TL;DR

The ratings agency Moody’s says lenders and insurers are consolidating their AI onto a handful of model builders and cloud platforms, and that the resulting concentration risks hardening into a dependency the whole system carries. The uncomfortable part is not procurement cost. It is that the institution stays accountable for services whose behaviour a supplier can alter without telling anyone.

Why uptime monitoring misses the problem

A conventionally outsourced application does defined things and repeats them. A foundation model does not. Outputs vary, and a vendor update can move accuracy, latency, tone or the risk controls embedded in the service while the bank’s own code sits untouched. Ordinary availability checks will not register that, because the system remains online and keeps returning answers as its quality erodes. Testing therefore has to cover degradation rather than only failure: how quickly a shift in behaviour is noticed, what threshold forces intervention, and whether a process can be handed back to people before any customer feels the effect.

The fallback nobody has exercised

Naming a second provider is not the same as being able to reach one. Prompting conventions differ from one model to the next, and so do the interfaces, the safety controls and the shape of data each expects. Applications also drift towards whatever a particular vendor happens to do uniquely well. Moody’s wants resilience testing that genuinely moves a critical workload across and checks portability, compatibility and how the substitute behaves in production. It also flags hidden commonality: several apparently independent applications can rest on the same cloud, the same base model or the same specialist hardware, which makes an estate look more diversified than it is.

Looking forward

Britain has just had the live demonstration. Four major providers went dark in an overlapping window last week, which is exactly the correlated failure this report describes. The Financial Stability Board already lists supplier dependency and provider concentration among the channels through which AI could magnify risk across the system, and the Bank of England has been making comparable points about frontier models since August. For UK finance teams the useful question is unglamorous: has the exit plan ever actually been run? A multi-model strategy buys nothing when every model sits on one cloud, and an open-weights alternative is no safer if nobody has been funded to maintain, secure and watch it.