Cited in institutional work

This note is cited on page 76 of the report of the French Senate's parliamentary mission on the alignment of artificial intelligence systems, delivered to the French minister for digital affairs in July 2026. Read the contribution and the cited passages in French →

Board synthesis

Decide in sixty seconds

AI installs a dependency that grows quietly. The leader keeps the hand on it through thresholds set before the integration.

Understand

The three forms of dependency

Technical

The system becomes indispensable to the running of a critical process.

Commercial

A single supplier sets the prices and the conditions.

Strategic

The tool takes the hand on the business decision.

Governing

The three levers

Diversification

Two sources per critical function, migration capacity maintained.

Transparency

Explainable systems, teams that understand the tool.

Resilience

A degraded mode retained and tested.

Decide

The board's three acts

Map

List dependencies, rank them by criticality.

Set the thresholds

Non-delegation and reversibility, arbitrated upstream.

Test

Rehearse the degraded mode and the supplier exit.

Five alert thresholds

Alert thresholds proposed by VEIA, to be calibrated by each organisation. The indicators that must reach the committee

  • 70 %Critical decisions supported by AI
  • 1 dayReturn to manual mode
  • 1 onlySuppliers on a critical function
  • 50 %Teams able to explain the system
  • AlertSupplier exit requiring major re-engineering

Technological dependency is a permanent strategic risk. The board sets two markers, on the same footing as financial or legal risk: the decisions that stay human in all circumstances, and the exit capacity maintained on every critical dependency. Decision sovereignty is built there, in the thresholds the leader sets and holds.

How can organisations govern the risks of technological dependency and decisional concentration linked to AI?

One of the least visible and most important risks of AI integration is the creation of technological dependency . As an organisation integrates AI systems into its critical processes, it becomes progressively dependent on those systems, their suppliers, their data and their updates. This dependency can reduce agility, decision sovereignty and the capacity to make free decisions .

This strategic note proposes a cadre to identify, measure and govern the dependency risks linked to AI, so that organisations keep their decisional freedom and their operational resilience.

What is technological dependency in AI?

Technological dependency takes several forms. It can be technical (the organisation cannot operate without the technology), commercial (the organisation becomes captive of a supplier's pricing model), or strategic (AI drives the business choices rather than supporting them).

Technical dependency

An organisation develops a technical dependency when its critical business processes rest entirely on an AI system it cannot forgo without major dysfunction. It can happen quickly if the AI integration has eliminated the manual or alternative processes.

Commercial dependency

Commercial dependency emerges when an organisation buys a proprietary AI service and the supplier raises prices, changes the terms of use, or introduces new restrictions. The organisation has no plan B and becomes hostage to the commercial relationship.

Strategic dependency

Strategic dependency is the most insidious. It happens when AI, instead of supporting human decisions , starts to dictate them. Business decisions are no longer made because they are strategically sound, but because it is what AI recommends or optimises.

The three dimensions of dependency governance

Dimension 1: Diversification and portability

The first defence against dependency is diversification. An organisation must not concentrate too many critical functions on a single AI system or supplier. Moreover, it must retain the capacity to migrate to other solutions or suppliers.

  • Identify critical functions and ensure coverage by at least two possible sources.
  • Retain the code, the data and the intellectual property needed to switch supplier.
  • Regularly test portability: can we really migrate to another solution?
  • Explicitly document the dependencies on external suppliers.

Dimension 2: Transparency and understanding

An organisation cannot govern effectively govern a dependency unless it understands it. This requires complete transparency on how AI systems work, their limits, their risks and their decisional impacts.

  • Require that every AI system be auditable and explainable, not a black box.
  • Conduct regular audits to verify that AI does what we think it does.
  • Train teams to understand AI systems, not to worship them.
  • Put in place alerts to detect when AI starts to determine business decisions rather than support them.

Dimension 3: Resilience and fallback plans

A resilient organisation must be able to operate without its AI systems. This requires keeping manual or alternative processes, even if they are less efficient, and regularly testing the capacity to operate in degraded mode.

  • Retain the alternative manual processes for every critical function.
  • Regularly test the shift to degraded mode: can the organisation continue without AI?
  • Explicitly document the switch-over thresholds: at what point of dysfunction do we stop the AI?
  • Plan business continuity exercises that include the loss of AI systems.

The key dependency indicators

How to measure whether an organisation is too dependent on its AI systems? Here are the key indicators.

  • Share of business decisions supported by AI. If more than 70% of critical decisions rest on AI, the risk of strategic dependency is high.
  • Time to switch back to manual process. If the organisation takes more than a day to operate without AI on a critical function, technical dependency is too high.
  • Number of critical suppliers. If a single AI or a single supplier supports a critical business function, commercial dependency is absolute.
  • Team understanding. If less than 50% of the business team can explain how the AI works, dependency is problematic.
  • Exit flexibility. If the organisation cannot change supplier without major re-engineering, commercial dependency is locked.

Action recommendations

To govern AI dependency effectively, organisations must act on several fronts:

  • Carry out a full audit of every existing AI dependency.
  • Rank the dependencies by criticality: which ones put the survival of the organisation at risk?
  • For each critical dependency, design a de-escalation plan: how to reduce the dependency?
  • Invest in internal skills to maintain an understanding of AI systems.
  • Put in place the governance needed for every new AI integration to be assessed through the lens of dependency.

Technological dependency is not a technical problem to be solved once and for all. It is a continuous strategic risk that requires an governance explicit and vigilant governance. Only organisations that govern this risk will keep a real decision sovereignty at the AI era.

Download

Receive the note.

A doctrine to frame digital dependency before commitments. PDF delivered immediately.

No commercial use. Unsubscribe at any time. GDPR-compliant. The note is available in French.

Discuss this publication ?

Fifteen to twenty minutes to discuss this subject applied to your organisation.

Get in touch