What happens to critical systems when a frontier model they depend on becomes unavailable?
There is a lot of research and policy activity around creating an AI kill switch. [1][2][3] The dependency chain, and what happens downstream when the switch is used, is less understood. There is some work in that area [4][5][6], but if we don't evaluate the problem thoroughly, an off-button scenario will likely have mission-critical impacts.
Who feels it
The lab controls the switch, but it only controls the model. The impact lands on everyone who built on it. Anything running on that model could stop, from business automation like support queues and SOC triage to applications that are genuinely mission-critical. An agent can stop partway through a task, leaving work half done with its credentials still active. The lab can't see any of that, and many dependent applications likely haven't planned for it.
How hard-wired things are
Of 330,153 public repositories SignalScout measures, 45,299 call a model provider's API and 71.5% of those (32,393) use only one provider, with no router or other secondary model. We see similar concentration when we filter the data: 61.2% of repos that are containerized with automated testing, and 61.7% of company-owned repos. These are public repos, and private code may look different, but it is a rough signal of how concentrated model dependencies are. [7]
What's missing
The Cloud Security Alliance has established AI provider concentration as an enterprise resilience problem [4], but the open question is whether that risk becomes systemic across everyone who depends on a widely used model. I haven't found anyone checking whether the existing guidance is followed, or adding up exposure across companies. In July 2026 the UK put four cloud providers under direct financial oversight as critical third parties but didn't include any AI model providers. [8]
A model for this already exists
There is a precedent in the Dodd-Frank Act which was created after the 2008 financial crisis to mitigate systemic risk to the banking system. [9] It requires the largest banks to submit resolution plans showing how they could be wound down in the event of material financial distress or failure. Regulators found most of those plans inadequate for years; just the act of creating these plans forced banks to consider their dependency risk. An AI version would ask a deployer what depends on the model, what happens if it disappears tomorrow, and whether that's been tested.
Next steps
The dependency chain for model disablement must be better understood. Start by evaluating a sample of mission-critical workflows for the impact of losing model access. Then build dependency simulations to estimate the wider impact on critical infrastructure and the economy if a frontier lab model were disabled. Frontier models are becoming critical infrastructure, and this work should inform the standards, regulation and playbooks that follow.