Written by: Michał Sobieraj, Operations Manager, Digital Colliers
Mistral just went from research lab to infrastructure company overnight. The €3B raise at a €21B valuation signals they're building a GPU cloud, not just shipping weights. If you're running open models in production for product recs, search, or support, you need to run a dependency audit this quarter.
The pattern is familiar. A scrappy model shop earns your trust, you fine-tune their weights, you ship to production. Then they raise a war chest and pivot upmarket. Suddenly the model you deployed six months ago sits on infrastructure you don't control, and the support contract you thought covered weights now assumes you're renting their metal too. In a market where 88% of AI proof-of-concepts never reach widescale deployment, vendor lock-in adds a second failure mode on top of technical risk.
Model Provenance: Who Actually Owns What You Tuned
Start with the weights themselves. Most teams grab a checkpoint from Hugging Face, fine-tune on labeled tickets or transaction logs, and call it done. The question isn't whether you own the fine-tuned adapter layers. You do. The question is whether the base model license lets you move those weights to a different inference stack without retraining.
Check the model card. If the license includes field-of-use restrictions or mandates the vendor's API for commercial deployment, you've got exposure. Some open-weight licenses let you run anywhere. Others define open as open to download, closed to port. The difference matters when your vendor starts charging enterprise GPU rates.
Document where your training data lives. If you fine-tuned on the vendor's managed platform, do you have a cold export? Can you pull the dataset and retrain on Replicate or Modal without breaking copyright or NDA terms? Most ops teams skip this step because the vendor made training frictionless. That convenience becomes a moat the day you want to leave.
Inference Location: Whose Metal Runs Your Model
Next, map where inference actually happens. If you're calling an API, check whether the vendor owns the data center or resells someone else's capacity. The failure mode isn't the vendor going under. More than 80% of AI projects fail, but the vendors usually get acquired. The failure mode is them repricing you 300% because their cost structure shifted and you're too small to negotiate.
Look at your request logs. How many inferences do you run per day? What's your p99 latency? If the vendor starts throttling free-tier users to push everyone onto reserved capacity, can you absorb the cost jump or do you need to rearchitect? Retail ops teams often build product features assuming inference stays cheap. When the unit economics flip, the feature becomes a P&L liability. Given that 95% of enterprise GenAI pilots deliver zero measurable P&L impact, adding vendor repricing risk on top makes the math even harder.
Run a failover drill. Spin up the same model on a different provider and route 1% of traffic for a week. Measure latency, accuracy, and cost. If the delta is acceptable, you've got real optionality. If it breaks, you're locked in, and the vendor knows it.
Fallback Plan: Can You Move Without Retraining
The hard part isn't moving the model. The hard part is moving without losing the fine-tuning work. If your adapter layers assume a specific tokenizer or 128k context window that only exists in one vendor's fork of the base model, you can't port cleanly. You'll retrain from scratch, which means re-labeling data, re-running evals, and re-validating compliance checks.
Test portability while the vendor relationship is still good. Export your fine-tuned weights. Load them onto a competitor's infrastructure. Run your eval suite. If accuracy drops more than two percentage points, you've got a portability tax. Budget for it now or accept that switching costs will spike later.
Document your preprocessing pipeline. If you're doing custom embeddings or RAG lookups before the model sees the prompt, that logic needs to travel with you. Most teams store it in a monorepo that's tightly coupled to the vendor's SDK. Decouple it. Write a thin adapter layer that swaps providers without touching business logic.
The Ops Checklist
Before your next vendor renewal, walk through this:
- Pull the base model license and confirm you can run those weights anywhere.
- Export your fine-tuning dataset and confirm you own it outright.
- Spin up the model on two different providers and compare cost and latency.
- Run a week-long A/B test splitting 1% of traffic to the backup stack.
- Document every preprocessing step and confirm it works provider-agnostic.
- Schedule a quarterly review. Vendor strategies shift faster than annual contracts.
The Mistral raise isn't a crisis. It's a forcing function. Retail ops teams running AI in production need to audit dependencies the same way they audit payment processors or CDN providers. The model is critical infrastructure now. Treat it that way.

