The AI Dependency Web
Reducing dependence at one layer can deepen it at another. Governments and organizations should ask where exposure moves and whether capability and optionality grow.
Access Is Not Possession
On June 12, 2026, Anthropic said it had received a US government directive requiring it to suspend access to Fable 5 and Mythos 5 for foreign nationals. The company said the directive applied to foreign nationals both inside and outside the United States, including its own foreign-national employees, and that it disabled the two models for all customers to ensure compliance.
The restriction lasted 18 days. In a June 30 update, Anthropic said the controls had been lifted and Fable 5 would return globally from July 1. Mythos 5 returned first to approved US organizations while wider access remained under government coordination.
Access was first withdrawn under a government directive and later restored after the controls were lifted and Anthropic revised its safeguards. Anthropic said the directive followed an Amazon report about bypassing Fable 5’s safeguards; before redeployment, it trained an improved safety classifier and had the safeguards tested by the US Department of Commerce’s Center for AI Standards and Innovation. The point is institutional rather than normative: downstream organizations may consider those security conditions legitimate, but they do not control the regulatory channel through which access changes.
Access is not possession.
An organization may integrate a model into a workflow, train employees around it, and treat it as part of operational capacity. Yet the right to use that model can still depend on a jurisdiction, provider, license, compliance interpretation, or future policy change. The model may feel like infrastructure to the user while remaining permissioned access in legal and operational terms.
Dependence begins where someone else can change the terms of use, even though many such relationships are necessary and productive. Modern capability is built through electricity grids, telecom networks, payment systems, cloud providers, standards bodies, and vendors of every kind. The error is mistaking working integration for durable control.
AI makes integration especially easy to mistake for control because the interface hides what sits underneath it. A user sees an assistant, a procurement officer sees a vendor contract, and a minister sees a national AI initiative. Beneath each surface are model weights, hosting, chips, cloud accounts, software libraries, evaluation systems, data pipelines, compliance rules, and jurisdictional controls.
Adam Segal argues that frontier AI firms increasingly exercise geopolitical power through decisions about access, safety, continuity, and partnerships. For a public agency, that means a provider can become part of the operating environment without giving the adopting institution comparable leverage.
The AI Market Is Not One Market separated AI into linked markets for models, infrastructure, coordination, and assurance. Once those markets are separated, their dependency relationships become visible. If a buyer changes one layer, what happens to the others?
Four familiar strategic choices reveal the problem. An organization can switch model suppliers, adopt open-weight models, tune its workflows to one environment, or host models domestically. Each move can increase control or reduce exposure at one layer. Each can also leave a different part of the system outside the organization’s control.
Dependence can genuinely shrink when an intervention increases substitutability, disperses control, or creates multiple viable maintenance paths. Other interventions remove one dependency while leaving, deepening, or creating another elsewhere. Call this second pattern dependency relocation.
The right image is a web, not a chain. A chain breaks at its weakest link. A web redistributes load: pull on one strand, and tension often reappears in the strands that remain.
Figure 1: The AI Dependency Web: A Trade-off Map.
Each row in Figure 1 shows the same pattern: a real gain at one layer alongside exposure that remains or moves elsewhere. The comparison creates a practical test for any intervention: identify the strand that changed, locate the remaining exposure, and ask whether the new relationship can be switched, governed, or used for learning.
Dependency relocation names the mechanism; mapping the dependency web is the method. Increasing optionality is the objective.
Visibility Comes Before Strategy
Making the dependency web visible requires more than listing suppliers; it requires comparing the control gained with the exposure that remains. Switching suppliers may change model access while leaving platform control intact; domestic hosting may change jurisdiction while leaving training and hardware elsewhere. Dependency relocation appears in that gap.
The Fable and Mythos restriction was visible but largely non-controllable for most users. A model supplier inside a multi-model platform may be switchable, although replacement still carries integration costs. Contracts, independent evaluations, and portability requirements provide tools for governing some dependencies. A vendor relationship becomes capability-building when the buyer retains reusable evaluations, trained staff, and routines that survive the contract.
A large cloud platform and a small public agency may hold different dependencies even when they use the same provider. That provider can be switchable for the platform and effectively non-controllable for the agency. The categories describe a relationship for a particular actor, layer, and time horizon, not a permanent property of the technology or supplier.
The distinctions matter because they change the available response. Switching creates room to diversify; governance can be strengthened through contracts and independent evaluation; capability-building relationships leave reusable learning; non-controllable exposures require contingencies. Visibility does not supply control, but it prevents one response from being applied indiscriminately to every strand in the web.
Kyle Chan’s Brookings framework addresses a different problem: assessing the risks and benefits associated with Chinese technology products and investments. Its sequence is to identify the risk, assess the benefit, choose a targeted mitigation, explain the decision, and monitor change. That process still offers a useful procedural lesson for dependency mapping. Foreign-linked technology should be assessed by the exposure it creates and the layer where that exposure sits, rather than being treated as a single moral category.
Substitution Moves Dependence Into the Work Loop
Substitution matters because it is the most immediate response to a visible dependency. Brad DeLong’s discussion of model convergence remains a live and unsettled signal. If more models become acceptable for the same tasks and platforms make them easier to route, buyers gain the option to change suppliers without rebuilding the entire workflow. That substitution can be valuable, but it also changes who controls the environment through which the models are selected and used.
Microsoft’s reported exploration of a Microsoft-hosted DeepSeek option for Copilot Cowork illustrates the move. Axios reported that Microsoft was considering a fine-tuned version of DeepSeek V4, or another open-weight model, as a lower-cost option for Cowork. The report described an option under evaluation, not a completed product decision. Changing the model supplier could reduce one exposure while deepening reliance on the platform that hosts, routes, meters, secures, and bills for use.
Microsoft’s model-routing structure reveals the first relocation: from model supplier to multi-model platform. Microsoft documents Cowork as a product in which model availability and automatic selection sit inside organizational and administrative controls. The OECD identifies high capital requirements, economies of scale, proprietary software ecosystems, and vertical integration across AI infrastructure. As identity, data, connectors, billing, and procurement pass through the platform, easier model choice can concentrate reliance in the layer supplying that flexibility.
Open weights offer a more durable form of model substitution, but they change a different strand. Once lawfully downloaded, released weights cannot be withdrawn as API access can. Meta’s official Llama repository, for example, supplies downloadable weights under a custom license. The model still has to be hosted, evaluated, secured, monitored, updated, and connected to work. As CSIS notes, third-party hosting can also move prompts, logs, feedback, and other learning signals away from the model developer and toward the host or deployer.
Neither supplier choice nor access to model weights determines practical performance once the model enters a workflow. Coding agents, enterprise copilots, and research assistants construct context, call tools, manage credentials, check results, retry failures, and decide when to stop. Practitioners call this surrounding system the harness. An organization may become attached less to the model than to the environment that makes it useful.
A recent position paper combining leaderboard comparisons with a controlled experiment, “Stop Comparing LLM Agents Without Disclosing the Harness”, reports large performance differences when the same model is run through different scaffolds. In one public-leaderboard example, Claude Opus 4.5 scored 45.9 percent on SWE-bench Pro under one standardized scaffold and 55.4 percent under Claude Code. The result does not establish that one native harness will always win. It shows that context systems, permissions, tools, evaluations, memory, logging, and runtime jointly produce practical capability.
The work loop also absorbs the institution’s own knowledge. To make a system useful, a buyer supplies prompts, corrections, private evaluations, workflow traces, and institutional context. Depending on the architecture and contract, those signals can improve the service while accumulating outside the buyer’s control. Satya Nadella describes this through a “reverse information paradox” and an argument for firm-owned learning loops; his diagnosis is situated because it also aligns with Microsoft’s position as an enterprise platform provider. Dependency includes the location of the learning loop: where traces, evaluations, feedback, memory, and workflow improvements accumulate.
When evaluations, traces, and workflow knowledge accumulate around one environment, later substitution becomes harder. Research on coordination and lock-in shows how incompatibility, learning, setup costs, and network effects can make exit expensive. The European Union’s Data Act addresses related concerns in cloud and data-processing services through switching, open-interface, and interoperability requirements.
For AI buyers, ownership and portability are separate questions. An institution may own its evaluation records and still be unable to move them when the workflow logic, permissions, and audit history that produced them remain with the vendor. Procurement should therefore keep evaluations, connectors, logs, fallback rules, traces, and decision records portable enough for institutional controls and learning to survive a model change.
Sovereignty Moves Dependence Across Phases and Layers
Governments make a similar substitution when they move a foreign-trained model from an external API onto domestic infrastructure. Hosting the model locally can keep inference and relevant data within a preferred jurisdiction, depending on the deployment architecture. The upstream developer still controls how the model was trained, how its architecture evolves, and whether future versions are released.
Training, inference, evaluation, deployment, and governance are distinct forms of AI capability. Training produces or substantially improves a model; inference serves it reliably and cheaply. Evaluation judges its behavior in context, deployment embeds it into work, and governance determines whether an institution can audit, contest, update, suspend, or replace it.
Moonshot AI’s Kimi K3 shows why model access and inference capacity have to be assessed separately. Moonshot has released the model’s full weights, but wider availability does not itself provide the compute and serving capacity required for reliable use. The Associated Press reported that Moonshot temporarily paused new subscriptions when demand pressed against its serving capacity. Opening the weights reduced one form of access dependence while leaving the inference problem intact.
A sovereignty claim becomes misleading when it treats one changed phase as control over the whole system. Domestic hosting changes residency, legal reach, and procurement control. Training and update authority remain elsewhere. A domestic model can build language capability, engineering practice, and evaluation routines while the country continues to rely on foreign chips, cloud software, or toolchains. A country can gain greater control over inference while remaining dependent in training, or gain data control while lacking evaluation control. This layer-specific view is increasingly visible in work on managed interdependence.
Mistral offers one European route through this web: a regional model company, enterprise tools, a compute platform strategy, and publicly supported AI Factories. The route increases European agency while retaining dependencies on accelerators, energy, cloud channels, and semiconductor supply chains.
A government may gain control over inference without gaining control over training or evaluation. Continued use adds another variable: the skills, routines, and records that accumulate around the chosen system.
Dependence Accumulates With Use
Repeated use builds prompt libraries, evaluation suites, connectors, procurement routines, audit trails, and user habits. Concentrating this operational memory in one system can raise the cost of exit.
Proprietary interfaces and non-portable formats can make the system more productive while making its accumulated learning harder to move. Transferable skills, institution-owned evaluations, modular connectors, and portable records weaken that connection. A dependency held for five years can be a different exposure from the same one held for five months because more operational memory has become system-specific, not because time alone creates lock-in.
Figure 2: Capability and Exit Costs Can Accumulate Together.
An institution does not need frictionless switching. It needs the capability accumulated through use to move with it when a supplier, model, or contract changes.
India’s Dependency Web
India’s AI stack contains several kinds of dependency at once. EUV lithography cannot be substituted quickly; imported accelerators can be diversified only at a cost; public compute access can be governed; and domestic model partnerships can build capability if their learning remains portable. A single sovereignty label cannot describe all four.
Advanced lithography is, for now, a non-controllable dependency. ASML is the only manufacturer of EUV lithography systems, while a 2026 US Government Accountability Office report describes leading-edge logic and memory manufacturing as particularly concentrated in Taiwan and South Korea. India can build semiconductor partnerships, packaging capacity, design talent, and long-term industrial policy, but it cannot quickly control that bottleneck.
Imported accelerators are switchable only at cost. The IndiaAI Compute Portal’s live price list spans Nvidia, AMD, Intel, AWS, and Google hardware, but the options are not equivalent across workloads. Switching changes performance, software compatibility, pricing, availability, and support. Supplier diversity therefore has to be matched by benchmark portability, procurement clauses, fallback capacity, and enough engineering depth to avoid one software path becoming permanent.
IndiaAI’s compute portal and AIKosha offer visible and partly governable access infrastructure. Their value depends on whether allocated GPUs become repeatable institutional work: who gets capacity, whether users receive enough support to use it, what datasets are available, and what learning remains afterward. The mission’s Safe and Trusted AI work matters for the same reason. Evaluation and assurance are part of whether capability can be governed.
A domestic data center changes jurisdiction, data residency, and latency. Its strategic value also depends on what accumulates around the facility: reusable evaluation practices, skilled operators, public-sector deployment knowledge, and access rules that outlast a single vendor contract. Physical capacity becomes capability-building when institutions can repeatedly use and learn from it.
Sarvam is among the most visible companies developing foundation models through IndiaAI-linked efforts. If Sarvam and similar programs produce reusable benchmarks, Indian-language datasets, engineers who circulate, deployment practices public agencies can understand, and procurement templates that outlast one contract, dependence on a domestic firm may build national capability. If the traces, evaluations, feedback, and workflow improvements remain inside the company, public institutions may simply replace foreign vendor dependence with domestic vendor dependence. The capture is localized, not removed.
Across these four dependencies, the strategic question is what remains when access or a contract ends. Public spending and enterprise deployment can leave reusable evaluations, skilled operators, procurement knowledge, and bargaining power. When that learning remains inside one provider or stack, the result is procurement at scale rather than capability formation.
The Strategic Aim Is Optionality
No major AI actor controls every layer. Countries and firms depend on semiconductor supply chains, energy systems, platforms, standards, capital, and corporate coordination they do not fully command. The first task is to make those relationships visible, then decide which can be switched, governed, used for capability-building, or only managed as non-controllable exposures.
The Fable and Mythos case makes operational continuity concrete. An institution building around a system whose terms can be changed elsewhere needs a fallback map: the work that would stop, the data that could be stranded, the available replacement, the evaluations that would have to be rerun, the procurement clause that would matter, and the human capability that would remain.
Middle powers cannot declare sovereignty over every layer or rent intelligence indefinitely from systems they cannot inspect, govern, or replace. The path between those errors is narrower and more demanding: map the dependency, price the switching cost, govern what can be governed, learn from what must be used, and build options where control is not yet possible.
Optionality has a carrying cost. Maintaining fallback models, modular connectors, independent evaluation, and redundant capacity requires resources that a single optimized path appears to save. AI makes the pattern unusually visible, but the same logic travels through cloud, energy, payments, telecommunications, critical minerals, and other modern technology systems. The purpose of AI strategy is not independence. It is increasing optionality faster than dependencies accumulate: rethreading the web strand by strand, rather than pretending it can be cut.
The mature question is no longer whether we are dependent. It is what kind of dependence we hold, and what capability will remain when the supplier changes the terms.
Visual note: The diagrams in this essay are original Yukti visuals, designed from the author’s briefs and produced with AI-assisted code generation, then reviewed before publication.
Earlier Essays
The Stack Beneath the Interface - why AI capability has to be read layer by layer.
Operational Capacity Is AI Capability - why evaluation, procurement, audit, and institutional control are not administrative afterthoughts.
Digital Public Infrastructure and Its Limits - why coordination layers can expand access while infrastructure constraints continue to bind.
Capability Formation, Not Technology Adoption - why access matters only when it turns into durable institutional learning.
Why Technology Is an Institutional Problem - why procurement, workflow, oversight, and recourse shape what technology becomes.
The Dynamic Trilemma of Technology Strategy - the strategic trade-offs middle powers face when autonomy, acceleration, and openness pull in different directions.
The Uneven Acceleration Problem - why access can move faster than institutions can absorb, evaluate, and govern it.
The AI Market Is Not One Market - why buyers enter linked markets for models, infrastructure, coordination, and assurance; this essay follows the dependencies created across them.
Further Reading
Henry Farrell and Abraham Newman, “Weaponized Interdependence” - the established account of how network position and chokepoints create coercive power.
Carliss Baldwin and Kim Clark, “The Option Value of Modularity in Design” - why modular architecture creates substitution options while imposing design costs.
Wesley Cohen and Daniel Levinthal, “Absorptive Capacity: A New Perspective on Learning and Innovation” - why external access becomes capability only through accumulated organizational learning.
Arvind Narayanan and Akash Kapur, “Up the Stack: How AI’s Escape From the Commodity Trap Risks Enterprise Lock-in” - an adjacent economics account of how easier model switching can coexist with deeper dependence on orchestration, embedded workflows, accumulated state, and commercial contracts.
Sources and Case Materials
Anthropic’s June 12 access statement and June 30 redeployment update - the opening case of frontier-model access changing through provider-state coordination.
Adam Segal, The AI Balance of Power - support for treating frontier-firm control over access and operating decisions as a source of public and geopolitical leverage.
Axios, Microsoft weighs DeepSeek for Copilot Cowork and Microsoft’s Cowork model-choice documentation - reported model substitution and the documented multi-model platform layer.
Brad DeLong, “Convergence in LLM Quality & Slowdown in LLM Improvement” - a live, unsettled signal that narrower model gaps may shift value and dependence into surrounding platforms.
Meta’s official Llama model repository - model cards, downloadable weights, licenses, and release history for the open-weight example.
Moonshot AI’s Kimi K3 model page and Associated Press reporting on its serving-capacity pause - released model weights and the operational constraint that wider availability still requires serving capacity.
CSIS, What to Know About Chinese AI Models - the provider-side trade-off between open-weight diffusion, direct usage signals, enterprise relationships, and integrated-product monetization.
Zhang et al., Stop Comparing LLM Agents Without Disclosing the Harness - evidence that agent performance is jointly produced by model and execution environment.
Satya Nadella, The Reverse Information Paradox and A frontier without an ecosystem is not stable - an interested enterprise account of proprietary context, learning loops, orchestration, and the ownership of traces, evaluations, memory, and feedback.
European Commission, Data Act explained - switching, open-interface, and interoperability requirements for data-processing services.
Brookings and CEPS, Is AI sovereignty possible? - the adjacent managed-interdependence account of layer-specific AI sovereignty.
Mistral Compute and European Commission, AI Factories - European private and publicly supported compute initiatives.
OECD, Competition in Artificial Intelligence Infrastructure - scale economies, capital barriers, proprietary ecosystems, and vertical integration in AI infrastructure.
Farrell and Klemperer, Coordination and Lock-In - switching costs arising from incompatibility, learning, setup, and network effects.
Kyle Chan, A New Risk Framework for Chinese Technology Products and Investments - risk, benefit, mitigation, transparency, and monitoring as an instrument-selection sequence.
ASML on its EUV position and GAO on semiconductor supply-chain concentration - leading-edge lithography and fabrication concentration.
IndiaAI Compute Portal price calculator and the PIB release on the Compute Portal and AIKosha - current accelerator options and governable public-access infrastructure.
The Rajya Sabha portfolio reply - IndiaAI-linked foundation-model efforts.




