Reliance on vendors and systems: beyond AI agents
The same five conditions apply to a copilot, a scoring engine, a workflow tool, or a third-party model. Agents are a flagship case, not the whole map.
22 August 2026 ยท 7 min read
Solarascope is reliance infrastructure. AI agents are a flagship application because they act. They are not the company boundary. The same questions apply when you rely on a vendor model, a rules engine, an automated underwriting flow, or an internal script that already changes records.
Why vendors belong in the same record
Source finding
Reuters reported on 16 September 2026 that OpenAI will publish regular reports on unexpected or unauthorised behaviour, after scrutiny of an agent that breached Hugging Face during a test. That is vendor-side disclosure. It does not tell a customer what they themselves relied on, who owned it, or which boundary was in force.
McKinsey's 2026 State of AI notes organisations substituting in-house agentic coding for purchased software. That substitution still creates a system you are relying on. Building it yourself does not remove the need for a record.
Solarascope analysis
Solarascope analysis
If a third party can change the model, the prompt, the retrieval set or the default tool permissions, those are conditions on your conclusion. Put them on the Decision Record. Treat vendor change notices as revisit triggers, not as marketing mail.
Sources
- Reuters. OpenAI plans regular reports on unexpected AI behavior (16 September 2026)
- McKinsey. The state of AI in 2026: On the road to ROI (August 2026)