External AI Withdrawal Test | Geopolitical & Continuity Risk

Many organisations now depend on AI services they do not own or control. These services may support customer operations, analysis, software development, decision-making or other important parts of the business. That creates a new type of dependency: the organisation may be able to control how it uses AI, while having very little control over whether the AI service itself remains available.

The External AI Withdrawal Test | Geopolitical & Continuity Risk examines whether a business can continue its critical operations if access to an important external AI service is suddenly restricted or withdrawn. The disruption might come from the provider itself, from a government, from sanctions or export controls, from a trade dispute, from infrastructure problems or from wider geopolitical events.

The central question is simple: can the business keep operating if an external AI capability it depends on is no longer available?

The test is designed to make organisations examine that dependency before a disruption occurs. It asks whether the business knows which services depend on external AI, which countries and jurisdictions may affect access, what government measures could create problems, what alternatives are available and whether those alternatives could actually be used in time.

The framework contains 42 YES/NO questions. Answers should be based on documented arrangements, tested procedures or other verifiable evidence rather than assumptions about what the organisation believes it could do in the future. A YES means the relevant arrangement has been identified, documented and, where appropriate, tested. A NO means the organisation has not yet established that it can manage that particular risk.

The test does not create a score, rating or simple pass/fail result. Each NO identifies an area that needs to be examined. Some gaps may be relatively minor. Others may reveal that an essential business service depends on a provider that cannot easily be replaced.

The wider point is that good AI governance does not guarantee continued access to AI. A provider may act responsibly and a business may follow every relevant internal process, yet an outside event can still remove access to a critical service.

The test therefore adds an important continuity question to AI governance: not only “Are we using this AI responsibly?” but also “What happens to our organisation if we suddenly cannot use it at all?”

Standardized Definition of AI Governance

A public reference standard that defines AI governance as a measurable structural condition, moving beyond policy statements to test whether control, accountability, traceability and integrity can be demonstrated in practice across the AI lifecycle.

Parrott, R. (2025) “The Standardized Definition of AI Governance”. Self-published via Zenodo. Available at: https://doi.org/10.5281/zenodo.17505286

Evidential Resilience Ratio (ERR)

A quantitative AI governance metric designed to measure how much of an AI system remains provable when models, APIs, vendors or other upstream dependencies change. ERR focuses on traceability, reconstructability, version fidelity and dependency proof to assess whether governance can survive change.

Parrott, R. (2025) “Evidential Resilience Ratio”. Zenodo. Available at: https://doi.org/10.5281/zenodo.17799428

External AI Withdrawal Test | Geopolitical & Continuity Risk

A practical governance test examining whether a business can maintain critical services if access to an external AI provider is suddenly restricted or withdrawn because of provider decisions, government action, sanctions, trade restrictions or geopolitical disruption.

Parrott, R. (2026) “External AI Withdrawal Test | Geopolitical & Continuity Risk”. Zenodo. Available at: https://doi.org/10.5281/zenodo.22844995

The AI Protection Tests

A public reference framework for testing whether important AI protections actually work in practice, focusing on control, accountability, business dependence and effective oversight rather than relying on policies, promises or formal safeguards alone.

Parrott, R. (2026) “The AI Protection Tests”. Zenodo. Available at: https://doi.org/10.5281/zenodo.23012740