Leadership

AI Vendor Concentration Risk: What Leaders Need to Decide Before an Agentic Platform Runs Core Operations

Ryanair's five-year Google Cloud deal, built to survive an outage like Delta's 2024 one, shows why agentic AI needs a resilience plan, not just a roadmap.

You’re three days into a trek through a stretch of the Annapurna range with no signal and no road out. Before you left, you packed two of nearly everything that could strand you if it failed: two water filters, two ways to start a fire, two headlamps. Not because you doubted the first one. You packed a spare because if a single filter failure means no clean water for the rest of the trip, the whole plan hinges on one seal in one canister holding forever. Redundancy isn’t about distrust of your main tool. It’s about knowing, in advance, which failures you can shrug off and which ones end the trip.

Now, what does a water filter in the Himalayas have to do with an airline’s AI rollout? Everything, actually. In August 2026, Ryanair signed a five-year deal to run Google Cloud’s Gemini Enterprise agents across crew scheduling and operational decision-making, while keeping its existing AWS systems running in parallel rather than migrating off them. Same instinct as the trekker: build real capability into the new tool, but never let it become the only path back to a working operation.

Most companies picking an agentic AI platform still evaluate it like a software purchase: which vendor has the sharpest model, the most integrations, the smoothest onboarding. That’s a fine way to choose a tool that drafts emails. It stops being fine the moment the agent is the thing deciding which of your flight crews cover which routes tomorrow morning. At that point, a platform outage isn’t a productivity dip, it’s a grounded fleet. Ryanair’s CEO, Eddie Wilson, was explicit about the reasoning behind the deal: with the airline targeting 300 million passengers a year by 2034, “we need to ensure we have excellent infrastructure resilience,” alongside “technology partners that match our speed.” The industry’s cautionary tale sitting behind that sentence is Delta Air Lines’ July 2024 outage, a global IT failure that grounded and delayed thousands of Delta flights over several days and cost the airline hundreds of millions of dollars, precisely because so much of its operation depended on one fragile chain holding.

You might be thinking: Ryanair, an airline that charges for a printed boarding pass, just signed a nine-figure-scale bet on running two cloud providers at once. Isn’t that exactly the kind of cost duplication a discount carrier would avoid? Here’s the answer: it isn’t duplication, it’s a deliberate split. AWS keeps the existing workloads it already runs. Google Cloud gets the new agentic layer, purpose-built crew logistics agents, plus Google DeepMind’s AlphaEvolve and WeatherNext models for fleet operations and maintenance scheduling, rolled out to 35,000 staff through Google Workspace. Two vendors, two different jobs, so an outage at either one doesn’t take the other down with it.

What Ryanair is actually drawing a line between is two different kinds of AI risk. The first is capability risk: does the AI do the job well? The second is concentration risk: what happens to your operation if the vendor supplying that capability has a bad day? Most leaders only ever evaluate the first one, because it’s the one vendors pitch decks are built to answer.

Capability risk asks whether the AI is good. Concentration risk asks what happens to your business the day it isn’t there.

In my experience, procurement teams size an AI deal by the capability it unlocks and almost never by the outage it would need to survive, right up until the year they need it to.

Single-vendor AI concentrationDeliberate multi-vendor resilience
Outage exposureOne vendor’s bad day stops your operationOne vendor’s bad day, the other keeps running
System splitEverything migrates to the new platformNew agentic layer and legacy workloads live on different providers
Integration complexityLower, one set of APIs and one support lineHigher, two stacks to maintain and reconcile
Cost profileOne contract, but full exposure concentrated thereTwo contracts, but risk deliberately spread
Best fitLow-stakes AI use (drafting, search, internal Q&A)AI making or triggering operational decisions

To be fair to the single-vendor case: not every AI decision needs this treatment. An internal search tool going down for an afternoon is an inconvenience, not a crisis, and building a second stack around it is wasted resilience spending. The judgment call is knowing which AI deployments have crossed from “helpful tool” into “operational dependency,” which is the line Ryanair drew: keep AWS running the existing systems untouched, and build the new, higher-stakes agentic capability, crew logistics, fleet and maintenance scheduling, on Google Cloud, because those are the systems where an outage grounds planes. The deal’s existence and scope are independently reported by multiple outlets (Computer Weekly, The Register, Yahoo Finance); the resilience rationale and CEO quote are Ryanair’s own framing, worth flagging as self-reported motive even where the deal itself is verified fact. No public deal value has been disclosed.

So here’s the question worth bringing to your own team this week: pick the single AI-dependent decision your business would miss most if it stopped happening for twelve hours tomorrow. Do you know which vendor that decision actually depends on, and have you ever tested what happens when that vendor has a bad day, or have you just assumed the answer?

← All articles