Open Models, Strategic Dependencies: Why AI Sovereignty Is Becoming A Supply Chain Issue

The next major supply-chain dependency may not involve semiconductors, critical minerals, transportation capacity, or industrial components. It may be embedded inside the artificial intelligence models companies use to build their next generation of operational systems.

Open AI models are becoming foundational components of enterprise technology architectures. Companies can download them, customize them, fine-tune them with proprietary information, and deploy them privately. This can lower costs, improve control, and reduce dependence on a small number of closed-model providers.

But open does not necessarily mean independent.

As more of the open-model ecosystem consolidates around model families developed outside the United States, companies may be exchanging one form of vendor dependence for another. How much of an enterprise AI architecture should depend on a model ecosystem whose future development, governance, licensing, and geopolitical availability the company does not control?

The Rapid Rise of Qwen

Researchers affiliated with the ATOM Project recently documented a major shift in the open-model ecosystem. Qwen’s share of newly released fine-tunes and adaptations rose from approximately 1% in January 2024 to 69% by February 2026, while Meta’s share declined sharply from its earlier peak.

That does not mean 69% of enterprise AI deployments use Qwen. The figure measures the model families developers select when creating new fine-tunes, adapters, and derivative models.

Even so, the trend matters. Fine-tunes and derivative models show where developers are investing time, expertise, datasets, integrations, and tooling. Once a model becomes the default foundation for downstream applications, it begins to resemble a digital industrial platform.

Developers optimize libraries around it. Enterprises build evaluation frameworks, deployment pipelines, governance processes, and specialized skills around its behavior. That creates ecosystem gravity, and ecosystem gravity creates switching costs.

This Is Not an Argument Against Chinese Models

The rise of Chinese open models should not be dismissed as careless adoption or geopolitical naïveté. Many are highly capable, economically attractive, and available under licenses that permit extensive modification and deployment.

Chinese AI laboratories have increased competition, accelerated open-model development, and put downward pressure on inference costs. For enterprises, that is broadly positive.

Manufacturers, retailers, logistics providers, and software companies can build useful AI applications with models that are less expensive to run and easier to customize than the largest proprietary alternatives. Open models can also be deployed closer to operational data and used where privacy, latency, or cost makes a fully hosted service impractical.

The issue is not whether companies should use Chinese-developed models. It is whether they understand the concentration risk created when one model family becomes deeply embedded across the AI stack.

Model Dependence Is Supplier Dependence

Supply-chain organizations already know how to evaluate dependence on a critical supplier. They examine substitution difficulty, geographic concentration, financial stability, capacity, regulatory exposure, and the time required to qualify an alternative.

A foundational AI model should increasingly be evaluated the same way.

When a company builds an operational application around a model family, it may create retrieval pipelines, fine-tuned adapters, prompt libraries, security controls, evaluation benchmarks, agent workflows, model-specific infrastructure, integration logic, and employee expertise.

The surrounding implementation represents accumulated investment and organizational learning.

Replacing the model may require revalidating the application. Outputs can change. Tool calls may behave differently. Fine-tunes may not transfer cleanly. Safety controls may need redesign. Performance may deteriorate in specialized tasks.

That is what makes a supply source strategically important: not simply the cost of the item, but the cost and operational disruption associated with replacing it.

The risk extends beyond model access. Enterprises should ask who maintains the architecture, controls its repositories, corrects vulnerabilities, and determines its future direction.

There is also a provenance problem. A derivative model may have passed through several rounds of fine-tuning by unknown parties. Each stage can alter its behavior, security profile, or susceptibility to manipulation.

This does not make derivative models inherently unsafe. It means enterprises need software-supply-chain disciplines for AI. Models should have traceable lineage, version records, license information, modification histories, and documented approval status. The principles behind a software bill of materials will increasingly apply to models, adapters, embeddings, agent tools, and AI-generated code.

AI Sovereignty Is an Architectural Question

AI sovereignty is usually discussed at the national level. Governments want domestic access to computing infrastructure, semiconductors, data, talent, and foundational models.

But sovereignty also matters at the enterprise level.

An organization has greater AI sovereignty when it can preserve operational continuity, move between model providers, control proprietary context, and replace components without rebuilding the entire system.

This does not require every company to train its own large language model. For most businesses, that would be economically irrational. It does require enterprises to avoid architectures in which the model becomes inseparable from the application.

The model should be treated as a replaceable intelligence component rather than the permanent center of the stack. Enterprise data, business rules, workflow orchestration, tool definitions, security controls, evaluation datasets, audit trails, and decision rights should remain outside the model whenever practical.

This separation is becoming more achievable. Retrieval-augmented generation can keep proprietary knowledge outside the model. Graph-enhanced retrieval can represent operational relationships. Model Context Protocol servers can standardize access to enterprise data and tools, while Agent-to-Agent protocols can help specialized agents exchange work.

Together, these technologies can create an abstraction layer between the foundational model and the operational system. The enterprise then owns the context, integrations, workflows, and governance, even when it changes the model providing the reasoning capability.

Supply-Chain Leaders Should Demand Model Portability

Technology teams often evaluate models on benchmark performance, speed, inference cost, and ease of deployment. Supply-chain leaders should add portability and concentration risk.

Four questions matter most.

Can the application operate with more than one model family? A production system should be tested against at least one credible alternative so the organization understands the effort required to switch.

Is proprietary knowledge stored outside the model? The more enterprise knowledge is embedded only in a model-specific fine-tune, the harder migration becomes.

Are tools and integrations exposed through standardized interfaces? Model-specific integration code increases lock-in. Standardized APIs, schemas, and protocols make substitution easier.

Does the company own independent evaluation datasets and a fallback plan? Enterprises need their own tests to determine whether a replacement model performs adequately, along with a defined alternative for critical workflows.

The objective is not maximum model diversity. Excessive variety creates fragmented governance, duplicated infrastructure, and cybersecurity exposure.

The objective is controlled optionality.

A company may designate one preferred model while validating one or two alternatives. Specialized models can support transportation exceptions, supplier-risk analysis, or document processing, with another model available for continuity or privacy-sensitive workloads.

This resembles a sound sourcing strategy: single-source where justified, dual-source where necessary, and standardize where redundancy would create more cost than resilience.

The United States Faces an Open-Model Policy Dilemma

The enterprise challenge reflects a broader national issue.

The United States has focused heavily on semiconductor controls and domestic computing infrastructure. But hardware policy alone cannot secure the open-model ecosystem.

If American developers increasingly build on foreign model foundations, the United States may retain strength in chips, cloud platforms, and frontier proprietary models while losing influence over the open development layer.

Restricting foreign open models would carry significant costs. It could reduce competition, slow innovation, and disadvantage smaller companies that benefit from inexpensive, capable models.

A more productive response would be to strengthen American open-model competitiveness through research support, shared evaluation infrastructure, high-quality public datasets, secure distribution systems, and incentives to release commercially usable model families.

Dean Meyer and Konstantine Buhler, whose analysis helped elevate this debate, have also argued for stronger American capabilities in controlled post-training and model adaptation. That deserves attention. The strategic contest may be determined not only by who trains the largest model, but by who creates the most useful ecosystem for adapting models to operational work.

The Supply Chain Is Moving Inside the Model Stack

Supply-chain risk management has historically focused on materials, components, factories, ports, carriers, and inventory. Enterprise AI adds a digital layer.

Organizations now depend on model weights, vector databases, orchestration tools, APIs, data pipelines, agent protocols, and cloud infrastructure. Together, they form a digital supply chain that can be disrupted, compromised, or politically constrained.

The rise of Qwen and other Chinese open models should be understood in that context. Their growth reflects technical and commercial success. It also shows how quickly the open-model ecosystem can consolidate.

The correct response is neither prohibition nor complacency.

Companies should use the strongest tools available while preserving the ability to change them. They should treat model provenance as a governance issue, portability as an architectural requirement, and concentration risk as a supply-chain concern.

Open models can reduce dependence on proprietary AI providers. Without deliberate architecture and sourcing discipline, however, they can also create a new strategic dependency beneath enterprise operations.

The companies that understand this distinction will not merely adopt AI faster. They will build AI systems that remain resilient when technology markets, vendor landscapes, and geopolitical conditions change.


AI Is Reshaping Supply Chain Execution. Here’s What Comes Next.

Two ARC Advisory Group white papers on the next stage of AI in supply chain operations.

AI is moving beyond isolated copilots and technical architecture into coordinated operational decision systems. This ARC Advisory Group white paper explains how supply chain AI is shifting from capability to execution, where context, governance, workflows, thresholds, and action pathways determine whether AI improves real decisions across planning, logistics, sourcing, fulfillment, and risk management.

Download Our Featured White Paper:

AI in the Supply Chain Part II: From Architecture to Execution - Defining the Decision Intelligence Layer in Modern Supply Chain

Download Our Foundational White Paper:

AI in the Supply Chain: Architecting the Future of Logistics with A2A, MCP, and Graph-Enhanced Reasoning

Explore Our Domains

Planning, Execution & Visibility | Transportation & Logistics Operations | Warehousing, Fulfillment & Automation | Global Trade & Compliance | AI & Advanced Analytics | Data, Integration & Interoperability | Supply Chain Platforms | Risk & Resilience | Sustainability & ESG

Independent ARC research for supply chain leaders and technology decision-makers.

RECENT NEWS

Copper's Comeback: Inside BHP And Lundin's Argentine Asset Acquisition

Copper, often dubbed "the metal of electrification," is experiencing a resurgence in demand due to its critical role in ... Read more

Revitalizing Commodities: How Clean Energy Is Breathing New Life Into A Stagnant Market

The commodities market, traditionally a cornerstone of investment portfolios, has experienced a decade of stagnation. Ho... Read more

European Airports Disrupted By Escalating Climate Protests

Climate activists have escalated their protests at European airports, blocking runways and causing flight disruptions in... Read more

Hungary's Russian Oil Dilemma: Why Brussels Is Cautious In Offering Support

Hungary's reliance on Russian oil has led it to seek support from Brussels to ensure continued access to this crucial en... Read more

Unveiling China's Secret Commodity Stockpiles: What Lies Ahead?

Xi Jinping's extensive reserves of grain, natural gas, and oil hint at future challenges.In a move shrouded in secrecy, ... Read more

Copper Miners Brace For Industry Overhaul As End Users Seek Direct Deals

The copper mining industry is bracing for a significant overhaul as end users, including cable manufacturers and car com... Read more