AI does not enter the workflow. It becomes the workflow.
The deepest enterprise AI risk is not a bad answer or a leaked document. It is the quiet transfer of operating power from the organization to the model vendor.
A proprietary model without an exit architecture is not only a tool. It is a landlord installed inside the operating system.
Five layers of capture
Select a layer. Lock-in is cumulative: each layer makes the next easier to impose and more dangerous to reverse.
Process capture
At first, the model assists a task. Then the task is redesigned around the model. Returning to the old process would mean rebuilding roles, controls, documentation and staffing.
Dependency model
Adjust the four conditions. The result estimates how much operational leverage has shifted from the organization to the vendor.
This is a transparent governance exercise, not a validated scientific index. Its purpose is to make assumptions contestable before dependency becomes invisible.
The capture chain
Capture rarely arrives as one procurement decision. It emerges through a chain of reasonable local choices.
Convenience
The tool saves time on a visible task.
Standardization
Teams adopt the same model and interface.
Dependency
Knowledge, roles and controls are rebuilt around it.
Vendor sovereignty
Pricing, access, behavior and policy changes now shape operating capacity.
The exit test
A serious AI strategy must prove the organization can still leave. Check only controls that genuinely exist and have been tested.
First move: export prompts, embeddings, logs and process knowledge into an open, documented format.
The enterprise question is not “How much work can the model do?” It is “How much of the organization can still function when the vendor says no?”