The question boards started asking in 2026
For three years the board question about artificial intelligence was some version of “are we using it yet”. That question has been answered in almost every large company, and it has been replaced by a harder one.
If our primary model provider raised prices 40 percent tomorrow, how long would it take us to move?
Most companies cannot answer. Not approximately, not in the wrong unit, not at all. The people who would know have never been asked to find out, and the answer is not written down anywhere. That is a strange position for a board to sit in, given that AI now touches revenue-generating products in most of these organisations.
The question is not hypothetical posturing. It is the same question boards learned to ask about cloud infrastructure, about payment processors, and about single-source suppliers. The discipline is old. Only the category is new.
It is also worth noticing how modest the question is. It does not ask whether the current provider is the right one, and it does not imply that anything is wrong. A board can be entirely satisfied with a supplier and still expect management to know the cost of replacing it. That expectation is routine in every other category of spend. In AI it is treated as an unusual request, which tells you something about how quickly this line item grew and how little of the ordinary governance apparatus grew with it.
We have seen this movie before
The cloud version of this story ran for roughly a decade.
Companies moved workloads to a single provider because it was faster than building anything themselves. The savings were real. Then the dependency matured, egress fees and committed spend agreements arrived, and buyers discovered they had traded capital expenditure for a negotiating position they no longer controlled. What handed leverage back was not a change of provider. It was an abstraction: containers, orchestration layers, and infrastructure defined in code, all of which made the underlying provider a decision rather than a foundation.
AI is running the same curve. The difference is the clock speed. What took the cloud market about ten years is taking the model market somewhere closer to eighteen months.
The pace is the part executives underestimate. Head-to-head comparisons of the current flagship models are rewritten every quarter, which means a procurement decision resting on last year’s evidence is not conservative. It is simply out of date.
That compression matters for governance. In a ten-year cycle, an annual vendor review is adequate oversight. In an eighteen-month cycle, an annual review means the board is looking at the market roughly two generations after the fact. The oversight cadence has to move with the market, or it stops being oversight.
There is one important difference from the cloud story, and it favours the buyer. Moving a database between clouds is a migration. Moving a workload between models is, in principle, a configuration change. The switching cost is genuinely lower this time. Companies simply have not built themselves the option.
What model independence looks like in practice
Independence here does not mean using every provider, and it does not mean avoiding the good ones. It means the ability to change your mind at a reasonable cost. Three preconditions have to be held.
A vendor-neutral integration layer.
The first condition is the least glamorous and the most load-bearing: an integration layer that exposes a unified API for hundreds of AI models, so that replacing one provider with another becomes a routing decision rather than a re-architecture. Without it, every model choice hardens into an application dependency, and the cost of reversing it grows quietly for as long as nobody tests it.
Portable prompts and evaluation assets.
Your prompts, your test cases, and your quality criteria are company assets, and they should live somewhere your company controls. Many organisations have allowed these to accumulate inside a single vendor’s tooling. When that happens, the technical ability to switch exists but the institutional ability does not, because nobody can prove the replacement performs as well.
A continuous cost and quality baseline.
If you cannot say what your current provider delivers at what price on your own work, you cannot evaluate an alternative, and you cannot tell whether a price rise is worth accepting. Companies with a live baseline treat a 40 percent increase as an arithmetic problem. Companies without one treat it as a crisis.
Notice what none of these require. None of them ask the company to leave its current provider, and none of them are cheap-vendor arguments. A company can hold all three preconditions and still choose to send the majority of its work to the most expensive model available. The difference is that it is choosing, and it can prove the choice.
The governance dividend
The reason this reaches board agendas is not really resilience. It is that the side effects happen to be the things boards already care about.
Centralised audit logs. One place that records which model saw which data, when, and on whose authority. That record is the foundation of every AI governance framework now being written, and most companies currently assemble it by hand from several vendor dashboards, if they assemble it at all.
Controllable data residency. When routing sits in one layer, “this category of data never leaves this region” becomes a policy you can enforce and evidence, rather than an assurance you hope holds.
Spend attributed by the business unit. This is the one finance teams ask for first.
Attribution also makes the pricing conversation concrete. Once a finance team can see what the major providers charge per million tokens beside what each business unit actually consumed, the question shifts from “is AI expensive” to “which workload is on the wrong model”. Those are very different conversations. The first one produces a budget freeze. The second one produces a decision. Providers now publish their rates openly, and Anthropic is among those doing so, which means the comparison is available to any finance team willing to sit down and make it.
One compliance review instead of one per vendor. For regulated organisations, this is often the largest single saving, and it is measured in weeks of legal and risk time rather than in licence fees.
None of this is a technology argument. It is the ordinary machinery of corporate control applied to a category that grew too quickly for it.
Three questions to put to your CTO this quarter
You do not need to understand model architectures to exercise oversight here. You need three answers, and you should expect them in writing.
How many days would it take us to move our primary AI workload to a different provider, and when did we last test that?
An answer in days with a test date attached is a healthy answer. An answer in months means the dependency is real. “We have never tried” is the answer that should concern you most, because it means the number is unknown rather than large.
Can our evaluation set run against any provider, and who owns it?
If the answer names a vendor’s platform, the company has outsourced its own quality standard. That is recoverable, but it needs to be a named piece of work rather than an assumption.
Can you show me last quarter’s AI spend broken out by business line?
This one is deliberately blunt, because it is the fastest diagnostic available. A company that can produce that breakdown almost certainly has the layer, the baseline, and the governance in place, because it is very difficult to produce the report without them. A company that cannot has just told you where to start.
The board’s job here is not to choose a model. It is to make sure the company retains the ability to choose again.






