refers to page 4 of the note. The scale gap between European actors and hyperscalers, and the consolidation of the rare European challengers in compute.

Edition

April 2026
34 pages

Cited in

Pages 44 & 76
Parliamentary report

Notes

101 & 154
Pages 10 & 4

Recommendation

No. 32
Public buyers

Cited in institutional work

This note is cited on page 76 of the report of the French Senate's parliamentary mission on the alignment of artificial intelligence systems, delivered to the French minister for digital affairs in July 2026. Read the contribution and the cited passages in French →

Board synthesis

Decide in sixty seconds

AI installs a dependency that grows quietly. The leader keeps the hand on it through thresholds set before the integration.

Understand

The three forms of dependency

Technical

The system becomes indispensable to the running of a critical process.

Commercial

A single supplier sets the prices and the conditions.

Strategic

The tool takes the hand on the business decision.

Governing

The three levers

Diversification

Two sources per critical function, migration capacity maintained.

Transparency

Explainable systems, teams that understand the tool.

Resilience

A degraded mode retained and tested.

Decide

The board's three acts

Map

List dependencies, rank them by criticality.

Set the thresholds

Non-delegation and reversibility, arbitrated upstream.

Test

Rehearse the degraded mode and the supplier exit.

Five board questions

The indicators that must reach the committee

  • ConcentrationHow many suppliers carry each critical function.
  • Exit capacityCost and lead time of the switchover, established before it is needed.
  • Degraded modeWhat the organisation still does without the system.
  • Delegation ceilingDecisions that remain human under any circumstance.
  • Last test evidenceDate on which the switchover and degraded mode were exercised.

Technological dependency is a permanent strategic risk. The board sets two markers, on the same footing as financial or legal risk: the decisions that stay human in all circumstances, and the exit capacity maintained on every critical dependency. Decision sovereignty is built there, in the thresholds the leader sets and holds.

How can organisations govern the risks of technological dependency and decisional concentration linked to AI?

One of the least visible and most important risks of AI integration is the creation of technological dependency . As an organisation integrates AI systems into its critical processes, it becomes progressively dependent on those systems, their suppliers, their data and their updates. This dependency can reduce agility, decision sovereignty and the capacity to make free decisions .

This strategic note proposes a cadre to identify, measure and govern the dependency risks linked to AI, so that organisations keep their decisional freedom and their operational resilience.

What is technological dependency in AI?

Technological dependency takes several forms. It can be technical (the organisation cannot operate without the technology), commercial (the organisation becomes captive of a supplier's pricing model), or strategic (AI drives the business choices rather than supporting them).

Technical dependency

An organisation develops a technical dependency when its critical business processes rest entirely on an AI system it cannot forgo without major dysfunction. It can happen quickly if the AI integration has eliminated the manual or alternative processes.

Commercial dependency

Commercial dependency emerges when an organisation buys a proprietary AI service and the supplier raises prices, changes the terms of use, or introduces new restrictions. The organisation has no plan B and becomes hostage to the commercial relationship.

Strategic dependency

Strategic dependency is the most insidious. It happens when AI, instead of supporting human decisions , starts to dictate them. Business decisions are no longer made because they are strategically sound, but because it is what AI recommends or optimises.

What the report cites

The ten layers of dependency

Every artificial intelligence process in Europe rests on a technological stack whose every layer commits the sovereignty of the one above. The note identifies ten of them, listed from the hardware layer to the cognitive frames.

01

Hardware — chips, accelerators, memory, networks.

02

Compute infrastructure — data centres, energy, cooling.

03

Operating systems and low-level drivers.

04

Training frameworks and software libraries.

05

Foundation models.

06

Training data and corpora.

07

Fine-tuning, alignment and evaluation pipelines.

08

Application interfaces and APIs.

09

Regulatory and normative frameworks.

10

Cognitive frames — protocols, taxonomies, business languages.

Sovereignty is measured on the entire stack, not on a single layer.

Data cut-off: April 2026.

What the report cites

The scale gap

European compute infrastructure remains an order of magnitude below that of the US hyperscalers.

~3%

OVHcloud revenue relative to Amazon Web Services in Europe.

2024

Acquisition of Graphcore, the last independent British producer of AI-dedicated processors, by SoftBank.

The scale gap cannot be closed within a strategic-plan cycle. It is governed upstream, through the entry and exit conditions set before integration.

Data cut-off: April 2026.

The framework

The five dimensions of the framework

01

Layer-by-layer mapping of dependencies

Governance begins with an explicit reading of the ten layers on which critical processes rest. For each layer, the map identifies suppliers, jurisdiction, substitutability and the weight of the layer in the business outcome.

The executive committee qualifies the critical processes, the consequences, the responsibilities and the recovery times. The establishment of the underlying technical stack falls to the information systems and procurement departments.

02

Non-delegation thresholds

Decisions that commit the organisation over the long term, those that are irreversible or that touch on fundamental rights remain human. The non-delegation threshold is set before deployment and documented at board level.

03

Contractual conditions and reversibility

Contracts set portability, log access, artefact retention duration, ownership of fine-tuning, exit conditions and restitution timelines. Reversibility is not a principle: it is a clause, quantified and dated.

04

Switchover plans and European alternatives

Each critical function carries a switchover plan to a documented, tested and executable alternative. The map of European alternatives is reviewed at least once a year.

05

Geopolitical stress-tests

Dependency also reads as a scenario. Geopolitical stress-tests probe continuity in the event of jurisdictional rupture, export restriction, sanction or conflict affecting a critical actor in the stack. Test outcomes are reported to the board.

The key dependency indicators

How to measure whether an organisation is too dependent on its AI systems? Here are the key indicators.

  • Share of business decisions supported by AI. If more than 70% of critical decisions rest on AI, the risk of strategic dependency is high.
  • Time to switch back to manual process. If the organisation takes more than a day to operate without AI on a critical function, technical dependency is too high.
  • Number of critical suppliers. If a single AI or a single supplier supports a critical business function, commercial dependency is absolute.
  • Team understanding. If less than 50% of the business team can explain how the AI works, dependency is problematic.
  • Exit flexibility. If the organisation cannot change supplier without major re-engineering, commercial dependency is locked.

Action recommendations

To govern AI dependency effectively, organisations must act on several fronts:

  • Carry out a full audit of every existing AI dependency.
  • Rank the dependencies by criticality: which ones put the survival of the organisation at risk?
  • For each critical dependency, design a de-escalation plan: how to reduce the dependency?
  • Invest in internal skills to maintain an understanding of AI systems.
  • Put in place the governance needed for every new AI integration to be assessed through the lens of dependency.

Technological dependency is not a technical problem to be solved once and for all. It is a continuous strategic risk that requires an governance explicit and vigilant governance. Only organisations that govern this risk will keep a real decision sovereignty at the AI era.

Dependency now extends to the powers granted to the systems themselves. This shift is the subject of a separate publication.

Versions available

April 2026 edition — version cited by the report. Pagination and URL preserved. Receive the PDF ↓

September 2026 addendum — forthcoming.

Request the note

Request the note.

April 2026 edition, version cited by the report. Personal delivery following a short exchange, to set the reading context.

Write directly

To request the note, schedule a meeting or open a confidential exchange. Personally reviewed.

Discuss this publication ?

Fifteen to twenty minutes to discuss this subject applied to your organisation.

Get in touch