State of AI Architecture 2026

Introduction

In September 2026, we surveyed 520 leaders who are responsible for their organization’s use of large language models and/or AI agents. All respondents work at companies with more than 500 employees in the United States or Canada, hold a manager-or-above title, and have AI agents in pilot or production. Respondents came from twelve industries, with software (27%) and financial services (16%) the largest groups.

Most enterprise AI conversations focus on the model: which one, from whom, and at what price. This study looks at everything that gets built around the model, including the integrations, workflows, guardrails, memory and evals that turn a model into a working system, then asks how portable that system really is. We wanted to understand how enterprises are assembling their AI stacks, how much they worry about being locked in to any one model or provider, and what (if anything) would actually be hard to move.

Following is a summary of the results. As with our previous research, we are intentionally avoiding subjective commentary and sales pitches; we figure you’re here because you want the benchmarking data points.

What we mean by “open architecture”

A closed, or vertically integrated, architecture is one where the layers (the model, harness, runtime, tool integrations, memory, evals and more) are supplied by a single vendor and are designed to work together on that vendor’s terms. An open architecture is one where the layers around the model are built on open standards and open source software so that an enterprise can use any model from any provider, and can move between providers without having to rebuild layers.

Insight 1: Lock-in is a fear, but not (yet) a buying criterion

We asked respondents about the composition of their current agent stack. Frontier lab APIs are close to universal, hyperscaler platforms are in a majority of stacks, and roughly three in ten organizations have an open source agent framework (per above, an internally built agent platform). With that baseline established, we dove into the study.

“Which of the following are part of your organization’s AI stack today?”

  • Frontier labs (OpenAI, Anthropic, Google, etc.) 76%
  • Hyperscaler AI platforms (Bedrock, Vertex, Azure AI, etc.) 55%
  • Vertical SaaS with embedded agents (Salesforce, ServiceNow, etc.) 44%
  • Open source agent frameworks (LangChain, CrewAI, etc.) 30%
  • Internally built agent platform 28%
View data table
Category Value
Frontier labs (OpenAI, Anthropic, Google, etc.) 76%
Hyperscaler AI platforms (Bedrock, Vertex, Azure AI, etc.) 55%
Vertical SaaS with embedded agents (Salesforce, ServiceNow, etc.) 44%
Open source agent frameworks (LangChain, CrewAI, etc.) 30%
Internally built agent platform 28%

Given that a majority of respondents are utilizing vertically integrated stacks, we wanted to explore awareness and perception of lock-in risks. Respondents were nearly unanimous that lock-in exists and that it matters: 81% agree that frontier labs and hyperscalers make it difficult to move between vendors, and 84% say it is important that their AI strategy avoids vendor lock-in.

“Please indicate your agreement with each of the following statements.”

  • The proprietary platforms of frontier labs and hyperscalers make it difficult to move between vendors Strongly agree: 15% Agree somewhat: 66% Disagree somewhat: 18% Strongly disagree: 2%
  • It is important that our AI strategy avoids vendor lock-in Strongly agree: 37% Agree somewhat: 47% Disagree somewhat: 12% Strongly disagree: 3%
  • Strongly agree
  • Agree somewhat
  • Disagree somewhat
  • Strongly disagree
View data table
Category Strongly agree Agree somewhat Disagree somewhat Strongly disagree
The proprietary platforms of frontier labs and hyperscalers make it difficult to move between vendors 15% 66% 18% 2%
It is important that our AI strategy avoids vendor lock-in 37% 47% 12% 3%

Respondents reinforced that this is not a theoretical worry. 81% report that concern about switching costs has already caused their organization to delay, scale back or restructure a migration from one model provider to another; 29% say it happens frequently. In financial services, 92% have experienced this at least once.

“Have concerns about vendor switching costs ever caused your organization to delay, scale back or restructure a migration from one model provider to another?”

  • All Yes, frequently: 29% Yes, rarely: 53% No, never: 19%
  • FSI Yes, frequently: 26% Yes, rarely: 66% No, never: 8%
  • Software Yes, frequently: 29% Yes, rarely: 58% No, never: 13%
  • Yes, frequently
  • Yes, rarely
  • No, never
View data table
Category Yes, frequently Yes, rarely No, never
All 29% 53% 19%
FSI 26% 66% 8%
Software 29% 58% 13%

When asked to estimate how long it would take to move their current workloads to a different model provider, 57% said four months or more, and 3% said they could not migrate at all. Financial services firms expect the longest migrations: 68% estimate four months or more.

“If your team decided to move these workloads to a different model provider, how long do you estimate the migration would take?”

  • All Less than 1 month: 10% 1-3 months: 30% 4-6 months: 26% 6-12 months: 24% More than 12 months: 7% We could not migrate to another provider: 3%
  • FSI Less than 1 month: 8% 1-3 months: 22% 4-6 months: 37% 6-12 months: 22% More than 12 months: 9% We could not migrate to another provider: 4%
  • Software Less than 1 month: 13% 1-3 months: 35% 4-6 months: 23% 6-12 months: 23% More than 12 months: 4% We could not migrate to another provider: 1%
  • Less than 1 month
  • 1-3 months
  • 4-6 months
  • 6-12 months
  • More than 12 months
  • We could not migrate to another provider
View data table
Category Less than 1 month 1-3 months 4-6 months 6-12 months More than 12 months We could not migrate to another provider
All 10% 30% 26% 24% 7% 3%
FSI 8% 22% 37% 22% 9% 4%
Software 13% 35% 23% 23% 4% 1%

The obstacles that respondents cite are mostly engineering barriers rather than commercial ones. Technical complexity leads, followed closely by the switching cost of expertise and tooling. Contractual obligations rank fourth.

“What is the biggest barrier to switching AI model providers? Choose up to 2 of the following.”

  • Technical complexity 41%
  • Switching costs of expertise and tooling 38%
  • Cost uncertainty 35%
  • Existing contractual obligations 27%
  • Potential performance degradation 26%
  • Loss of vendor-specific features 19%
View data table
Category Respondents
Technical complexity 41%
Switching costs of expertise and tooling 38%
Cost uncertainty 35%
Existing contractual obligations 27%
Potential performance degradation 26%
Loss of vendor-specific features 19%

Here is the gap. When the same respondents were asked what matters most when selecting AI infrastructure, the ability to switch providers without rebuilding ranked sixth out of eight options, and avoiding dependence on a single vendor ranked last. Data security and privacy dominated, followed by cost control, regulatory compliance and capabilities. Lock-in is something respondents expect to suffer, but that’s a problem that arrives later, whereas cost controls and compliance have to be dealt with now. This may be present bias, discounting future pain, or the tragedy of the commons, in that lock-in is likely to be someone else’s problem down the line.

“What are the most important factors when your organization selects AI infrastructure? Choose up to 3 of the following.”

  • Data security and privacy 64%
  • Cost control 43%
  • Compliance with regulatory requirements 40%
  • Capabilities 39%
  • Auditability of agent actions 29%
  • Ability to switch providers without rebuilding 24%
  • Speed of deployment 21%
  • Avoiding dependence on a single vendor 20%
View data table
Category Respondents
Data security and privacy 64%
Cost control 43%
Compliance with regulatory requirements 40%
Capabilities 39%
Auditability of agent actions 29%
Ability to switch providers without rebuilding 24%
Speed of deployment 21%
Avoiding dependence on a single vendor 20%

Two cuts are worth noting. Security leaders rank auditability of agent actions much higher than their peers (45% vs. 29% overall). And organizations already using three or four model providers are the most likely to rank switching ability as a top-three factor (30%), a preview of the theme in the next section. That’s a nifty segue; let’s go there now.

Insight 2: Enterprises are seeking a cross-provider solution now that multi-model is the default

Only 8% of respondents use one model provider. Half use two or three, and nearly a quarter use five or more. The larger the enterprise, the more likely it is that they are using multiple model providers. 37% of companies with more than 10,000 employees use five or more providers, compared with 12% of companies with 500 to 2,500 employees.

“How many different model providers does your organization use in production or pilot today?”

  • All: 8% 500-2,500: 14% 2,501-10,000: 5% 10,000+: 5% 1
  • All: 24% 500-2,500: 30% 2,501-10,000: 28% 10,000+: 17% 2
  • All: 27% 500-2,500: 32% 2,501-10,000: 30% 10,000+: 20% 3
  • All: 17% 500-2,500: 12% 2,501-10,000: 18% 10,000+: 20% 4
  • All: 7% 500-2,500: 5% 2,501-10,000: 9% 10,000+: 5% 5
  • All: 18% 500-2,500: 7% 2,501-10,000: 10% 10,000+: 32% More than 5
  • All
  • 500-2,500
  • 2,501-10,000
  • 10,000+
View data table
Category All 500-2,500 2,501-10,000 10,000+
1 8% 14% 5% 5%
2 24% 30% 28% 17%
3 27% 32% 30% 20%
4 17% 12% 18% 20%
5 7% 5% 9% 5%
More than 5 18% 7% 10% 32%

The organizations with five or more providers are heavier users of every stack component, and they are far more likely to have built the connective layers that make a multi-model architecture work: 76% have built integrations to internal systems or MCP servers, versus 42% of organizations using one or two model providers.

“Selected results by number of model providers in use”

  • Have built integrations to internal systems or MCP servers 1-2 Providers: 42% 3-4 Providers: 59% 5+ Providers: 76%
  • Portability across providers is critically or very important 1-2 Providers: 42% 3-4 Providers: 62% 5+ Providers: 67%
  • “Highly likely” to evaluate an open alternative to closed frontier architectures 1-2 Providers: 13% 3-4 Providers: 20% 5+ Providers: 35%
  • Flexibility (avoiding lock-in) is an advantage of open source 1-2 Providers: 51% 3-4 Providers: 67% 5+ Providers: 69%
  • Use open source agent frameworks today 1-2 Providers: 22% 3-4 Providers: 29% 5+ Providers: 45%
  • 1-2 Providers
  • 3-4 Providers
  • 5+ Providers
View data table
Category 1-2 Providers 3-4 Providers 5+ Providers
Have built integrations to internal systems or MCP servers 42% 59% 76%
Portability across providers is critically or very important 42% 62% 67%
“Highly likely” to evaluate an open alternative to closed frontier architectures 13% 20% 35%
Flexibility (avoiding lock-in) is an advantage of open source 51% 67% 69%
Use open source agent frameworks today 22% 29% 45%

In other words, the more providers an organization runs, the more portability moves from a nice-to-have to an operating requirement; they need an architecture that treats the model as an interchangeable component.

Insight 3: The agent layer is stickier than the model

If enterprises already swap models routinely, where does lock-in actually live? We asked respondents which elements of an AI system they had built or deployed on their current models. Most have built a substantial amount around the model. At the top of the list are team skills, integrations to internal systems or MCP servers, and multi-step agent workflows.

“Which of the following elements of an AI system has your organization built or deployed on your current models?”

  • Technical skills and operational knowledge 62%
  • Integrations to internal systems or MCP servers 58%
  • Multi-step agent workflows 51%
  • Guardrails, content policies or access-control configurations 49%
  • Organization-specific memory and context 47%
  • Prompt libraries and skill packages 47%
  • Agent definitions grounded in internal knowledge 46%
  • Evaluation suites, benchmarks or regression tests for AI outputs 39%
View data table
Category Respondents
Technical skills and operational knowledge 62%
Integrations to internal systems or MCP servers 58%
Multi-step agent workflows 51%
Guardrails, content policies or access-control configurations 49%
Organization-specific memory and context 47%
Prompt libraries and skill packages 47%
Agent definitions grounded in internal knowledge 46%
Evaluation suites, benchmarks or regression tests for AI outputs 39%

We then asked which of those elements would be most challenging to move to another model provider. Integrations to internal systems and MCP servers ranked first, followed by multi-step agent workflows. Prompt libraries, the element most closely tied to a specific model’s behavior, ranked last. Only 10% of respondents said none of these elements would be hard to move.

“Which part of your existing AI system would be most challenging to move to another model provider? Choose up to 2 of the following.”

  • Integrations to internal systems or MCP servers All respondents: 30% Among those who built the element: 53%
  • Multi-step agent workflows All respondents: 27% Among those who built the element: 52%
  • Guardrails, content policies or access-control configurations All respondents: 19% Among those who built the element: 40%
  • Team skills and operational knowledge All respondents: 27% Among those who built the element: 28%
  • Agent definitions grounded in internal knowledge All respondents: 16% Among those who built the element: 36%
  • Evaluation suites, benchmarks or regression tests All respondents: 15% Among those who built the element: 39%
  • Organization-specific memory and context All respondents: 15% Among those who built the element: 31%
  • Prompt libraries and skill packages All respondents: 11% Among those who built the element: 24%
  • None of these would be challenging to move All respondents: 10% Among those who built the element: 0%
  • All respondents
  • Among those who built the element
View data table
Category All respondents Among those who built the element
Integrations to internal systems or MCP servers 30% 53%
Multi-step agent workflows 27% 52%
Guardrails, content policies or access-control configurations 19% 40%
Team skills and operational knowledge 27% 28%
Agent definitions grounded in internal knowledge 16% 36%
Evaluation suites, benchmarks or regression tests 15% 39%
Organization-specific memory and context 15% 31%
Prompt libraries and skill packages 11% 24%
None of these would be challenging to move 10% 0%

Among organizations that have built integrations or multi-step workflows, more than half name that element as one of their two hardest things to move. The work that connects an agent to the enterprise is the work that is hardest to take with you.

This shows up again in what respondents worry about when they build on a frontier lab or hyperscaler platform. Pricing changes after commitment is the most common concern overall, but 37% worry specifically about the inability to export agent state, memory or evaluations, and 39% fret over product or API deprecation. Only 3% have no concerns.

“What concerns do you have about building on frontier lab or hyperscaler platforms?”

  • Pricing changes after we are committed All: 56% FSI: 48% Software: 60%
  • Insufficient transparency for security review or audit All: 49% FSI: 45% Software: 46%
  • Vendor accessing our IP All: 42% FSI: 40% Software: 46%
  • Product / API deprecation All: 39% FSI: 46% Software: 38%
  • Inability to export agent state, memory or evals All: 37% FSI: 52% Software: 41%
  • Terms-of-service or usage policy changes All: 33% FSI: 30% Software: 26%
  • Vendor entering our market as a competitor All: 26% FSI: 28% Software: 37%
  • I don't have any concerns All: 3% FSI: 1% Software: 6%
  • All
  • FSI
  • Software
View data table
Category All FSI Software
Pricing changes after we are committed 56% 48% 60%
Insufficient transparency for security review or audit 49% 45% 46%
Vendor accessing our IP 42% 40% 46%
Product / API deprecation 39% 46% 38%
Inability to export agent state, memory or evals 37% 52% 41%
Terms-of-service or usage policy changes 33% 30% 26%
Vendor entering our market as a competitor 26% 28% 37%
I don't have any concerns 3% 1% 6%

In financial services, the inability to export agent state, memory or evals is the single most common concern; whereas retailers are worried about pricing and vendors entering their market.

Insight 4: Appetite for open exceeds readiness for open

Given all of the above, it is not surprising that interest in an open alternative is broad. 80% of respondents say they would be likely to evaluate an open source alternative to the vertically integrated, closed architectures offered by frontier labs, and one in five is highly likely. Engineering leaders are the most enthusiastic (32% highly likely); operations leaders the least (10%).

“If there was an open source alternative to the vertically-integrated and closed architectures offered by frontier labs, how likely would your organization be to evaluate it?”

  • All Highly likely: 21% Somewhat likely: 59% Somewhat unlikely: 15% Highly unlikely: 5%
  • Engineering Highly likely: 32% Somewhat likely: 51% Somewhat unlikely: 15% Highly unlikely: 2%
  • AI/ML Highly likely: 24% Somewhat likely: 62% Somewhat unlikely: 14%
  • Security Highly likely: 20% Somewhat likely: 51% Somewhat unlikely: 24% Highly unlikely: 6%
  • Operations Highly likely: 10% Somewhat likely: 66% Somewhat unlikely: 16% Highly unlikely: 8%
  • Highly likely
  • Somewhat likely
  • Somewhat unlikely
  • Highly unlikely
View data table
Category Highly likely Somewhat likely Somewhat unlikely Highly unlikely
All 21% 59% 15% 5%
Engineering 32% 51% 15% 2%
AI/ML 24% 62% 14% 0%
Security 20% 51% 24% 6%
Operations 10% 66% 16% 8%

The appetite extends to control more generally. 88% agree that their team expects to take more control of its AI architecture as it gains experience, rather than continuing to rely so heavily on current vendors. Among AI/ML leaders that figure is 97%. And 76% describe themselves as very interested in open source alternatives for AI architectures.

“Please indicate your agreement with each of the following statements.”

  • Our team expects to take more control of our AI architecture as we gain experience rather than relying so heavily on current AI vendors Strongly agree: 24% Agree somewhat: 64% Disagree somewhat: 11% Strongly disagree: 1%
  • I am very interested in open source alternatives for AI architectures Strongly agree: 22% Agree somewhat: 54% Disagree somewhat: 15% Strongly disagree: 9%
  • Strongly agree
  • Agree somewhat
  • Disagree somewhat
  • Strongly disagree
View data table
Category Strongly agree Agree somewhat Disagree somewhat Strongly disagree
Our team expects to take more control of our AI architecture as we gain experience rather than relying so heavily on current AI vendors 24% 64% 11% 1%
I am very interested in open source alternatives for AI architectures 22% 54% 15% 9%

Respondents are clear about their motivations. Flexibility and cost control tie as the leading advantages of a more open architecture, with sovereignty over code and data close behind.

“In your opinion, what advantages can be gained from the use of open source in your AI architecture?”

  • Flexibility – avoiding lock-in to proprietary solutions 62%
  • Cost control – managing costs at scale 62%
  • Sovereignty – hosting your code and controlling your data 53%
  • Transparency – understanding and/or auditing code 47%
  • Velocity – accessing innovations from the wider community 38%
  • Influence – contributing to current capabilities and future roadmap 32%
  • There are no advantages to using open source for AI 2%
View data table
Category Respondents
Flexibility – avoiding lock-in to proprietary solutions 62%
Cost control – managing costs at scale 62%
Sovereignty – hosting your code and controlling your data 53%
Transparency – understanding and/or auditing code 47%
Velocity – accessing innovations from the wider community 38%
Influence – contributing to current capabilities and future roadmap 32%
There are no advantages to using open source for AI 2%

However, respondent practices lag some of their intentions. Today, open source is critical or significant in the AI architecture of 56% of respondents; for the other 44%, commercial solutions do the heavy lifting.

“Which of the following best describes the role of open source software in your AI architecture today?”

  • Critical – our AI systems could not run without open source 10%
  • Significant – we rely on open source alongside commercial solutions 46%
  • Peripheral – we use some open source, but commercial solutions do the heavy lifting 29%
  • Minimal – we have some limited use of open source 10%
  • None – there is no open source in our AI architecture 5%
View data table
Category Respondents
Critical – our AI systems could not run without open source 10%
Significant – we rely on open source alongside commercial solutions 46%
Peripheral – we use some open source, but commercial solutions do the heavy lifting 29%
Minimal – we have some limited use of open source 10%
None – there is no open source in our AI architecture 5%

We asked every respondent to complete the sentence “We would move more AI workloads to an open architecture if…” and we received 277 substantive answers. Coded by theme, roughly four in ten mention security, compliance, privacy or governance. The next most frequent theme was performance or capability parity with frontier models, followed by ease of integration or migration.

“We would move more workloads to an open architecture if it offered …”

(% of responses)

  • Security, compliance and/or governance guarantees 36%
  • Performance or capability parity with frontier models 22%
  • Ease of integration or migration 12%
  • Enterprise support, SLAs or vendor accountability 10%
  • Proven enterprise adoption or track record 8%
  • Other themes 12%
View data table
Category Respondents
Security, compliance and/or governance guarantees 36%
Performance or capability parity with frontier models 22%
Ease of integration or migration 12%
Enterprise support, SLAs or vendor accountability 10%
Proven enterprise adoption or track record 8%
Other themes 12%

Respondent profile

Geographies

This was a North American study. All respondents were based in the United States or Canada.

Industries

The study did not exclude any industries. Software and financial services together account for 43% of the sample and are the two industries we occasionally drill into in the report (given sufficient sample).

Primary industry

  • Technology – Software 27%
  • Financial services and insurance 16%
  • Services 8%
  • Technology – Other 7%
  • Telecommunications 7%
  • Healthcare 7%
  • Manufacturing 6%
  • Retail 5%
  • Government 4%
  • Energy and utilities 3%
  • Food and beverage 2%
  • Media 2%
  • Other 6%
View data table
Category Share
Technology – Software 27%
Financial services and insurance 16%
Services 8%
Technology – Other 7%
Telecommunications 7%
Healthcare 7%
Manufacturing 6%
Retail 5%
Government 4%
Energy and utilities 3%
Food and beverage 2%
Media 2%
Other 6%

Organization size

The study targeted mid-sized and large enterprises. Seventy percent of respondents work at companies with more than 2,500 employees, and 38% at companies with more than 10,000 employees.

Employees

  • 500 – 2,500 employees 31%
  • 2,501 – 10,000 employees 32%
  • More than 10,000 employees 38%
View data table
Category Share
500 – 2,500 employees 31%
2,501 – 10,000 employees 32%
More than 10,000 employees 38%

Respondent role

Respondents were screened for direct responsibility over their organization’s use of LLMs or AI agents. They sit across the functions that typically share ownership of an AI platform, with engineering and operations the largest groups.

“What function best describes your role?”

  • Engineering 27%
  • Operations 25%
  • AI / ML 17%
  • Executive with multiple responsibilities 16%
  • Security 11%
  • Research 5%
View data table
Category Share
Engineering 27%
Operations 25%
AI / ML 17%
Executive with multiple responsibilities 16%
Security 11%
Research 5%

Forty-five percent of respondents hold director-or-above titles.

“Which of the following best describes your current job title?”

  • Team manager 55%
  • Director-level manager 25%
  • VP-level executive 10%
  • C-level executive 10%
View data table
Category Share
Team manager 55%
Director-level manager 25%
VP-level executive 10%
C-level executive 10%

AI maturity

Anyone whose organization was still in early exploration, or had no AI activity, was filtered out of the study. The remaining respondents are well past experimentation: 58% run LLMs or AI agents in production across multiple business functions.

“Which best describes your organization’s current use of LLMs or AI agents for building or delivering technology solutions for employees, customers or partners?”

  • In production across multiple business functions 58%
  • In production in one business function 21%
  • In active pilot or evaluation 21%
View data table
Category Share
In production across multiple business functions 58%
In production in one business function 21%
In active pilot or evaluation 21%

Conclusions

Enterprise AI leaders are already multi-model: 92% use more than one provider and a quarter use five or more. They overwhelmingly recognize that proprietary platforms make systems hard to move, and most have already delayed or restructured a migration because of it. Yet portability and vendor independence still rank near the bottom of their stated selection criteria, behind security, cost, compliance and capabilities.

The data suggests why. Lock-in is not accumulating at the model layer, which respondents swap with some regularity, but in the agent layer around it: the integrations to internal systems and MCP servers, the multi-step workflows, the guardrails and the organization-specific memory that turn a model into a working system. Those are the elements enterprises have invested in most heavily and expect to find hardest to move. For example, in financial services, the inability to export state is now the leading concern about building on a frontier lab platform.

The appetite for an alternative is broad. Four in five would evaluate an open architecture, and nearly nine in ten expect to take more control of their AI architecture over time. What stands between interest and adoption is assurance; respondents expect an open architecture to meet exacting standards for security, compliance, support and performance, and that lets them keep using the frontier models they already rely on. Where those conditions are met, the organizations furthest along in their AI journey are the ones most ready to move.

Ready to see it live?

Get a demo of the Stacklok platform

See how leading teams govern MCP servers and enforce security across their AI toolchain.