Published September 2, 2026 | Version v3

Exit-Capable by Design: Vendor Concentration Is a Sovereignty Risk

  • 1. Robotiqa Technologies Ltd.

Description

De-perimeterisation taught the security field to stop trusting the network boundary. Its modern corollary: stop trusting the commercial one.

This paper argues that vendor concentration in critical systems is a sovereignty problem wearing a procurement badge, and sets out exit-capability as a tested design requirement — decoupling the record of authority from the platform of convenience, maintaining the exit path as a living artefact, measuring concentration deliberately, and extending the same discipline to AI model dependencies.

It examines how four jurisdictions have reached three different remedies for the same diagnosis: obliging the institution (OSFI Guideline B-10, DORA Article 28, the CBUAE outsourcing rules), supervising the provider (DORA's critical ICT third-party oversight, the UK critical third parties regime), and making the market switchable (Chapter VI of the EU Data Act). It sets out the five elements an exit plan needs to be more than theatre, why concentration hides in regions, licensing regimes, identity planes and fourth parties rather than in vendor counts, and why none of the switching regimes reaches model behaviour. Closes with five questions for a board.

Part of the Sovereign Digital Resilience series.

Notes (English)

NOTE: v3 changelog - metadata update; paper text unchanged.

Files

exit-capable-by-design.pdf

Files (212.9 kB)

Name Size Download all
md5:6e025c73a427b067599d8bd710821d29
212.9 kB Preview Download

Additional details

Related works