Published on 15 September 2026
The recent coincidence of availability issues affecting several of the leading artificial intelligence platforms has once again brought an important question to the forefront, one that organizations will need to address sooner rather than later: what happens when business processes start depending on AI that simply becomes unavailable.
Artificial intelligence is being incorporated into organizations at a pace that is difficult to compare with any other recent technological transformation. In just a few years, we have moved from experimenting with generative models to integrating them into software development, customer service, information analysis, operations, automation and, of course, cybersecurity.
This month served as a reminder of what such dependence could mean.
Several major AI platforms experienced availability issues at almost the same time. ChatGPT and Codex suffered incidents acknowledged by OpenAI; Claude also experienced infrastructure problems; and Grok underwent a significant outage.
The timing quickly sparked all kinds of interpretations, ranging from the existence of a shared technological dependency to the possibility of a coordinated incident.
At this stage, there is no public evidence supporting either of those hypotheses. The known explanations, in fact, point to different causes.
But perhaps that is not the most important question.
Are we prepared for the moment when the artificial intelligence on which our processes depend simply becomes unavailable?
From Productivity Tool to Business Infrastructure
Until relatively recently, an outage affecting an AI platform had a limited impact.
A professional might be unable for a few hours to use their assistant to draft a document, analyze information, generate code or answer a question.
Fundamentally, it was a productivity problem.
But we are rapidly entering a different reality.
AI is increasingly embedded within applications, platforms and business processes. The arrival of AI agents will accelerate this transformation even further.
Agents will not simply answer questions. They will execute actions, query systems, analyze information, make certain decisions and coordinate entire processes.
This means that AI unavailability may cease to affect only the user and begin to directly impact the process itself.
And at that point, the nature of the risk changes completely.
Consider, for example, a cybersecurity operations center.
SOCs are progressively incorporating artificial intelligence to support alert triage, data enrichment, threat intelligence, incident investigation, query generation, vulnerability analysis and the automation of specific response processes.
Now imagine that a significant part of that chain depends on a particular AI model.
What happens if that model stops responding for one hour? Or for four? Is there an alternative model available? Can the process continue without AI? Do we know which functions will be degraded? Can we recover tasks that were in progress when the interruption occurred?
These questions may seem highly technical today, but soon they will become business continuity questions.
A New Technological Dependency
For decades, we have learned to design architectures with availability in mind.
We built redundancy into data centers, communications networks, storage systems, critical infrastructure and cloud providers. We developed business continuity plans, disaster recovery strategies and contingency mechanisms.
However, there is a risk that we are integrating AI into critical processes without applying those same principles with sufficient maturity.
And the challenge may become even greater with agent-based architectures.
An agent may depend on a model, but also on APIs, databases, external tools, identities, MCP systems and other agents.
The technology chain is becoming increasingly complex.
Therefore, we should no longer ask only whether our AI provider is available.
We must understand what happens to the entire process when any dependency required by that AI becomes unavailable.
Resilience must be designed from the outset.
The Two Conversations We Are Already Having
From a cybersecurity perspective, we are currently focused on two main dimensions of artificial intelligence.
The first is Security for AI.
In other words, how we protect AI itself.
This includes topics such as model and data protection, agent security, machine identities, APIs, prompts, credentials, new MCP-based architectures and the risks associated with connecting enterprise systems to external models.
It is a vast territory that we are only beginning to explore.
The second dimension is AI for Security.
How we use artificial intelligence to improve our cybersecurity capabilities.
The opportunities are equally significant.
SOC automation, incident investigation, threat intelligence, threat detection, vulnerability analysis, code generation and review, offensive security, GRC and incident response are just some of the areas undergoing rapid transformation.
But I believe we need to start incorporating a third dimension.
AI Resilience
We could call it AI Resilience: the ability of organizations to maintain their processes when the artificial intelligence they rely on is unavailable or operating in a degraded state.
And it will likely become one of the fastest-evolving areas in the coming years.
Enterprise architectures will need to consider multi-model and, in some cases, multi-provider strategies.
If a process can operate using different models, the temporary unavailability of one should not necessarily bring it to a halt.
We will also need fallback mechanisms capable of redirecting certain operations to alternative models.
For some critical functions, it may even make sense to maintain local models capable of preserving minimum operational capabilities when external services are unavailable.
But resilience is not simply about having another model ready.
We will need observability.
Organizations must be able to understand in real time which agents are running, which models they are using, what dependencies they have, what operations they are performing and what impact the unavailability of any of those components may have.
Controlled degradation mechanisms will also be required.
A system should know which functions can continue operating when specific AI capabilities are lost and which must stop.
And, of course, there remains something that is sometimes forgotten amid the race toward automation: alternative operating procedures.
Because automating a process should not mean losing the ability to operate when automation fails.
The Concentration Risk
There is another issue that deserves attention.
The market for large AI models is extraordinarily concentrated.
Thousands of organizations are building applications, agents and processes on top of a relatively small number of providers.
This delivers major efficiencies but also creates new forms of technological concentration.
The phenomenon itself is not new.
We have seen it before with cloud computing, telecommunications, specific software vendors and critical Internet infrastructure.
The difference is the speed.
We are embedding AI into business processes much faster than we built many of the technological architectures that preceded it.
And that speed may lead us to create dependency first and only later think about how to manage it.
We should strive to do the opposite.
From Technological Availability to Business Risk
Artificial intelligence is gradually ceasing to be just another tool.
It is becoming a new infrastructure layer on which increasingly important business processes will be built.
And when a technology becomes part of an organization's infrastructure, its availability is no longer solely the responsibility of the technology department.
It becomes a business risk.
Boards of directors, risk managers, CIOs, CISOs and business leaders will need to understand which processes depend on artificial intelligence, what the impact of its unavailability would be and which mechanisms are in place to guarantee continuity.
Exactly as we have done for years with other critical technology services.
Perhaps, a few years from now, it will seem strange that we ever deployed AI agents without first analyzing their continuity requirements.
At that point, the evolution of cybersecurity around artificial intelligence may be summarized through three major dimensions:
- Security for AI. Protecting artificial intelligence.
- AI for Security. Using artificial intelligence to protect ourselves more effectively.
- And a third dimension that is rapidly becoming essential: AI Resilience. Ensuring that organizations can continue operating when artificial intelligence itself comes to a stop.
Because AI will become increasingly capable. But it will still be technology. And every technology, sooner or later, fails.






