Exit-Capable by Design: Vendor Concentration Is a Sovereignty Risk
Description
De-perimeterisation taught the security field to stop trusting the network boundary. Its modern corollary: stop trusting the commercial one.
This paper argues that vendor concentration in critical systems is a sovereignty problem wearing a procurement badge, and sets out exit-capability as a tested design requirement — decoupling the record of authority from the platform of convenience, maintaining the exit path as a living artefact, measuring concentration deliberately, and extending the same discipline to AI model dependencies.
It examines how four jurisdictions have reached three different remedies for the same diagnosis: obliging the institution (OSFI Guideline B-10, DORA Article 28, the CBUAE outsourcing rules), supervising the provider (DORA's critical ICT third-party oversight, the UK critical third parties regime), and making the market switchable (Chapter VI of the EU Data Act). It sets out the five elements an exit plan needs to be more than theatre, why concentration hides in regions, licensing regimes, identity planes and fourth parties rather than in vendor counts, and why none of the switching regimes reaches model behaviour. Closes with five questions for a board.
Part of the Sovereign Digital Resilience series.
Notes (English)
Files
exit-capable-by-design.pdf
Files
(212.9 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:6e025c73a427b067599d8bd710821d29
|
212.9 kB | Preview Download |
Additional details
Related works
- Is described by
- Preprint: https://www.sanjeetkumar.com/papers/exit-capable-by-design (URL)