NEWAI Brain Fry Fix — The 3-Layer Stack Method$19 AUD →

Sovereign AI Audit — Vendor Lock-in Risk Assessment

Your AI stack runs on someone else’s terms. What’s your exit path?

When a frontier model vendor restricts access, silently changes the model, or restructures a contract you built workflows around, the risk lands on you — not them. This audit maps the procurement, data, and exit risks buried in your current AI vendor stack before they become urgent.

The trust collapse is structural, not incidental.

Signal, June 2026: The US government asked OpenAI to restrict access to GPT-5.6, with agencies vetting who can use the model. For any organisation that built procurement plans around unrestricted frontier model access, this is the risk that just became structural. Read the full signal →

AI vendor risk is not a theoretical concern. It is the category of operational exposure that organisations discover at the worst possible moment: when a renewal is due, a compliance review is underway, or a model they built around silently changes behaviour without notice.

Most AI procurement today optimises for capability and time-to-value. The questions that do not get asked are the ones that matter most when something changes: Who owns the data sent to this model? What happens if access is restricted? What is the actual SLA coverage when the output is wrong — not just when the API is down? What is the exit path if this vendor restructures, raises prices, or exits the market?

Vendor lock-in in AI is not about being unable to switch tools. It is about not knowing how much of your operating model you have handed to a vendor whose terms you accepted without fully reading.

The Sovereign AI Risk Audit exists to answer those questions before they become urgent. It is a structured, productised engagement that maps your vendor exposure across five dimensions and produces a risk register and remediation plan you own — regardless of what you decide to do next.

Five dimensions. One consolidated risk picture.

Each dimension maps a category of exposure that standard AI procurement processes typically leave unresolved. The audit covers all five and produces a ranked finding for each one.

Critical

Dimension 1 — Model Access

Access dependency and restriction risk

What happens if your primary model vendor restricts access based on jurisdiction, policy change, or commercial restructuring? This dimension maps your current access dependencies, identifies single points of failure, and documents what workflows stop functioning under restriction scenarios.

  • Primary model dependency and concentration
  • Jurisdictional and regulatory access exposure
  • Government or enterprise restriction scenarios
  • Viable fallback model and provider options
Critical

Dimension 2 — SLA Coverage

What your SLA actually covers — and what it does not

Most AI vendor SLAs guarantee uptime but not accuracy, output quality, or model consistency. This dimension audits your current contracts against nine known SLA gap patterns: uptime-only coverage, hallucination liability transfers, model-version instability, and missing output quality commitments. Read the SLA red-flags guide →

  • Uptime vs accuracy SLA gap analysis
  • Hallucination liability clause review
  • Version-change notice and pinning rights
  • Accuracy regression and remediation terms
High

Dimension 3 — Model Versioning

Version stability and the right to pin

Model version changes are not software updates. A vendor pushing a new model to your production integration without notice can materially change output behaviour, break downstream logic, and invalidate evaluation baselines — without breaching any contract clause. This dimension maps your current version-pinning rights and notice period exposure.

  • Current model-version pinning rights
  • Notice period for forced model upgrades
  • Regression window entitlements
  • Exit rights on material output degradation
High

Dimension 4 — Data Sovereignty

What your data does inside the vendor’s infrastructure

Every prompt, completion, and fine-tuning dataset sent to an AI vendor is subject to their data retention, training, and residency policies — which change. This dimension audits your current data exposure: what leaves your perimeter, where it is stored, whether it trains future models, and whether your current jurisdiction accepts that arrangement.

  • Data residency and storage jurisdiction
  • Training data opt-out status and evidence
  • Regulatory exposure (Privacy Act, GDPR adjacency)
  • PII and confidential data flow mapping
Moderate

Dimension 5 — Exit Path

Transition readiness and migration cost

Exit path readiness is the dimension most organisations have never mapped, because switching vendor feels theoretical until it is not. This dimension documents your portability: which workflows are model-agnostic, which are tightly coupled, what migration would realistically cost, and what you would lose in capability vs what you would gain in sovereignty.

  • Workflow portability assessment
  • Tight-coupling and exit-cost estimation
  • Alternative vendor capability comparison
  • Migration priority and sequencing plan

Consolidated output

One risk register. Five ranked findings.

Every dimension produces a finding with a risk tier, an estimated exposure, and a remediation option. The consolidated risk register ranks your five findings and gives you a prioritised action list with decision criteria for each: fix now, renegotiate at renewal, or accept and document.

  • Ranked risk register across all five dimensions
  • Remediation options with effort and impact estimates
  • Contract renegotiation briefing notes where relevant
  • Sovereign-AI posture summary for executive reporting

How the engagement works

A typical engagement runs two to three weeks from scoping call to risk register handoff. The scope is your current AI vendor stack — not a speculative exercise about future vendors.

Scoping call — ~30 min

Map your current vendor stack, the workflows that depend on it, the contracts that govern it, and where your instincts already tell you something is exposed. Thirty minutes establishes whether this engagement fits and what the highest-priority dimensions are for your situation.

You leave with: a clear framing of your top three exposure areas and a decision on whether to proceed.

Document and contract review — 3–5 days

Review your current AI vendor contracts, SLAs, data processing agreements, and usage policies against each of the five audit dimensions. Map what is documented, what is missing, and what the contracts do not cover that you assumed they did.

You leave with: a completed gap map across all five dimensions with preliminary findings.

Workflow and dependency mapping — 3–5 days

Trace the workflows that depend on each vendor, how tightly coupled they are, what breaks under each restriction scenario, and what the realistic migration cost would be. The goal is a clear-eyed picture of exposure, not a theoretical risk matrix.

You leave with: workflow dependency map and scenario analysis for the three highest-risk dimensions.

Risk register and handoff — 1 session

Consolidated risk register across all five dimensions with ranked findings, remediation options, and a sovereign-AI posture summary you can present to a board, compliance function, or executive team. Walk through the findings together and confirm you can act on them without RFE Online in the room.

You leave with: a risk register, remediation briefing, and contract negotiation notes you own going forward.

What you receive

Three artefacts, delivered by email at engagement close.

Deliverable 1

Sovereign AI Risk Register

A ranked PDF covering all five audit dimensions. Each finding states the risk tier, the evidence from your actual contracts and workflows, and a remediation option with effort and impact estimates. Prioritised so the first item is the exposure you cannot afford to carry into your next renewal.

Deliverable 2

Contract & SLA Gap Report

Specific clauses to add, renegotiate, or flag for legal review — drawn from your current contracts against nine known SLA gap patterns. Includes briefing notes your legal or procurement team can use at renewal without needing to re-read the full audit.

Deliverable 3

Sovereign AI Posture Summary

A one-page executive summary of your current vendor posture, the highest-priority gap, and the recommended remediation path. Board-ready and compliance-ready — structured for a risk committee, a board update, or a government contract submission requiring demonstrated AI risk governance.

Who this audit is built for

The buyer for this engagement has already committed to AI in production. They are not evaluating whether to use AI. They are looking at their current stack and asking: what risk have we taken on that we have not fully mapped?

Operators with production AI workflows

Teams that have AI models running in live operations — summarising, routing, generating, or deciding — and have not yet mapped what changes if a vendor restricts access or changes the model they built around.

Leaders facing contract renewals

Decision-makers approaching an AI vendor renewal with no clear view of what their current SLA actually covers, what data exposure they have accepted, or what their negotiating position is if the vendor raises prices or changes terms.

Compliance and risk functions

Risk, legal, or compliance teams who need a clear sovereign-AI posture document for a board presentation, regulatory review, or enterprise security assessment — and who do not have the technical framework to produce one internally.

This audit is not generic AI strategy. It is a structured assessment of your current stack, your current contracts, and your current exposure — producing findings you can act on before something changes.

Packages & indicative pricing

Every engagement starts with a scoping call to confirm the vendor stack, the contracts we will review, and the dimensions that matter most for your situation. The price ranges below are directional anchors.

Focused

Single Vendor Audit

From $1,800 AUD

One vendor relationship · three dimensions · scoping through risk report


  • 30-min scoping call
  • Contract and SLA gap analysis (one vendor)
  • Three audit dimensions of your choice
  • Preliminary risk finding and remediation note
  • 30-min handoff session

Enterprise

Multi-Vendor Fleet Audit

From $9,500 AUD

5+ vendor relationships · enterprise stack · board-ready risk posture


  • Everything in Full Stack, across your vendor fleet
  • Cross-vendor concentration risk analysis
  • Procurement policy gap documentation
  • Board or executive presentation deliverable
  • Regulatory and compliance framing (Privacy Act, GDPR adjacency)
  • Six-month vendor posture review option

Final scope and price are confirmed on the scoping call. If your stack is smaller, simpler, or more complex than these anchors suggest, say so in the inquiry form and we will scope accordingly. No obligation until we both agree it fits.

Start the conversation

Leave your email and a few words about your AI stack or the concern that brought you here. A confirmation email with a Calendly link lands in your inbox the same second — or book directly from the screen that appears after you hit send. No pitch deck, no obligation.

Related reading from the Sovereign AI pillar

The risk picture these articles document is the same risk this audit is designed to map.

Good fit

This engagement is built for operators, risk leads, and decision-makers who have already committed to AI in production and want a clear, structured view of their vendor exposure — before a contract renewal, a compliance review, or an access restriction forces the question.

It is not a vendor comparison, a build-vs-buy analysis, or a strategic roadmap. The job is to map the risk that already exists in your current stack and give you a risk register and remediation plan you can act on.

Thirty minutes to map your sovereign AI exposure.

A scoping call is where we look at your current AI vendor stack, the contracts that govern it, and the workflows that depend on it — and identify where the highest-risk exposure actually is. No proposal, no pitch until we both agree the engagement fits your situation.