The trust collapse is structural, not incidental.
Signal, June 2026: The US government asked OpenAI to restrict access to GPT-5.6, with agencies vetting who can use the model. For any organisation that built procurement plans around unrestricted frontier model access, this is the risk that just became structural. Read the full signal →
AI vendor risk is not a theoretical concern. It is the category of operational exposure that organisations discover at the worst possible moment: when a renewal is due, a compliance review is underway, or a model they built around silently changes behaviour without notice.
Most AI procurement today optimises for capability and time-to-value. The questions that do not get asked are the ones that matter most when something changes: Who owns the data sent to this model? What happens if access is restricted? What is the actual SLA coverage when the output is wrong — not just when the API is down? What is the exit path if this vendor restructures, raises prices, or exits the market?
Vendor lock-in in AI is not about being unable to switch tools. It is about not knowing how much of your operating model you have handed to a vendor whose terms you accepted without fully reading.
The Sovereign AI Risk Audit exists to answer those questions before they become urgent. It is a structured, productised engagement that maps your vendor exposure across five dimensions and produces a risk register and remediation plan you own — regardless of what you decide to do next.
Five dimensions. One consolidated risk picture.
Each dimension maps a category of exposure that standard AI procurement processes typically leave unresolved. The audit covers all five and produces a ranked finding for each one.
Critical
Dimension 1 — Model Access
Access dependency and restriction risk
What happens if your primary model vendor restricts access based on jurisdiction, policy change, or commercial restructuring? This dimension maps your current access dependencies, identifies single points of failure, and documents what workflows stop functioning under restriction scenarios.
- Primary model dependency and concentration
- Jurisdictional and regulatory access exposure
- Government or enterprise restriction scenarios
- Viable fallback model and provider options
Critical
Dimension 2 — SLA Coverage
What your SLA actually covers — and what it does not
Most AI vendor SLAs guarantee uptime but not accuracy, output quality, or model consistency. This dimension audits your current contracts against nine known SLA gap patterns: uptime-only coverage, hallucination liability transfers, model-version instability, and missing output quality commitments. Read the SLA red-flags guide →
- Uptime vs accuracy SLA gap analysis
- Hallucination liability clause review
- Version-change notice and pinning rights
- Accuracy regression and remediation terms
High
Dimension 3 — Model Versioning
Version stability and the right to pin
Model version changes are not software updates. A vendor pushing a new model to your production integration without notice can materially change output behaviour, break downstream logic, and invalidate evaluation baselines — without breaching any contract clause. This dimension maps your current version-pinning rights and notice period exposure.
- Current model-version pinning rights
- Notice period for forced model upgrades
- Regression window entitlements
- Exit rights on material output degradation
High
Dimension 4 — Data Sovereignty
What your data does inside the vendor’s infrastructure
Every prompt, completion, and fine-tuning dataset sent to an AI vendor is subject to their data retention, training, and residency policies — which change. This dimension audits your current data exposure: what leaves your perimeter, where it is stored, whether it trains future models, and whether your current jurisdiction accepts that arrangement.
- Data residency and storage jurisdiction
- Training data opt-out status and evidence
- Regulatory exposure (Privacy Act, GDPR adjacency)
- PII and confidential data flow mapping
Moderate
Dimension 5 — Exit Path
Transition readiness and migration cost
Exit path readiness is the dimension most organisations have never mapped, because switching vendor feels theoretical until it is not. This dimension documents your portability: which workflows are model-agnostic, which are tightly coupled, what migration would realistically cost, and what you would lose in capability vs what you would gain in sovereignty.
- Workflow portability assessment
- Tight-coupling and exit-cost estimation
- Alternative vendor capability comparison
- Migration priority and sequencing plan
Consolidated output
One risk register. Five ranked findings.
Every dimension produces a finding with a risk tier, an estimated exposure, and a remediation option. The consolidated risk register ranks your five findings and gives you a prioritised action list with decision criteria for each: fix now, renegotiate at renewal, or accept and document.
- Ranked risk register across all five dimensions
- Remediation options with effort and impact estimates
- Contract renegotiation briefing notes where relevant
- Sovereign-AI posture summary for executive reporting
How the engagement works
A typical engagement runs two to three weeks from scoping call to risk register handoff. The scope is your current AI vendor stack — not a speculative exercise about future vendors.
Scoping call — ~30 min
Map your current vendor stack, the workflows that depend on it, the contracts that govern it, and where your instincts already tell you something is exposed. Thirty minutes establishes whether this engagement fits and what the highest-priority dimensions are for your situation.
You leave with: a clear framing of your top three exposure areas and a decision on whether to proceed.
Document and contract review — 3–5 days
Review your current AI vendor contracts, SLAs, data processing agreements, and usage policies against each of the five audit dimensions. Map what is documented, what is missing, and what the contracts do not cover that you assumed they did.
You leave with: a completed gap map across all five dimensions with preliminary findings.
Workflow and dependency mapping — 3–5 days
Trace the workflows that depend on each vendor, how tightly coupled they are, what breaks under each restriction scenario, and what the realistic migration cost would be. The goal is a clear-eyed picture of exposure, not a theoretical risk matrix.
You leave with: workflow dependency map and scenario analysis for the three highest-risk dimensions.
Risk register and handoff — 1 session
Consolidated risk register across all five dimensions with ranked findings, remediation options, and a sovereign-AI posture summary you can present to a board, compliance function, or executive team. Walk through the findings together and confirm you can act on them without RFE Online in the room.
You leave with: a risk register, remediation briefing, and contract negotiation notes you own going forward.
What you receive
Three artefacts, delivered by email at engagement close.
Deliverable 1
Sovereign AI Risk Register
A ranked PDF covering all five audit dimensions. Each finding states the risk tier, the evidence from your actual contracts and workflows, and a remediation option with effort and impact estimates. Prioritised so the first item is the exposure you cannot afford to carry into your next renewal.
Deliverable 2
Contract & SLA Gap Report
Specific clauses to add, renegotiate, or flag for legal review — drawn from your current contracts against nine known SLA gap patterns. Includes briefing notes your legal or procurement team can use at renewal without needing to re-read the full audit.
Deliverable 3
Sovereign AI Posture Summary
A one-page executive summary of your current vendor posture, the highest-priority gap, and the recommended remediation path. Board-ready and compliance-ready — structured for a risk committee, a board update, or a government contract submission requiring demonstrated AI risk governance.
Who this audit is built for
The buyer for this engagement has already committed to AI in production. They are not evaluating whether to use AI. They are looking at their current stack and asking: what risk have we taken on that we have not fully mapped?
Operators with production AI workflows
Teams that have AI models running in live operations — summarising, routing, generating, or deciding — and have not yet mapped what changes if a vendor restricts access or changes the model they built around.
Leaders facing contract renewals
Decision-makers approaching an AI vendor renewal with no clear view of what their current SLA actually covers, what data exposure they have accepted, or what their negotiating position is if the vendor raises prices or changes terms.
Compliance and risk functions
Risk, legal, or compliance teams who need a clear sovereign-AI posture document for a board presentation, regulatory review, or enterprise security assessment — and who do not have the technical framework to produce one internally.
This audit is not generic AI strategy. It is a structured assessment of your current stack, your current contracts, and your current exposure — producing findings you can act on before something changes.
Packages & indicative pricing
Every engagement starts with a scoping call to confirm the vendor stack, the contracts we will review, and the dimensions that matter most for your situation. The price ranges below are directional anchors.
Focused
Single Vendor Audit
From $1,800 AUD
One vendor relationship · three dimensions · scoping through risk report
- 30-min scoping call
- Contract and SLA gap analysis (one vendor)
- Three audit dimensions of your choice
- Preliminary risk finding and remediation note
- 30-min handoff session
Most common
Full Stack
Sovereign AI Risk Audit
From $4,500 AUD
Full vendor stack · all five dimensions · risk register and remediation plan
- Everything in Focused
- All five audit dimensions across all primary vendors
- Consolidated risk register with ranked findings
- Contract renegotiation briefing notes
- Sovereign-AI posture summary for executive reporting
- Remediation options with effort and impact estimates
Enterprise
Multi-Vendor Fleet Audit
From $9,500 AUD
5+ vendor relationships · enterprise stack · board-ready risk posture
- Everything in Full Stack, across your vendor fleet
- Cross-vendor concentration risk analysis
- Procurement policy gap documentation
- Board or executive presentation deliverable
- Regulatory and compliance framing (Privacy Act, GDPR adjacency)
- Six-month vendor posture review option
Final scope and price are confirmed on the scoping call. If your stack is smaller, simpler, or more complex than these anchors suggest, say so in the inquiry form and we will scope accordingly. No obligation until we both agree it fits.
Start the conversation
Leave your email and a few words about your AI stack or the concern that brought you here. A confirmation email with a Calendly link lands in your inbox the same second — or book directly from the screen that appears after you hit send. No pitch deck, no obligation.
Thanks — next step: book the call
We have your details. Click below to pick a 30-minute slot on Calendly — no pitch, just a direct scoping conversation about your vendor stack.
Book scoping call on Calendly →
A confirmation email with this link is also on its way to your inbox — use it to book when you are ready if you would rather step away first.
Related reading from the Sovereign AI pillar
The risk picture these articles document is the same risk this audit is designed to map.
Regulatory Risk — The Case
When the US government can gate access to the frontier AI model your workflows depend on, sovereign AI stops being a policy preference. The regulatory argument — jurisdiction risk, Privacy Act exposure, Five Eyes alignment — made concrete by the GPT-5.6 restriction.
Read the case →
Procurement Risk — Signal
The US government restricted GPT-5.6 access. For any organisation that assumed frontier model access was a commodity they could buy on demand, this is the structural risk that just became real.
Read the signal →
Contract Risk — Checklist
Nine contract clauses that signal an AI vendor is offloading operational risk onto you. A procurement checklist for decision-makers reading an AI vendor SLA before they sign.
Read the checklist →
Stack Risk — Analysis
When AI agents replace application interfaces, the vendor lock-in question moves from the app layer to the model layer. What the Notion/Skiff shutdown signals for AI procurement strategy.
Read the analysis →
Regulatory Risk — Hardened Systems
The GPT-5.6 restriction made hosting location urgent. But data classification controls, audit instrumentation, substitution architecture, and vendor risk documentation are hardening requirements that geography alone cannot satisfy. What the Australian regulatory stack actually demands of your system design.
Read the hardening brief →
Good fit
This engagement is built for operators, risk leads, and decision-makers who have already committed to AI in production and want a clear, structured view of their vendor exposure — before a contract renewal, a compliance review, or an access restriction forces the question.
It is not a vendor comparison, a build-vs-buy analysis, or a strategic roadmap. The job is to map the risk that already exists in your current stack and give you a risk register and remediation plan you can act on.
Thirty minutes to map your sovereign AI exposure.
A scoping call is where we look at your current AI vendor stack, the contracts that govern it, and the workflows that depend on it — and identify where the highest-risk exposure actually is. No proposal, no pitch until we both agree the engagement fits your situation.