Written by: Kamil Ponicki, Director of Talent Acquisition, Digital Colliers
Anthropic signed a $45B compute deal with Nscale this month. Stack that on top of the Amazon, Google, and Oracle commitments already announced, and you're looking at a model vendor whose forward compute obligations sit north of most G-SIB technology budgets. If your bank runs Claude in production, or in a proof-of-concept that anyone in the business now depends on, that is your problem too.
This isn't a story about whether Anthropic is a good company. It's a story about what your third-party risk team is supposed to do when a vendor's balance sheet is structurally unknowable, and the regulator has already told you the answer isn't "trust the brand."
The number you actually have to explain
Aggregate the public Anthropic commitments and you get a compute book that dwarfs the annual IT spend of most banks buying its API. The Nscale deal alone is $45B. Add the prior hyperscaler agreements and the shape is clear: revenue has to grow into these obligations, or someone rewrites them, or the counterparty gets restructured.
Any of those three outcomes is a vendor event for you. Restructuring changes contract terms. Renegotiated compute changes latency and price. Growth pressure changes model behaviour, safety posture, and the rate at which endpoints get deprecated under you. None of that is hypothetical, and none of it shows up in a SOC 2 report.
Why DORA already made this your problem
DORA has been in force since 17 January 2025. If you're a financial entity in scope, you owe the regulator a live register of ICT third-party arrangements, concentration analysis, exit plans, and evidence you've actually tested them. "Critical or important function" is the trigger, and a model provider embedded in credit decisioning, KYC narrative generation, or client comms clears that bar without much argument.
Layer on the EU AI Act. Article 50 transparency obligations bite from 2 August 2026. High-risk obligations follow on 2 December 2027, with fines up to €15M or 3% of global turnover for the worst violations. GDPR is still sitting there at €20M or 4% for the data-handling piece underneath. The compliance surface is not the model output. It's the vendor relationship producing the output.
A vendor-viability data model for AI
Most banks are still assessing model vendors with a security questionnaire and a chat with procurement. That is not going to survive a DORA inspection, and it definitely won't survive a vendor stress event. The pattern that holds up looks more like a live data model with roughly these fields, refreshed monthly:
- Financial runway signal: disclosed funding, disclosed compute commitments, ratio of commitments to trailing revenue, known customer concentration.
- Compute dependency graph: which hyperscalers and neoclouds sit under the vendor, and what your own hyperscaler exposure looks like once you collapse the graph.
- API stability telemetry: deprecation notices in the last 12 months, average lifetime of a model version, breaking-change frequency per endpoint you actually call.
- Contractual exit posture: notice periods, data portability terms, model weight escrow if any, and the identity of the backup vendor you've actually integration-tested.
- Regulatory exposure: which of your use cases are AI Act high-risk, which touch automated decisioning under GDPR, which sit inside a DORA critical function.
- Substitutability score: for each production use case, hours of engineering work to swap to the second-choice model with acceptable quality loss.
The point of the model isn't the score. The point is that when the vendor event happens, and something will happen across a book this size, you already know which use cases move first, which contracts you can invoke, and which regulator conversation you're going to have.
The left-behind risk
Around 95% of enterprise AI projects never reach production or ROI. The ones that do are increasingly the load-bearing bits of customer journeys and internal ops. Banks that treat model vendors as SaaS and rely on brand comfort will spend 2026 explaining to supervisors why their concentration register is a PDF.
The ones building the data model above will spend 2026 negotiating better contracts, because they can actually show, in numbers, what their exposure is. That's the gap opening up right now, and it's the one worth closing before the next mega-deal announcement makes the maths worse.

