AI Civilization Knowledge Hub
Industry AnalysisGlobal

External insight · BIS Papers series

The AI Economy Is Also a Five-Layer Supply Chain

A paper published in the BIS Papers series maps AI through hardware, cloud infrastructure, training data, foundation models and applications, highlighting concentration and resilience risks.

The AI Supply Chain18 March 2025
Read the original source
Conceptual view of semiconductors, cloud infrastructure and AI applicationsConceptual visual
Independent editorial analysis

This is FUURAA’s own editorial analysis of the cited public source, prepared independently from the cited institution. Source materials remain attributable to their authors and publishers; FUURAA is responsible for their selection, synthesis and interpretation. No cited institution has reviewed or endorsed this article unless expressly stated.

External evidence

What the public source says

The authors of a paper published in the BIS Papers series describe five connected layers: hardware, cloud infrastructure, training data, foundation models and AI applications. Each layer has distinct costs, scale effects and competitive dynamics.

High fixed costs, network effects and strategic behaviour can increase concentration. The paper raises implications for consumer choice, innovation, operational resilience, cybersecurity and financial stability.

FUURAA editorial analysis

FUURAA editorial perspective

Evidence-led analysis in the public interest

AI products are never only software interfaces. They depend on a chain of infrastructure, data, models, vendors and operational controls, with risk able to travel across layers.

Resilient system design therefore includes portability, vendor awareness, fallback paths, security controls and a clear understanding of where critical dependencies sit.

Key judgments
  1. AI services inherit technical, commercial and governance dependencies from hardware, cloud infrastructure, training data, foundation models and application layers.
  2. Concentration can support scale and innovation while also creating correlated operational, competitive and security risks that individual application providers may not fully control.
  3. A paper published in the BIS Papers series provides an analytical map of the AI supply chain, not a certification of any vendor or a prediction that every identified risk will materialise.
01

The visible application is only the final layer

The authors of a paper published in the BIS Papers series describe an AI supply chain spanning hardware, cloud infrastructure, training data, foundation models and applications. This framing matters because users usually encounter the application interface while most critical dependencies remain out of sight. A service can appear independent yet rely on the same chips, cloud capacity, model providers or datasets as many competitors. FUURAA’s interpretation is that responsible product analysis must look through the interface and identify which upstream components affect availability, cost, privacy, security and performance. The five-layer model is useful for orientation, although real systems may contain additional intermediaries and relationships that do not fit neatly into one diagram.

02

Concentration produces both capability and exposure

High fixed costs, network effects and strategic behaviour can increase concentration across parts of the chain. Scale can bring sophisticated engineering, more efficient operations and faster diffusion of capability; it should not be assumed that concentration has only negative effects. The concern is that shared dependencies may reduce bargaining power or turn one failure, policy change or security incident into disruption across many services. Competition also has several dimensions: the number of providers, practical switching costs, access to essential inputs and the ability of smaller organisations to reach users. No single concentration measure can capture all of these effects.

03

Resilience begins with knowing what cannot easily be replaced

A credible resilience plan maps providers, data flows, permissions, interfaces and recovery procedures before an incident occurs. Portability can reduce dependence, but it is not costless: moving models, data or workloads may change performance, create legal questions or require substantial engineering. Full duplication is not always efficient or even possible. Organisations therefore need proportionate choices, including tested backups, graceful degradation, clear service boundaries and human escalation when automation fails. These are operational implications drawn from the supply-chain analysis; the paper does not prescribe one architecture for every organisation.

04

Governance must follow risk across contractual boundaries

Outsourcing a component does not remove the consequences of its failure. Buyers and builders need enough visibility to understand material dependencies, while suppliers also have legitimate security and intellectual-property limits on disclosure. A balanced approach focuses on information that supports risk management: service responsibilities, data handling, incident communication, change processes and exit conditions. Policymakers should similarly distinguish between supporting interoperability and imposing uniformity that could weaken innovation. The public interest lies in ensuring that responsibility does not disappear between layers and that essential services can recover when a critical component changes or becomes unavailable.

Alternative views & uncertainty

What this evidence does not settle

  • Diversifying every component can increase complexity, cost and attack surface; a well-governed primary provider may sometimes be safer than several poorly integrated alternatives.
  • Vertical integration can improve coordination and accountability within one system, so it should be evaluated by conduct, contestability and outcomes rather than treated as inherently harmful.

Public-interest implications

What this means for different stakeholders

public

Users benefit when providers communicate material outages, data responsibilities and service limitations without requiring specialist knowledge of the entire supply chain.

organisations / industry

Critical systems should maintain current dependency maps, proportionate fallback plans and realistic tests of switching or recovery.

policy

Competition and resilience policy should examine practical access, switching and correlated dependence across layers, not only the number of visible applications.

research

Independent work can improve understanding of cross-layer failures, portability trade-offs and how concentration affects different markets over time.

What to watch next

  • Whether new interfaces and standards make switching genuinely easier or merely add another dependency layer.
  • Whether providers disclose enough operational information for customers to manage critical risks and incidents.
  • Whether concentration changes in hardware, cloud, data, models and applications at the same or different rates.
Conclusion

The supply-chain view changes the question from which AI application performs best to which system of dependencies can be trusted for a particular purpose. Scale, integration and specialisation can create real benefits, but they also make failures and strategic choices travel across organisational boundaries. Resilience does not require eliminating every dependency; it requires knowing which ones matter, assigning responsibility and preparing credible recovery paths. FUURAA regards this discipline as essential for infrastructure and Agent systems, while recognising that appropriate safeguards must vary with context, consequence and the realistic alternatives available.

Independence and relevance disclosure

This is FUURAA’s independent editorial analysis of a paper published in the BIS Papers series. The paper states that its authors’ views do not necessarily reflect those of the BIS or its member central banks. Neither the authors nor the BIS reviewed or endorsed this interpretation.

Forward view

Operational questions

01

Dependency mapping

Which providers, chips, clouds, models and datasets are critical to continuity?

02

Portability

Can workloads and data move when a component changes, fails or becomes unavailable?

03

Concentration risk

How could shared suppliers create correlated failures across many services?