Deloitte Launches a Practice to Help CIOs Stop Betting Everything on One AI Model Vendor
Digital Transformation

Deloitte Launches a Practice to Help CIOs Stop Betting Everything on One AI Model Vendor

Deloitte's new Open Model Engineering practice is built to help enterprises mix open and proprietary AI models instead of locking into a single vendor's stack.

PublishedSeptember 6, 2026
Read time6 min read
Share

The single-vendor AI bet is starting to look risky

Deloitte has launched a new Open Model Engineering practice across its global member firms, an explicit response to a problem many CIOs are only now naming out loud in board meetings: concentrating an entire agentic AI roadmap on one proprietary model vendor concentrates risk in ways that finance and procurement teams have grown increasingly uncomfortable with over the past year. The initial rollout covers North America, Europe, and Asia Pacific, three regions where enterprise AI spending has scaled fastest and where regulatory scrutiny of data handling practices has correspondingly tightened.

Deloitte plans to hire, train, and certify forward-deployed engineers for the practice through fiscal 2027, a timeline that matters because it signals staffing commitment tied to a multi-year enterprise AI deployment cycle rather than a marketing wrapper thrown around existing consulting work. Building a certified bench of engineers who can work across both open and proprietary model architectures takes years, not quarters, and Deloitte appears to be planning around that reality from the outset.

Four problems the practice is built to solve

Deloitte frames the practice around four deployment considerations that enterprises keep running into as they scale agentic AI past the pilot stage. Model flexibility means choosing the architecture best suited to a given workload instead of forcing every use case through a single vendor's model. Cost predictability addresses getting control of token economics that have made AI spend difficult for finance teams to forecast a quarter ahead, let alone a fiscal year. Data sovereignty covers where inference physically happens and how sensitive data is handled during that process. Competitive protection focuses on keeping proprietary intellectual property out of a vendor's training loop entirely.

Deloitte positions these four as interdependent rather than separate checkboxes, arguing that a model strategy optimized for cost alone tends to quietly undermine sovereignty or protection commitments made elsewhere in the same organization. Treating the four together, rather than sequentially, is the part of the framework Deloitte says most clients get wrong on their first attempt at a mixed-model rollout. Nitin Mittal, Deloitte's global AI leader, said open models increasingly complement proprietary platforms, enabling mixed-model approaches while optimizing choices across the AI stack for cost, performance, and control simultaneously. That framing represents a materially different pitch than the all-in cloud AI narrative most enterprises heard consistently through 2024 and much of 2025, when standardizing on a single frontier model provider was the default recommendation from most major consultancies.

Nvidia's fingerprints are all over the technical foundation

The practice runs on Nvidia's Nemotron open models and NIM microservices, integrated directly with Deloitte's own Zora AI digital workforce platform to deliver agentic capabilities across client environments. Kari Briski, Nvidia's vice president of generative AI, said enterprises need both open and proprietary models depending on the workload, along with greater control over data handling and secure deployment paths for regulated industries in particular. For CIOs, the practical upside is a hardware and software stack that does not require ripping out existing Nvidia infrastructure investments to add a second or third model provider into the mix, which lowers the switching cost of experimenting with additional models considerably compared with a full platform migration.

That framing is obviously convenient for Nvidia, which benefits regardless of which model an enterprise ultimately chooses so long as it keeps buying compute to run it. It also reflects a real technical shift worth noting: open-weight models have closed much of the capability gap with proprietary frontier models over the past year, making a mixed-model architecture financially defensible on its own merits rather than a compromise enterprises settle for while waiting for something better. That matters most for teams already deep into a single vendor's ecosystem who worry that any diversification effort means starting the infrastructure build over from scratch, and it shortens the internal approval cycle needed to greenlight that kind of experimentation in the first place.

What this means for governance and procurement

For CIOs and CTOs, the practical shift this creates lives mostly in procurement architecture. A mixed-model strategy requires governance frameworks, security review processes, and vendor contracts that can accommodate swapping models per workload, rather than standardizing everything on a single platform's terms of service, data handling commitments, and pricing structure negotiated once and left in place for years. That means legal and security teams need standing playbooks for onboarding a new model quickly, not a one-off review process built for a single annual vendor decision.

That is a heavier governance lift up front, requiring security and legal teams to review multiple vendor relationships instead of one consolidated agreement. It directly addresses the vendor concentration risk that has made boards nervous about AI spend commitments tied entirely to a single provider's roadmap, pricing changes, and long-term strategic direction, none of which any individual enterprise customer has meaningful influence over on its own regardless of contract size or negotiating leverage.

Why this lands differently for PE-backed operators

Portfolio companies under private equity ownership face a specific version of this exposure: buyer due diligence increasingly asks precise questions about where AI inference happens and what happens to sensitive data during that process, and a single-vendor commitment can quietly become a liability at exit if a prospective buyer's own compliance stack does not align with the seller's chosen model provider or its data residency terms. Operators who wait until diligence begins to ask these questions typically find the answers cost far more to fix under a deal clock than they would have earlier, when there was still time to renegotiate quietly rather than disclose a gap under pressure with a buyer's legal team already reading every contract line by line.

A deliberately mixed-model approach, executed well ahead of a sale process, gives operators real leverage in future vendor negotiations and a cleaner sovereignty story to present to acquirers during diligence. Deloitte is effectively betting that enough enterprises will pay consulting fees to build that flexibility on purpose now, rather than scrambling to retrofit it under deal pressure later when negotiating leverage has already shifted to the buyer's side of the table. A sovereignty gap discovered mid-diligence tends to show up as a valuation haircut rather than a fixable action item on a punch list, since there is rarely enough time left in the process to remediate it credibly before signing.

Tagged#news#digital-transformation#enterprise#cio#erp#strategy#governance#ai-strategy#open-models#deloitte#nvidia#vendor-risk#procurement