Vulnerabilities Bearish 7

91% of Execs Lack AI Dependency Visibility, Creating Massive Cyber Risk: IBM Study

An IBM study reveals that 91% of enterprises don't understand their AI vendor dependencies, while 81% would face severe disruption from a week-long outage. For cybersecurity leaders, this lack of visibility introduces supply chain vulnerabilities, compliance gaps, and business continuity threats that urgently need remediation.

· 4 min read · Verified by 2 sources ·
Share

Key Takeaways

  • An IBM study reveals that 91% of enterprises don't understand their AI vendor dependencies, while 81% would face severe disruption from a week-long outage.
  • For cybersecurity leaders, this lack of visibility introduces supply chain vulnerabilities, compliance gaps, and business continuity threats that urgently need remediation.

Mentioned

IBM company AI technology Ana Paula Assis person Oxford Economics company

Key Intelligence

Key Facts

  1. 171% of surveyed senior executives say switching their primary AI vendor or model would be difficult, signaling deep vendor lock-in.
  2. 291% of respondents do not fully understand their organization’s dependencies across AI vendors, models, and infrastructure.
  3. 368% of executives find it challenging to meet data residency and sovereignty requirements across geographies.
  4. 4Organizations reported an average of six AI-related disruptions over the past two years, driven mainly by vendor issues.
  5. 581% say a seven-day outage of their primary AI vendor would cause severe or critical disruption, effectively halting operations.
Executives lacking full AI dependency visibility
91%

Limits ability to assess cyber risk and plan for disruption

AI has introduced new forms of dependency that evolve faster than traditional governance, procurement, or technology cycles were designed to handle. The stakes are no longer technical; they are economic. Any loss of control can translate directly into margin pressure, compliance exposure, or outright business disruption.

Ana Paula Assis Senior Vice President and Chair, EMEA and APAC, IBM

Foreword to The Calculus of AI Sovereignty study

Analysis

When you can't see your critical supply chain, you can't secure it. That is the hard lesson from IBM’s latest research on AI sovereignty, which finds that almost all enterprises (91%) lack full visibility into their AI dependencies—a blind spot that cybersecurity leaders can no longer ignore. As AI models and platforms become deeply embedded in operations, these opaque dependencies expose organizations to vendor-driven disruptions, unmonitored data flows, and new attack surfaces that legacy third-party risk frameworks were never designed to handle. The study quantifies just how exposed enterprises really are and why the CISO must now own AI dependency risk as a top-tier security concern.

A new global study from the IBM Institute for Business Value, based on a survey of 1,000 senior executives across 16 countries and 17 industries, paints a stark picture of enterprise AI dependencies: 71% of respondents say switching their primary AI vendor or model would be difficult, and 68% struggle to meet data residency and sovereignty requirements across geographies. The research, titled The Calculus of AI Sovereignty, reveals that while AI is becoming more deeply embedded in core business operations, most organizations have ceded control over critical systems in ways that create significant operational, financial, and compliance risks. The findings highlight a growing governance gap that, if left unaddressed, could expose enterprises to costly disruptions and limit their ability to adapt as the AI landscape evolves.

That is the hard lesson from IBM’s latest research on AI sovereignty, which finds that almost all enterprises (91%) lack full visibility into their AI dependencies—a blind spot that cybersecurity leaders can no longer ignore.

Why this matters now is simple: AI adoption is no longer limited to experimental projects. Enterprises are using AI to power customer-facing applications, supply chain optimization, and internal decision-making. The dependencies that come with this adoption—on specific large language models, cloud infrastructure, and third-party services—are multiplying faster than most organizations can track. The IBM study quantifies the blind spot: 91% of surveyed executives admit they do not fully understand their organization's dependencies across AI vendors, models, and infrastructure. This lack of visibility, combined with the difficulty of switching vendors, creates a potent combination of vendor lock-in and unmanaged risk.

The operational impact is already measurable. Respondents reported an average of six AI-related disruptions over the past two years, primarily triggered by vendor-side issues such as price increases, usage restrictions, model deprecations, and performance degradation. More alarmingly, 81% said that a seven-day outage of their primary AI vendor would cause severe or critical disruption, effectively halting operations. In other words, AI has become a single point of failure for many enterprises, but without the contingency planning that typically accompanies mission-critical systems.

This dependency dynamic intersects with the growing regulatory pressure around data sovereignty. As countries enact stricter data localization laws, organizations must ensure AI workloads comply with residency requirements. The study’s finding that 68% see this as a major challenge underscores how governance complexity is compounding vendor lock-in. Enterprises not only depend on a few AI providers but also face legal hurdles when trying to move data or models out of certain jurisdictions, making the technical difficulty of switching even more pronounced.

The concept of AI sovereignty, championed by IBM in the study foreword by Senior Vice President Ana Paula Assis, frames the issue as an economic and strategic imperative, not just a technical one. Assis argues that loss of control can translate directly into margin pressure, compliance exposure, and outright business disruption. The study’s segmentation of organizations into different AI control profiles suggests that companies proactively designing sovereignty into their AI architecture—through multi-vendor strategies, open standards, and transparent monitoring—are better positioned to manage costs, maintain resilience, and accelerate innovation.

What to Watch

For the broader market, these findings are likely to accelerate demand for open, interoperable AI solutions and for services that provide visibility into the AI supply chain. Cloud and AI providers that can offer portability, on-prem or local cloud deployment options, and rigorous compliance tools stand to gain. Conversely, enterprises that fail to address these dependencies risk not only operational disruptions but also the gradual erosion of negotiating leverage with vendors, which can lead to rising costs and deteriorating service levels. The study acts as a catalyst for board-level discussions about AI governance, elevating sovereignty from a niche technical concern to a core element of business strategy.

Looking ahead, the path to AI resilience will require enterprises to map their entire AI supply chain, stress-test vendor relationships, and invest in interoperability. The study’s data sets a benchmark: today, only a small fraction of organizations have comprehensive visibility and control. As AI continues to permeate every sector, the ability to switch vendors without disruption, maintain compliance across borders, and ensure operational continuity will separate leaders from laggards. The IBM research makes clear that the era of unmanaged AI dependency is a direct threat to enterprise performance.

Sources

Sources

Based on 2 source articles

Cite This Page

"91% of Execs Lack AI Dependency Visibility, Creating Massive Cyber Risk: IBM Study." Cyber Intelligence Brief, July 25, 2026. https://getcyberbrief.com/story/ibm-study-ai-dependencies-cyber-risk

How we covered this story

Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.