eudai
[email protected]Book a call
← Writing
Risk & Resilience · 9 min read

Your biggest dependencies are rarely visible on the architecture diagram.

This week’s biggest exposures ran through people, suppliers, physical infrastructure, trusted intermediaries, and the systems connecting them.

The short version
  • AI risk is becoming dependency risk: what happens when the vendors, data, and decision rights behind AI become critical?
  • A former AI-safety researcher publicly challenged the industry’s race. Anthropic’s alignment lead amplified the concern.
  • Boston Scientific restored operations after a cyberattack and still cut its outlook.
  • Attacks on energy infrastructure and shipping pushed Saudi supply to a three-decade low.
  • Law firms hold sensitive data that many companies do not meaningfully map or assess.

Six stories, one throughline: critical dependencies now extend far beyond the boundaries most organizations document, review, and test.

Here is what happened — and what it changes for the companies selling into this market and the teams buying from them.

A dashed boundary encloses six documented layers: applications, APIs and services, data stores, cloud infrastructure, identity and access, and network and endpoints. Outside the boundary sit six undocumented dependencies connected by dashed lines: outside counsel, tier-one suppliers, shipping lanes, model vendors, auditors and agencies, and internal dissent.
The left column is what gets documented, reviewed and tested; the right column is what actually failed this week.

The people closest to the work are raising the alarm

Anthropic published a threat-intelligence report covering attempted cyber espionage, model extraction, surveillance, and dual-use biological and weapons research. It shows a frontier lab taking on elements of threat intelligence and incident response alongside technology development.

Then Jacob Coxon, formerly of both OpenAI and Anthropic, resigned and warned publicly that the industry is building more capable systems without demonstrating it can control them. Anthropic’s alignment lead put the chance of AI-driven human extinction this decade above 10%.

A post by Sikander Asif reading: Anthropic: We are going to kill you. OpenAI: We are going to kill you first. Apple: now you can fold iPhone.
The race, as the internet sees it. Posted by @SikanderAsif11 on September 9, 2026.

There is an older story underneath that rupture.

In 1944, Joseph Rotblat became the only scientist known to leave the Manhattan Project on moral grounds. He had joined because he believed Germany might build the bomb first. When Allied intelligence made clear that premise had fallen away, so did his willingness to continue. His decision brought years of suspicion and professional cost. More than five decades later, Rotblat shared the Nobel Peace Prize for his work to reduce the role of nuclear weapons in international affairs.

Coxon’s decision carries a version of that question into the AI era: what does a scientist do when the assumptions that made the work feel defensible no longer hold?

There is a consequential difference. Rotblat’s dissent made him suspect. Coxon’s dissent makes him visible.

Coxon did give up equity that had not yet vested to leave Anthropic, a real personal cost. He has also entered a world in which his warning is being amplified by peers, policymakers, and a mature AI-safety ecosystem. The distinction says something about the era — and about the companies building it.

Frontier labs have created a culture where warning about catastrophic risk can be morally serious and commercially useful at the same time. The warning reinforces the idea that this technology is consequential. It can also reinforce the idea that the lab is uniquely qualified to manage the danger.

There is no evidence that Anthropic orchestrated Coxon’s resignation or its public reception. The question is more structural than that. What would a dissenting employee have to say — or what would they have to demonstrate — for the company’s trajectory to change?

The answer is not whether employees are allowed to speak. It is whether speaking changes the trajectory.

For providers: buyers will look closely at the relationship between public principles, employee safeguards, product controls, and commercial pressure. Be prepared to explain anticipated misuse cases, safeguards, monitoring, escalation paths, and response when a control fails.

For in-house teams: can someone raise a material concern, have it tested, escalate it, and alter a decision before it becomes external news? Most organizations have a policy. Far fewer have a working path — the gap between a governance mandate and someone accountable for it.

Copying a model changes the economics

The U.S. accused several Chinese AI firms of industrial-scale model distillation, while Anthropic’s report describes similar alleged extraction attempts. Proprietary models, training data, prompts, and workflows now belong inside the security perimeter.

For providers: performance alone is a thinner moat than it appeared a year ago. What is actually defensible? What can customers trust you to protect? Controlled workflows, protected access, proprietary data, and evidence of responsible deployment all matter.

For in-house teams: if a vendor’s advantage is its model, ask what happens to your agreement if that advantage is copied or commoditized. Bring that into the renewal conversation alongside the contractual questions buyers are already adding to AI deals.

Financial services AI has to carry its own evidence

OpenAI launched a financial-services version of ChatGPT, built around regulated workflows, firm data, established financial-data providers, role-based access, encryption, and audit logs.

For providers: the next phase of enterprise AI is verticalization. The bar is integrating with a buyer’s existing data, approvals, evidence requirements, and daily work. That is what creates relevance in a vertical market.

For in-house teams: a product that understands your evidence requirements can shorten assurance work considerably. Ask what it can produce for an auditor, alongside what it can produce for a user. The evidence burden regulation creates lasts much longer than the demo.

The supplier you cannot replace

A Capgemini survey found organizations mapping critical technology dependencies and planning for substitution as geopolitical risk, cyber threats, and export controls rise. The telling finding: replacing a key supplier could take months or longer.

For providers: resilience is moving upstream into architecture and vendor choice. Substitutability, data portability, fallback modes, and transparent dependency maps are becoming part of product value.

For in-house teams: if replacing a critical supplier takes months, it should sit alongside recovery objectives and in how you explain the program to the board.

Recovery came too late to save the quarter

Boston Scientific restored manufacturing, fulfillment, and shipping after a cyberattack, then cut its outlook. The systems came back. The business impact remained material enough to affect financial guidance.

Restored systems are an IT milestone. Protected revenue is the business outcome.

For providers: availability metrics can stay green through an event that still costs a customer a quarter. Cleared backlog, stable customer service, and protected revenue are the measures that matter. The gap between those vocabularies is where breach communications decides your positioning.

For in-house teams: run the exercise past restoration. Many tabletops end at “systems recovered,” which is where this incident’s real cost began.

From a shipping lane to the balance sheet

Saudi oil supply fell to a three-decade low after attacks on energy infrastructure and shipping.

For providers: resilience products often organize around threat categories. Real events tend to cross them.

For in-house teams: check whether your scenario set is built around threats and consequences. Consequence-based scenarios usually travel farther across complex events. Making that case internally is its own exercise.

Counsel is holding some of your most sensitive data

Multiple law firms disclosed incidents or litigation connected to breaches, including social engineering directed at lawyers. Law firms hold deal, litigation, regulatory, and personal data that clients cannot easily replace or re-secure after disclosure.

For providers: the third party as front door is a tangible and timely example. Advisors, counsel, auditors, and agencies may sit deep inside the practical perimeter without appearing in the architecture map.

For in-house teams: some of your most sensitive material may be held by organizations that barely feature in the vendor-risk program. Ask which outside parties hold data you could not recover from a disclosure — and whether anyone has assessed them.

The dependencies that decide whether you keep operating

These exposures ran through a researcher’s conscience, a supplier’s replacement timeline, a shipping lane, and a lawyer’s inbox.

Resilience depends on the full set of relationships, capabilities, and infrastructure that keep an organization operating.

The organizations with the best chance of operating normally after a week like this understand what they truly rely on, where those dependencies sit, and what happens when one of them breaks. Read this alongside what resilience documentation actually proves.

Paula Fontana
Written byPaula Fontana
Founder & CEO, eudai

Paula has spent two decades leading marketing for security, risk, and resilience companies — three times as CMO — taking technical platforms through category creation, repositioning, and growth. She advises founders and sits on boards in the space, is Gartner-published on go-to-market, and has been featured in The Wall Street Journal.

  • 3× CMO
  • Board director
  • Gartner-published
  • WSJ-featured
  • Elite 18 CMO
  • Fearless 50
Read next · AI GovernanceThe week AI became its own risk class. Sep 2026 · 8 min read

Working on a positioning, brand, or go-to-market problem in security, risk, or resilience?

Start a conversation →