This week’s public‑sector headlines — MPs urging ministers to prepare to replace the NHS Federated Data Platform supplier, large‑scale roll‑outs of Microsoft Copilot across NHS services, and updated UK regulator guidance on AI and data — are not isolated stories. They expose recurrent commercial and governance risks that senior leaders must treat as board‑level priorities: supplier concentration, unclear data access controls and inconsistent assurance for AI systems. The policy context is active and converging; the choices leaders make now will determine whether AI frees staff time and improves outcomes, or becomes a recurring source of cost, public distrust and regulatory sanctions.
What has changed — the evidence base
Three recent developments set the context. First, parliamentary committees have publicly urged the NHS to plan for alternatives to its £330m Federated Data Platform (FDP) supplier, citing vendor lock‑in, public trust and data‑sovereignty concerns. (Parliamentary committee statements and press coverage document calls for a replacement and preparedness to exercise break clauses.)
Second, the NHS has announced an accelerated, large‑scale deployment of Microsoft 365 Copilot to clinical and support staff, a move intended to reduce administrative burden but which concentrates core productivity and AI capabilities with a major global vendor.
Third, regulators and security agencies have updated practical guidance for organisations that design, procure or operate AI systems: the ICO has published explicit AI and data‑protection guidance in the context of new Data Use legislation, while the NCSC and government collections offer secure‑by‑design principles and a voluntary Code of Practice intended to shape organisational requirements.
Taken together, these signals mean procurement, legal, cyber and data teams face near‑term pressure to show how they will manage supplier risk, operational assurance and legal compliance before any further large‑scale roll‑outs or contract extensions.
Why this matters commercially
Supplier concentration increases several commercial risks: reduced negotiating leverage on price and SLAs; operational fragility if a supplier under‑performs or exits; and reputational and regulatory exposure if suppliers’ practices undermine compliance or public trust.
For public bodies the effect is amplified because large contracts are visible, politically sensitive and often carry break clauses linked to funding or strategic milestones. The Palantir discussion is a live example: MPs have emphasised the need for transparent benefit evidence plus contingency planning — and the reputational cost of being unable to provide it.
Conversely, rapid single‑vendor adoption (for example, enterprise productivity tools with embedded generative AI) can deliver clear productivity gains — but only when procurement, data access arrangements, security and vendor commitments are concurrently tightened. If those steps are missed, projects deliver limited ROI and create downstream technical debt.
Board questions you must be able to answer in 60 days
1) What is our AI supplier map and concentration profile? Be ready to show which vendors provide core services, their contract end dates, and single points of failure.
2) What data does each supplier access, and under what legal basis? Map identifiable vs aggregated data and confirm whether access is 'read', 'copy' or 'hosted externally'.
3) Where is independent assurance for AI decisions and outputs? Require evidence of model provenance, testing, monitoring and human‑in‑the‑loop controls.
4) What contingency options exist (multi‑vendor, in‑house fallback or exit plan) and what would replacement cost look like?
If you cannot answer these at board level within 60 days, you are exposed — operationally and politically.
Practical, prioritised steps for senior leaders
1) Run a 6‑week supplier‑risk sprint. Combine procurement, security, legal and clinical/data leads to produce an actionable supplier map, evidence of benefit (usage, outcomes) and a top‑tier risk register.
2) Fix data‑access statements in contracts. Move from high‑level commitments to precise, auditable clauses that limit data access to necessary processing, require logging, and define retention and deletion.
3) Require AI assurance packs for every supplier that handles regulated data. Packs should include model descriptions, test datasets, bias and safety checks, monitoring plans and incident playbooks.
4) Operationalise NCSC secure‑by‑design recommendations and the ICO’s AI guidance as minimum pass/fail gating criteria in procurement.
5) Create a ‘red team’ verification route. Independent testing (technical and clinical where relevant) must validate supplier claims and reported benefits.
6) Negotiate multi‑homing and export‑ready data formats. Ensure you can shift workloads and extract datasets in usable formats within contract timelines.
7) Publish a short, public transparency statement for high‑risk contracts. Publish what data is used, the purpose, and the governance arrangements to rebuild trust.
Procurement implications and negotiating levers
Procurement teams must change the default commercial stance. Standard enterprise‑software deals still deliver excessive platform control to vendors. Use available levers: staged procurement, performance‑linked payment, stronger audit rights, and enforceable data portability clauses.
Regulatory attention (CMA action on business software and cloud services, updated ICO guidance) strengthens the buyer’s hand. Where suppliers resist transparency, condition contract extensions on demonstrable, third‑party assurance outcomes and public interest safeguards.

A short NHS case study: Copilot rollout and the FDP debate
The NHS example is instructive. The planned roll‑out of Microsoft 365 Copilot promises productivity gains for half‑a‑million staff, but it concentrates productivity and generative AI capabilities within the Microsoft ecosystem. Separately, parliamentary scrutiny of the Federated Data Platform supplier has focused on usage evidence and public trust. The combined lesson is simple: large gains and large risks travel together. Leaders must therefore pursue operational assurance and contingency before continuing further roll‑outs or exercising long‑term renewals.
What success looks like in 12 months
A pragmatic success profile: a published supplier map; procurement clauses updated to require AI assurance packs; at least one critical system provisioned for multi‑home or with a tested in‑house fallback; improved logging and audit capability; and a short public transparency note for the top three high‑risk systems. These are achievable outcomes and would materially reduce political, legal and operational exposure.
Final recommendation
Treat AI supplier risk as a short, sharp commercial problem that requires cross‑functional execution. Start with the 6‑week sprint described above, use regulatory guidance as a contractual framework, and make contingency planning a mandatory deliverable for any large AI or data platform contract.
Boards should no longer accept 'trust us' from suppliers. Insist on auditable AI assurance, clear data access rules and a tested exit route before you scale.
Antares recommended actions
These are Antares's recommended first actions for organisations turning the issues in this article into practical governance and delivery.
- Initiate a 6‑week supplier‑risk sprint combining procurement, legal, data and security leads to produce a supplier map and risk register.
- Mandate AI assurance packs (model provenance, testing, monitoring, incident playbooks) as a precondition for deployment when regulated data is involved.
- Add precise, auditable data‑access clauses and logging requirements to all new and renewing contracts dealing with personal data.
- Negotiate multi‑homing, exportable data formats and tested data egress capabilities to avoid lock‑in.
- Condition contract extensions or phased roll‑outs on independent verification of claimed benefits and third‑party red‑teaming.
- Adopt NCSC secure‑by‑design principles and ICO AI guidance as procurement gate criteria.
- Publish a short public transparency statement for the top three AI/data contracts to rebuild public trust.
- Train senior non‑technical leaders (boards, accounting officers) on the commercial and reputational dimensions of supplier concentration.