91% of Execs Don't Understand Their AI Dependencies
An IBM survey of 1,000 executives found 91% don't grasp their AI vendor risk, months after Fable 5 went dark for 18 days.
At 5:21 p.m. Eastern on June 12, a single letter reached Anthropic's offices. Within hours, the company's two most capable AI models had gone dark for every customer on the planet, no exceptions. Two months later, a new IBM study asked 1,000 senior executives across 16 countries a direct question: if that happened to your primary AI vendor, would you know what to do? The answer, published this week, is that the overwhelming majority genuinely do not.
What the Letter Actually Triggered
The U.S. Commerce Department invoked export-control authority against Anthropic's Claude Fable 5 and Mythos 5 models after a reported jailbreak, and the directive was unusually broad: it barred access by "any foreign national, whether inside or outside the United States." Anthropic could not verify user nationality in real time across Amazon Bedrock, Google Cloud, Microsoft Foundry, and its own API simultaneously, so the company shut both models down globally rather than risk partial noncompliance. Fable 5 stayed dark for 18 days before the government partially reversed course, with Mythos 5 restored to roughly 100 vetted institutions while Fable 5 remained restricted for even longer. Nothing technically broke during those 18 days. No server failed, no data leaked, no company went bankrupt. A policy decision made in a capital where most affected companies had no representation simply erased a production dependency overnight, and there was nothing any individual enterprise customer could do about it.
The Numbers IBM Put Behind the Fear
The IBM Institute for Business Value, working with Oxford Economics, surveyed 1,000 senior executives across 16 countries and 17 industries between February and April 2026, publishing the results as "The Calculus of AI Sovereignty." The findings are stark. Ninety-one percent of executives say they do not fully understand their organization's AI dependencies across vendors, models, and infrastructure, with only 9 percent rating their own understanding as excellent. Seventy-one percent say switching their primary AI vendor or model would be difficult today. Eighty-one percent say a seven-day outage at their primary AI vendor would be severe or critical, effectively halting operations. Fable 5 was down for eighteen.
That gap between the outage duration executives fear and the one that actually happened is the report's central, uncomfortable point. CEOs told IBM that AI already drives roughly 25 percent of their operational decisions as of early 2026, and they expect that figure to reach 48 percent by 2030. Nearly half of all operating decisions, within four years, routed through dependencies most executives admit they cannot fully map today.
Why "Multi-Vendor" Doesn't Mean What Boards Think It Means
One finding in the report should concern any board that has taken comfort in having "multiple AI vendors" as a resilience strategy. When IBM asked what actually drives vendor diversity inside these organizations, deliberate risk management ranked dead last. Organizational fragmentation ranked first, followed by geographic and regulatory constraints. In plain terms, most companies' multi-vendor AI setups did not happen because someone designed them for redundancy. They accumulated from an acquisition here, a country subsidiary there, a procurement workaround somewhere else, delivering all of the cost of running multiple vendors with almost none of the actual risk protection that redundancy is supposed to buy.
The switching math backs up why genuine redundancy is so rare in practice. Executives estimate an average of 145 days to move AI training and operational data to a different environment. Fifty-seven percent say replacing a core model would require significant decoupling or a full system rebuild, not a configuration change. Fifty-six percent say shifting core AI systems to another vendor would take at least six months. A tactical vendor switch, on these numbers, is not a weekend project. It is a fiscal-year initiative that most companies have never actually rehearsed.
The Real Cost Is Hiding in the Token Bill
IBM's report attaches an unusually concrete price tag to a decision most companies treat as a technical afterthought: where data physically sits relative to where the model executes. Organizations pay 2.8 times more in token processing costs when data sits far from the model doing the processing, which IBM calculates at roughly 50 million dollars a year in pure waste for a 20-billion-dollar enterprise, buying no additional capability whatsoever. Run the same logic forward, and organizations with genuinely strong practical control across data, models, and infrastructure protect 55 percent more of their operating profit from AI-driven disruption. Seventy-two percent of executives say they would willingly absorb a 20 percent cost increase just to keep multiple vendors genuinely live and switchable, rather than technically present but practically unusable.
That willingness to pay a real premium for genuine optionality is the clearest signal in the entire report. Executives are not naive about the risk. They simply have not been given, or have not built, the architecture that would let them act on that awareness before the next Commerce Department letter arrives.
IBM's Pitch, and the Skepticism It Deserves
IBM's own answer to the problem is a product it calls Sovereign Core, generally available since May, which deploys models and inference inside a customer-controlled boundary rather than a hosted API a foreign government can order shut off in an afternoon. The platform accepts IBM's own models, open-weight alternatives, or a customer's proprietary model, built on Red Hat OpenShift, with a partner catalog spanning Mistral, AMD, Dell, and others. IBM has committed to open-sourcing the platform's core components, a move explicitly designed to blunt the obvious objection that a company selling sovereignty solutions has an financial incentive to inflate the fear driving demand for them.
That incentive is real and worth naming directly. IBM commissioned this research, and IBM sells the product positioned as its solution. The specific numbers, the 91 percent, the 145-day migration estimate, the 2.8-times cost multiplier, came from IBM's own survey methodology and deserve the same scrutiny anyone would apply to a vendor-funded study. What is harder to dismiss is the underlying event the numbers are describing. The Fable 5 shutdown happened, independently of anything IBM says about it, and 18 days of a frontier model going fully dark by government order is a matter of public record, not marketing.
Why This Outlasts One Company's Bad Month
The broader consequence of that 18-day shutdown was that competitors, particularly Chinese labs, used the gap to close ground that has not fully reopened since, which is precisely the kind of downstream cost IBM's survey is trying to get enterprise customers to price into their own planning before it happens to them directly. The precedent set in June was never really about Fable 5's specific capabilities. It was proof that a hosted frontier model, however capable, can be switched off entirely by a decision an enterprise customer has zero visibility into and zero vote over.
That fragility sits uneasily alongside Anthropic's own current trajectory, with investors now targeting a $2 trillion valuation for an October public listing built substantially on enterprise customers trusting the durability of exactly this kind of dependency. A company can be simultaneously the best-performing frontier AI lab on the market and a single point of regulatory failure for every enterprise that has not built a genuine exit path. IBM's report does not resolve that tension. It simply puts numbers on how few companies have actually confronted it, and how expensive that avoidance is quietly becoming.
Written by
Mr. Aayush Bhatt
Software Engineer interested in how models work and where they fail.