Swati Deepak Kumar is Senior Vice President of Information Technology at Citi.
Enterprises have spent years diversifying their technology. A company may use different applications for sales, procurement, customer service, software development, supply chain and legal work, each from a different vendor. At face value, that portfolio looks diversified.
But what if several of those applications are effectively thinking with the same brain?
Different software vendors may be using the same foundation model, model family, API, compute provider or AI ecosystem. We’ve diversified the applications while potentially concentrating the intelligence that powers them.
I call this cognitive concentration. It’s a proposed management lens, not an established regulatory term. Different applications can look independent while still relying on the same underlying knowledge system.
Why This Differs From Traditional Concentration Risk
As technology leaders, we already understand vendor, cloud and data concentration. When many workflows depend on a single vendor and it goes down, or most applications run through the same cloud provider and a region fails, systems simultaneously stop working. That system failure is immediately visible.
Cognitive concentration presents an even greater challenge because adverse changes can go unseen for an indeterminate amount of time. The system may remain operationally green and seemingly unchanged while the judgments it produces have been affected. While vendor concentration can shut down the system, cognitive concentration can leave the system running while decisions become correlated.
In a 2024 survey of 118 financial firms, the Bank of England and Financial Conduct Authority (FCA) found that the top three third-party providers accounted for 73% of reported cloud providers and 44% of model providers. The survey also found that 55% of AI use cases involved some automated decision-making, although only 2% were fully autonomous.
Members of the Bank of England and FCA’s AI Consortium have discussed how the same or similar models, even across different vendors, could create correlated errors and propagate flaws across institutions. These were members’ views, not regulatory policy, but they illustrate why leaders need to look beneath product names and evaluate the models they utilize.
Concentration Becomes A Problem When Consequences Rise
Cognitive concentration itself isn’t inherently bad. I am not suggesting that organizations adopt dozens of models simply to create the appearance of diversity. Understanding the risks of cognitive concentration is of greatest importance in the areas of your business where concentration intersects with consequence and weak substitutability.
For example, a low-risk marketing application with no fallback may be acceptable. But if procurement and supply-chain platforms use the same underlying model, have no fallback and require a long switching period, the priority becomes more critical. The same is true of high-risk workflows, such as lending, underwriting, trading, pricing, cybersecurity or production changes.
The higher the consequence of a correlated failure, the stronger the case for cognitive diversification and resilience. That is the decision principle CIOs need.
What Leaders Should Do Now
Map the AI dependencies behind critical applications. Rank workflows by consequence. Fund fallback capability first where concentration and criticality are high, and measure switching time in a real test rather than assuming a backup contract equals resilience.
For selected high-impact workflows, a genuinely independent model can act as a shadow evaluator, periodically challenging the primary model’s output. Major model changes should be staged and tested before they affect every dependent process. Difficult-to-reverse decisions also need strong controls, such as human review, deterministic rules, a traditional model or another independent validation mechanism.
The current evidence should be kept in perspective. In April 2026, the Bank of England’s Financial Policy Committee found that advanced AI had not yet been adopted in a way that presented systemic risk but warned that risks could increase rapidly as deployment expands.
Why now? Architecture choices are easier to change before dependencies become deeply embedded. Cognitive diversity is about knowing where shared intelligence exists, where a correlated failure would matter and how quickly the organization could respond if a model becomes problematic. As AI participates in more enterprise decisions, understanding what intelligence our systems share may become as important as understanding which technology vendors we use, making the Cognitive Concentration Index (to be discussed in my next article) of even greater importance.
The objective is not model diversity. It is decision resilience.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?


