RSS Amplifier

The Cabreza Independent · Jul 14, 2026

Model Monogamy Is an OT Problem Too

0
Sign in to vote or save

Jason Rivera · The Cabreza Independent

A specific argument moved from the fringe into the mainstream of enterprise software over the past week.

Alex Karp made it loudly, Satya Nadella made it in the language of economics, and Marc Benioff made it as product marketing.

Strip the personalities and you have the claim that: the model you rent is not the valuable part.

The value lives instead in the learning which accumulates around it, in the corrections and the rejected answers and the workflows and the edge cases that people catch.

The argument applies even more in operational technology than in IT, rather than less, and very few people in the field make it regularly enough.

Starting with what we already know, OT has spent decades inside proprietary protocols, closed historians and control systems that can’t be modified without the original manufacturer.

That means lock-in has never been a theoretical risk to an operator so much as a lived condition with a known price in narrowed options, rising switching costs and a slow transfer of leverage from the asset owner to the vendor.

I spoke about this during my s4x26 Pre-Purchase Risk Reduction session.

But two separate risks tend to get conflated :

  1. The first is leakage. A vendor retains or benefits from operational data. But zero data retention is a good answer to that.

  2. The second is evaporation: It runs quieter and, in OT, does more damage because an organization generates real judgment during AI use. An owner or operator overrides recommendations, flags unsafe suggestions or an escalation path gets exercised. If those moments disappear into chat histories or settle inside platforms outside explicit control, flawless data-retention protections won’t prevent the most valuable thing the technology produced from evaporating.

Evaporation is more impactful in OT because the engineers holding the tacit knowledge of a plant, reasons behind a setpoint, history of a failure mode and an unwritten sequence for a safe restart are retiring.

That knowledge is not being replaced at anything alike at the same rate.

AI adoption offers, among other things, a chance to capture that judgment in explicit form as humans approve, reject and correct machine behavior, which leaves the question of:

So the decision turns out to be less about privacy than about where the learning compounds.

Meaning, whether each interaction makes an internal system more differentiated and more owned, or makes an external platform more capable while leaving customers with next month’s usage bill.

This is not to argue against AI in OT. Responsible AI is a matter of design rather than posture.

The design keeps the model advising while it stays out of actuation, keeps humans and deterministic logic in the decision path, keeps provenance and outputs auditable, and keeps data inside a trust boundary the asset owner actually controls, with the model itself held to a standard and swapped when a better or safer one appears.

Each of those properties depends on independence from any single model or platform vendor, since a model welded into a vendor’s stack is no longer a supplier to be disciplined but a dependency to live with.

And it is independence that turns the model into a component build around a machine around and own, which is the principle enterprise buyers have applied to every other core system for decades.

The counterpoint is that independence can cost something, since you take on more of the integration burden and forgo the convenience of one vendor and one support line, and in general enterprise IT reasonable people land on both sides of that trade.

But not exactly, entirely or always. The application layer AI solutions lean into all of this every day and know how independence is a differentiator. AI infrastructure is swappable, interchangeable - and that is not the product.

Again, the product is the knowledge and meaning that customers gain.

In critical infrastructure I come down firmly on one side, because the thing being traded away are the safety and sovereignty boundaries of a physical process, and I don’t believe that boundary should belong inside a company whose commercial incentive is to keep it there.

Demand gets allocated dynamically and loyalty lasts only as long as the model stays competitive on capability, price and latency, so that the center of gravity moves from owning the customer to winning the workload.

For most software buyers that is an interesting shift to watch, and for an operator of critical infrastructure it reads more like an instruction to be the one who owns the machine and keep the model in the position of supplier.

Except for those who dare to not accept the marketing lines being fed from every direction, and instead trust their own instinct, judgement and courageous decision making, purse yielding power to affect change.

Read the original on cabreza.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.