AI value chain

Where AI risk accumulates in the chain

A map of the AI value chain, from compute to application: locate single points of failure, measure the cascade and the systemic exposure of a dependency. 100% in the browser, all parameters and sources shown.

~65%
Share of the top three providers in the global cloud market.
Synergy Research
SPOF
Single point of failure: a layer whose outage brings down the whole chain.
Resilience engineering
silent
Invisible accumulation: distinct insureds share the same upstream dependency.
Cyber reinsurance
correlated
One upstream outage can hit thousands downstream at once.
Systemic risk

Concentration by layer

For each layer, your level of dependency.
Compute & chips
Cloud & infrastructure
Foundation model
Orchestration & integration
Business application
DiversifiedConcentratedSingle dependency
Systemic exposure
77 / 100
Fragile
0 = diversified, resilient chain; 100 = everything rests on single dependencies.
Value chain
Each layer is coloured by its risk. A failure propagates downstream.
Compute & chips
Concentrated
Cloud & infrastructure
Single dependency
SPOF
Foundation model
Single dependency
SPOF
Orchestration & integration
Diversified
Business application
Concentrated

Layers & criticality2 SPOF

Compute & chipsConcentrated
Cloud & infrastructureSPOF
Foundation modelSPOF
Orchestration & integrationDiversified
Business applicationConcentrated

Layers whose failure alone interrupts the chain:

Fragile
The reinsurer's read

Systemic accumulation

Several critical layers rest on a single dependency. One upstream failure can bring down the whole chain and, in reinsurance, hit thousands of insureds at once.

Resilience levers
  • Cloud redundancy: multi-region and, where possible, multi-provider for the infrastructure layer.
  • Model portability: plan a fallback model and an abstraction that allows switching.
  • Contractual recourse: SLAs, step-in rights, reversibility and documented exit.

Cascade

Cascade radius
4 / 5

A failure at the "Cloud & infrastructure" layer propagates to 4 downstream layer(s): that is the cascade radius, the heart of accumulation risk.

Layers taken down downstream
  • Cloud & infrastructure
  • Foundation model
  • Orchestration & integration
  • Business application
The reinsurer's read

In liability, allocation follows the chain: the upstream provider is in principle answerable for defects in its layer, the downstream deployer for its use. Contracts (SLAs, caps) and the AI Act redistribute this burden, often against the least-equipped downstream layer.

How it is calculated
Model parameters
Systemic exposure77/100
Single points of failure2
Cascade radius4/5
Sources & calibration
Orders of magnitude; layer criticality calibrated on market structure, plus:
Uptime Institutesource →OCDE, politiques de l'IAsource →Stanford HAI, AI Indexsource →Data Center Mapsource →
Assumptions & limits
  • Layer risk = systemic criticality (fixed weight) x concentration factor (your dependency).
  • Single point of failure: a layer whose risk exceeds the critical threshold.
  • Cascade: a failure at the most upstream failing layer propagates to all downstream layers.
  • Systemic exposure: normalised weighted average of layer risks (0 to 100).
  • An architecture model, not an audit: real resilience depends on redundancy, contracts and recovery plans.
Go further
Measure a book's concentration with the accumulation assessor →

Order-of-magnitude model, for educational and framing purposes. It is neither an architecture audit, nor a continuity assessment, nor an insurability opinion. No provider is named: only the concentration level you declare is modelled. Neither advice nor pricing.