March 13, 2026 · Kealu Vector Team · Research
Research across 1.17M URLs in 61 countries reveals dangerous infrastructure consolidation patterns now repeating in enterprise AI.
The Internet has a concentration problem. And enterprise AI is about to inherit it.
New research from Northwestern University&039;s AquaLab , led by our own Chief Scientist, Prof. Fabian E. Bustamante , has mapped the consolidation of critical web infrastructure across 61 countries and 1.17 million URLs. The findings are striking: the top three providers serve an average of 92% of all traffic. The median number of DNS providers per government? One. A single point of failure for entire national infrastructures.
The Consolidation Watch research analyzed DNS resolution, CDN distribution, and certificate authority dependencies for government web properties across 61 nations. The methodology was rigorous: 1.17 million URLs, systematic crawling, cross-referencing third-party dependencies against commercial ecosystems in each country.
Consolidation is pervasive. Across every country studied, a small number of providers dominate critical services. Three providers handling 92% of traffic is not an outlier. It is the norm.
The research distinguishes between two types of consolidation. Some countries consolidate because their local ecosystem offers few alternatives , "constrained" consolidation. Others consolidate deliberately, choosing global providers even when local options exist , "strategic" consolidation.
Most importantly: strategic consolidation does not produce more resilient infrastructure. Speed improves , 43% faster latency on average. Resilience does not.
Now apply this framework to enterprise AI.
Today, the majority of enterprise AI workflows route through two or three cloud providers. OpenAI, Anthropic, and Google handle the vast majority of commercial LLM traffic. For many organizations, the entire AI stack depends on a single vendor&039;s API.
Consider what happens when your AI orchestration depends entirely on one provider. A rate limit change affects your throughput. A pricing update restructures your unit economics. A policy modification around data handling forces you to re-architect. A regional outage takes your AI capabilities offline. Every one of these has occurred in the past 18 months.
The coding agent market illustrates the acceleration. Cursor reached a $29 billion valuation. Cognition&039;s Devin raised at $10.2 billion. These are extraordinary growth rates, but every one of these platforms is cloud-only, single-provider dependent, and offers zero on-premise deployment capability.
For a hospital system processing patient data, a defense contractor handling classified workflows, or a financial institution subject to data residency requirements, this concentration is not acceptable.
Organizations consolidate because it appears simpler. One vendor means one contract, one integration, one support relationship. The initial deployment is faster. The learning curve is shorter.
This is the same logic that led governments to route 92% of their traffic through three providers. It works , until it doesn&039;t.
The efficiency gains of consolidation are real but shallow. They apply to the deployment phase. They do not apply to the resilience phase, the compliance phase, or the adaptation phase.
Switching costs don&039;t start high. They become high. Prompts are optimized for one model&039;s behavior. Workflows are tuned to one provider&039;s latency profile. Quality benchmarks are calibrated to one model&039;s output patterns. By the time an organization recognizes the lock-in, the cost of migration often exceeds the cost of staying.
For enterprises in regulated industries, consolidation risk intersects with four structural barriers that make AI adoption fundamentally different from consumer applications.
The alternative to consolidation is not fragmentation. It is orchestration. Multi-model orchestration means the ability to route AI workflows across multiple model providers based on the requirements of each specific task. This requires three capabilities. First, model-agnostic execution across Claude, GPT, Gemini, open-source models, and any future model. Second, deployment flexibility , the same engine running in public cloud and on-premise or air-gapped. Third, quality gates , automated checkpoints that validate AI output before production. Kealu Vector is built around those three capabilities. If you are responsible for AI infrastructure at a regulated enterprise, three immediate actions: The question is not whether consolidation is a risk. The research has answered that. The question is whether your organization will address it before or after the consequences arrive.What Multi-Model Orchestration Actually Means
What CTOs Should Do Now
Related articles