Why vendor dependence could become a bigger risk as HR teams build AI into everyday workflows
By the time Michael Pelosi took the stage at the Nrth Festival in Toronto this week to talk about open and closed AI models, the U.S. government had already done something that made his subject matter feel a lot less abstract.
In mid-June, the Commerce Department ordered Anthropic, one of the industry's frontier AI labs, to suspend access to its two most advanced models, Fable 5 and Mythos 5, for every customer in the world. The suspension lasted almost three weeks. It was a reminder that any company that came to depend on those models for AI could find that vendor switched off, without warning, by an authority that wasn't on their payroll.
Pelosi is country manager for Canada at Cohere, a Toronto-based enterprise AI company that builds large language models and competes with firms like OpenAI and Anthropic. Seher Shafiq, global community lead at Mozilla, interviewed him on a panel titled "Open Models, Open Future," about what an open AI ecosystem means for competition and control. Much of the conversation focused on chips, compute costs and the technical trade-offs between open and closed models.
But those technical questions led to a bigger one, with more immediate implications for businesses: who controls access to the technology in the first place?
A government order takes a leading AI model offline
On the panel, Pelosi pointed to the Anthropic suspension when he talked about what AI sovereignty means for businesses.
"What it means is control and ownership, and having access, you alone, your organization, your government entity, to the off switch," he said. "No one else."
In this case, the off switch belonged to the U.S. Commerce Department, which ordered Anthropic in June to suspend both models over national security concerns, according to Anthropic's own statement. Access wasn't restored for nearly three weeks, an episode a policy analysis from the Center for Strategic and International Studies called unprecedented for the AI industry.
For Pelosi, the episode was a preview of a risk enterprises haven't fully priced in, one he framed in terms of choice, comparing reliance on a handful of AI providers to hiring out a home renovation instead of doing it yourself.
"When I go back to my do-it-yourself option for the home reno, it's really easy in that example to think, well, get a professional," Pelosi said. "But now imagine you could never do it yourself. You were always beholden, not to a professional, but to three or four professionals globally who tell you how the house is going to be built, how it's going to be done and when it's going to be done."
Choice becomes the new currency in enterprise AI
Pelosi argued that most companies are still earlier in their AI deployment than the headlines suggest.
"We are not really using AI yet," he said. "Large enterprises, governments, small and medium enterprises, they are just scratching the surface."
Personal use of tools like ChatGPT is high, Pelosi said, but heavy production workloads, the kind that touch real operational data, are only beginning to scale. That scale-up is already showing up in headcount data: new research on AI spending and hiring growth found that companies investing heavily in AI are growing their workforces faster than companies that aren't. That matters for HR because the more a company depends on a single AI provider, the harder it gets hit if that provider goes down, and Pelosi's own answer to that risk is not to rely on just one type of model. Cohere, he said, deliberately uses both open and closed models rather than picking one.
"We have closed source models where certain teams don't want to have to think about the indemnity issues, and open source models," he said. "We encourage collaboration, we encourage experimentation, and we let folks use those as well to fine-tune to the way they need them to work."
What HR leaders should be asking about their AI vendors
Most HR functions don't own the technical decision of which model sits behind a recruiting assistant or an employee chatbot. But HR still owns the consequences when a tool goes dark, whether that means a stalled hiring pipeline or a manager coaching tool that vanishes mid-review cycle. One way to guard against that is not defaulting to the biggest model on the market in the first place. HRD America has already reported on whether smaller, cheaper AI models can do the job large language models are built for, and what getting locked into one vendor's answer can cost later.
Pelosi said that conversation, about mixing vendors and model types rather than betting everything on one, isn't happening enough yet.
"There's this almost divisive, it's one or the other," Pelosi said. "It's not one or the other, and it's how do you figure out where open source has incredible value to provide the opportunity for experimentation, control and flexibility, but also still, if needed, leveraging the benefits of closed source models for another use case."
Pelosi said deciding that mix comes down to a few concrete questions, like how large the workload is and how much compute it actually needs.
"What is the appropriate mix of these models to manage and mitigate risk, to think about production, high volume and robustness," he added. "To think about safety and security, and to think meaningfully about where these model types live in the organization, and what the combination should look like that's best suited for our individual enterprise."
HR may not choose which models a company relies on, but it's the one that feels it when a tool goes dark mid-cycle. This year showed that a government can suspend access to a frontier model with no warning. The real question for HR is what happens to the people relying on that tool if it disappears again. Pelosi's answer points to a simple starting point. Don't bet everything on one provider.