Concentration risk used to be easy to picture: one supplier, one system, or one floppy disk seller. In the era of AI, the single point of failure has learned to hide.

Different AI providers can quietly converge on the same testing firm, infrastructure, data source, or control, (i.e., a shared assurance mechanism). The danger is not just that something will fail. It is discovering during an incident that the “independent” alternatives in your resilience plan were never independent at all.

Four Companies, One Point Of Failure

Independent testing is intended to provide assurance. But when multiple AI providers rely on the same testing company, that assurance itself can become a point of concentration risk. And that’s what happened during cyber evaluations run by Irregular (a vendor that stress-tests AI models in simulated cybersecurity environments). Agents from OpenAI, Anthropic, Meta, and Google targeted real-world systems instead of remaining within the simulated environment. According to Irregular, one test scenario unintentionally permitted internet access while a fictional target overlapped with a real domain. Agents intended to attack the simulation targeted real systems instead.

The concentration risk was not in the models themselves, but in the shared assurance mechanism. But the lesson extends beyond one testing firm. A shared evaluator, testing method, or control can create correlated exposure across otherwise unrelated providers. One commonality is all it takes.

Provider Diversity Is Not Resilience

The Irregular case exposes control concentration. The September 3 outages affecting Claude, Grok, and ChatGPT  highlight a different problem: hidden dependencies. None of the AI providers confirmed a shared cause for the outage. Yet xAI pointed to its Memphis compute center, while Anthropic leases capacity in the same facility.

The point isn’t that the outages were connected, it’s that customers had little visibility into where supposedly independent AI providers might converge.  And that’s the AI concentration problem in a nutshell: diversity at the surface, a single source underneath. If customers can’t see where providers converge, they don’t know the extent of their exposure.

The Real Risk Is Below The Vendor

Three AI providers are not three independent alternatives when they rely on the same infrastructure, data source, provider, control, or critical component.  That’s why concentration risk, third-party risk management (TPRM), and continuous risk management converge: resilience comes from understanding overlaps, not counting suppliers. Risk leaders must look beyond the provider and understand the ecosystem that supports it.

Agentic AI raises the stakes. When an agent can make decisions, generate code, invoke tools, and interact with other systems, failures can spread before a human understands what happened. Hidden concentration risk does not just expand the blast radius. It compresses the time available to contain it.

Concentration Risk Throws A Wrench In Resilience: What To Do Now

Inventorying vendors and use cases is no longer enough. Risk leaders must uncover the hidden dependencies that turn seemingly diverse AI providers into the same bet.

Concentration risk has always been about correlated exposure. AI simply gives it more places to hide. Most companies already have backup AI providers. To identify whether those backups fail for the same reason, start here:

  • Map dependency paths, not providers. Trace the infrastructure, data, controls, and critical third parties behind your most important AI use cases. Your contract may stop at the provider, but your dependency chain doesn’t.
  • Demand visibility into critical dependencies. Ensure AI providers and SaaS vendors with AI capabilities disclose material dependencies, critical fourth parties, and the relationships that could create exposure to commonalities. TPRM depends on understanding who and what supports the services your company relies on.
  • Match level of scrutiny to criticality. The more autonomy an AI system has and the more critical the outcome it supports, the less tolerance risk leaders should have for opaque, shared, or untested dependencies. Use context and control to determine how much risk is acceptable.

Five AI vendors will not save you if they all brought the same parachute. If you are a Forrester client, schedule a guidance session to get insights and guidance concentration risk within your third-party AI risk management program.

Share