The next major supply-chain dependency may not involve semiconductors, critical minerals, transportation capacity, or industrial components. It may be embedded inside the artificial intelligence models that companies use to build their next generation of operational systems.
Open AI models are becoming foundational components of enterprise technology architectures. Companies can download them, customize them, fine-tune them using proprietary information, and deploy them within private cloud or on-premises environments. This can lower costs, improve control, and reduce dependence on a small number of closed-model providers.
But open does not necessarily mean independent.
As a growing share of the world’s open-model ecosystem consolidates around model families developed outside the United States, companies may be exchanging one form of vendor dependence for another. The result is an emerging strategic question for supply-chain leaders: How much of an enterprise AI architecture should depend on a model ecosystem whose future development, governance, licensing, and geopolitical availability the company does not control?
That question is no longer theoretical.
The Rapid Rise of Qwen
A recent analysis by researchers affiliated with the ATOM Project found a significant shift in the open-model ecosystem. Qwen’s share of newly released fine-tunes and adaptations increased from approximately 1% in January 2024 to 69% by February 2026. Over the same period, Meta’s share declined sharply from its earlier peak.
The numbers do not mean that 69% of all enterprise AI deployments use Qwen. They measure the model families selected by developers when creating new fine-tunes, adapters, and derivative models.
Nevertheless, the trend is strategically important. Fine-tunes and derivative models represent the layer where experimentation becomes application development. They reveal where developers are placing their time, technical knowledge, datasets, integrations, and tooling.
Once a model becomes the default foundation for thousands of downstream applications, it begins to resemble a digital industrial platform. Developers build around its architecture. Software libraries optimize for it. Internal teams develop specialized expertise. Enterprises create evaluation frameworks, deployment pipelines, and governance processes around its behavior.
That produces ecosystem gravity—and ecosystem gravity creates switching costs.
This Is Not an Argument Against Chinese Models
The rise of Chinese open models should not be dismissed as the result of careless adoption or geopolitical naïveté. Many of these models are highly capable, economically attractive, and available under licenses that allow developers to modify and deploy them with considerable flexibility.
Chinese AI laboratories have also demonstrated that strong model performance does not always require the largest possible training budgets. Their progress has increased competition, accelerated open-model development, and placed downward pressure on inference costs.
For enterprises, this is broadly positive.
A manufacturer, retailer, logistics provider, or software company may be able to build useful AI capabilities using models that are less expensive to run and easier to customize than the largest proprietary alternatives. Open models can be deployed closer to operational data, adapted to industry terminology, and integrated into systems where privacy or latency makes a fully hosted service impractical.
The issue is therefore not whether companies should use Chinese-developed models.
The issue is whether companies understand the concentration risk they may be creating when a single model family becomes deeply embedded across their AI stack.
Model Dependence Is Supplier Dependence
Supply-chain organizations already know how to evaluate dependence on a critical supplier. They examine substitution difficulty, geographic concentration, financial stability, production capacity, transportation exposure, regulatory risk, and the time required to qualify an alternative.
A foundational AI model should increasingly be evaluated in the same way.
Consider what happens when a company builds an operational application around a particular model family. The company may create:
Retrieval pipelines optimized for that model
Fine-tuned adapters trained on internal data
Prompt libraries and system instructions
Evaluation benchmarks
Security controls
Model-specific deployment infrastructure
Agent workflows
Integration logic
Employee expertise
Governance and approval processes
The model itself may be freely available, but the surrounding implementation is not free. It represents accumulated investment and organizational learning.
Replacing the model could require revalidating the entire application. Outputs may change. Tool calls may behave differently. Safety controls may need to be redesigned. Fine-tunes may not transfer cleanly. Performance may deteriorate in specialized tasks.
This is exactly what makes a supply source strategically important: not simply the cost of the item, but the cost and operational disruption associated with replacing it.
The Risk Is Broader Than Model Access
The most obvious geopolitical scenario would involve export restrictions, sanctions, licensing changes, or government intervention that affects the availability of a model. But that is only one category of risk.
Enterprises should also consider the broader ecosystem surrounding the model.
Who maintains the underlying architecture? How transparent is the training and post-training process? Where do security updates originate? Which organizations control the primary repositories? How rapidly can vulnerabilities be identified and corrected? What happens when the model’s commercial sponsor changes priorities?
Open weights can reduce dependence on a hosted provider, but they do not eliminate dependence on upstream research, tooling, documentation, and developer communities.
There is also a provenance problem. A company may download a derivative model that has passed through several rounds of fine-tuning by unknown parties. Each stage may alter the model’s behavior, security characteristics, or susceptibility to manipulation.
This does not mean derivative models are inherently unsafe. It means enterprises need stronger software-supply-chain disciplines for AI.
A model should have a traceable lineage. Organizations should know where it originated, who modified it, which datasets were used when that information is available, how it was evaluated, and whether the artifact has been altered since publication.
The same principles behind a software bill of materials will increasingly apply to models, adapters, embeddings, agent tools, and AI-generated code.
AI Sovereignty Is an Architectural Question
AI sovereignty is often discussed at the national level. Governments want domestic access to computing infrastructure, semiconductors, data, talent, and foundational models.
But sovereignty also matters at the enterprise level.
An organization has greater AI sovereignty when it can preserve operational continuity, move between model providers, control its proprietary context, and replace components without rebuilding the entire system.
This does not require every company to train its own large language model. For most businesses, doing so would be economically irrational.
It does require enterprises to avoid architectures in which the model becomes inseparable from the application.
The model should be treated as a replaceable intelligence component rather than the permanent center of the technology stack.
That means separating the model from:
Enterprise data
Business rules
Workflow orchestration
Tool definitions
Security controls
Evaluation datasets
User interfaces
Audit trails
Operational decision rights
This separation is becoming more practical as AI architectures mature.
Retrieval-augmented generation can keep proprietary knowledge outside the model. Graph-enhanced retrieval can provide structured relationships among suppliers, facilities, products, orders, shipments, and disruptions. Model Context Protocol servers can standardize access to data sources and tools. Agent-to-Agent protocols can help specialized agents exchange tasks and information.
Together, these technologies can create an abstraction layer between the foundational model and the operational system.
The enterprise then owns the context, integrations, workflows, and governance—even when it changes the model providing the underlying reasoning capability.
Supply-Chain Leaders Should Demand Model Portability
Technology teams often evaluate models based on benchmark performance, speed, inference cost, and ease of deployment. Those factors matter, but they are incomplete.
Supply-chain leaders should add portability and concentration risk to the evaluation.
Key questions include:
Can the application operate with more than one model family?
A production system should be tested against at least one credible alternative. This does not mean every model will produce identical results. It means the organization understands the effort required to switch.
Is proprietary knowledge stored outside the model?
The more enterprise knowledge is embedded exclusively within a model-specific fine-tune, the harder it may be to migrate.
Are tools and integrations exposed through standardized interfaces?
Model-specific integration code increases lock-in. Standardized APIs, schemas, and protocols make substitution easier.
Does the company maintain independent evaluation datasets?
Enterprises should own the tests used to determine whether a model performs adequately. Vendor benchmarks are not a substitute for operational validation.
Can the organization trace the model’s provenance?
The company should know the model’s source, version, license, modification history, and approval status.
What is the fallback plan?
Critical AI-supported workflows need a defined alternative, which may include another model, a rules-based process, or a human-controlled operating procedure.
How much of the architecture depends on one geopolitical jurisdiction?
This question should include models, cloud infrastructure, chips, development tools, and key software libraries.
Diversification Does Not Mean Fragmentation
Enterprises should not respond by deploying dozens of models without discipline. Excessive variety creates its own costs, including inconsistent outputs, fragmented governance, duplicated infrastructure, and greater cybersecurity exposure.
The objective is not maximum model diversity. It is controlled optionality.
A company may designate one preferred model for a class of tasks while validating one or two alternatives. It may use smaller specialized models for forecasting explanations, transportation exceptions, supplier-risk analysis, or document processing. It may use a larger proprietary model for complex reasoning while keeping an open model available for continuity, privacy-sensitive workloads, or cost control.
This resembles a well-designed sourcing strategy. The organization does not qualify every possible supplier. It identifies where single sourcing is justified, where dual sourcing is necessary, and where standardization creates more value than redundancy.
The United States Faces an Open-Model Policy Dilemma
The enterprise challenge reflects a larger national issue.
American technology policy has strongly supported advanced semiconductor controls and domestic computing infrastructure. But the open-model ecosystem cannot be secured through hardware policy alone.
If American developers increasingly build on foreign model foundations, the United States may retain strength in chips, cloud platforms, and frontier proprietary models while losing influence over the open development layer.
Restricting access to foreign open models would carry significant costs. It could reduce competition, slow innovation, and push developers toward less transparent distribution channels. It could also disadvantage smaller companies that benefit from inexpensive, capable models.
A more productive response would be to strengthen the competitiveness of American open models.
That could include support for open-model research, shared evaluation infrastructure, high-quality public datasets, secure model-distribution systems, and incentives for universities and companies to release commercially usable model families.
Dean Meyer and Konstantine Buhler, whose analysis helped elevate this debate, have also argued for stronger American capabilities in controlled post-training and model adaptation. That direction deserves attention. The strategic contest may not be determined solely by who trains the largest foundational model, but by who creates the most useful ecosystem for adapting models to real operational work.
The Supply Chain Is Moving Inside the Model Stack
Supply-chain risk management has historically focused on physical flows: materials, components, factories, ports, carriers, and inventory.
Enterprise AI adds a new layer.
The organization now depends on model weights, training frameworks, vector databases, orchestration tools, APIs, data pipelines, agent protocols, and cloud infrastructure. These components form a digital supply chain that can be concentrated, disrupted, compromised, or politically constrained.
The rise of Qwen and other Chinese open models should be understood in that context. Their growth is evidence of technical and commercial success. It is also a warning that the open-model ecosystem is consolidating faster than many enterprises realize.
The correct response is neither prohibition nor complacency.
Companies should use the strongest tools available while preserving the ability to change them. They should treat model provenance as a governance issue, portability as an architectural requirement, and concentration risk as a supply-chain concern.
Open models can reduce dependence on proprietary AI providers. But without deliberate architecture and sourcing discipline, they can also create a new strategic dependency beneath the surface of enterprise operations.
The companies that understand this distinction will not merely adopt AI faster. They will build AI systems that remain resilient when the technology market, vendor landscape, or geopolitical environment changes.
The post Open Models, Strategic Dependencies: Why AI Sovereignty Is Becoming a Supply Chain Issue appeared first on Logistics Viewpoints.