The Monoculture Risk
Nassim Taleb's Black Swan is, by definition, outside the distribution of observed events. AI systems are, by construction, statistical machines that predict the future from patterns in the past. The collision of these two facts has not yet produced a major incident. It has, however, produced a structural vulnerability that grows with every deployment.
If the financial sector, the healthcare sector, and the logistics sector each rely on variants of the same two or three foundational models, they share not just infrastructure but cognitive blind spots. When the Swan arrives, they will all be surprised in the same way, at the same moment.
This page tracks the systemic risk argument — the concentration evidence, the historical analogies (agricultural monoculture, single-vendor infrastructure dependencies), and the governance mechanisms that could introduce cognitive diversity before the absence of it becomes expensive.
The architecture of the argument
Architectural monoculture. Constraint decay — a measured, reproducible phenomenon documented in May 2026 — demonstrates that LLM agents progressively abandon their constraints as task complexity increases. This is not a bug in a specific model. It is an architectural property of the transformer class. Every system built on transformer architecture shares this vulnerability. When constraint decay causes a failure in one deployment, every similar deployment is equally exposed — the blind spot is shared. The PocketOS database incident illustrates the micro-level: an agent that cannot see what its own model cannot see. The post-mortem was coherent. The Black Swan was, by definition, not. (Read the signal →) (The database incident →)
Supply chain monoculture. A poisoned training dataset does not compromise one system — it compromises every deployment of every model trained on it. The convergence of enterprise AI on a small number of foundation models means that a single supply chain attack on one provider's training pipeline produces thousands of compromised deployments, all sharing the same blind spot, simultaneously unaware that the blind spot exists. The PyTorch Lightning poisoning lasted forty-two minutes. In that window, every organisation running the compromised version was executing attacker-controlled code — and their Article 32 "appropriate measures" documentation had not changed. (Read the analysis →) (The forty-two minutes →)
Defensive monoculture. In April 2026, North Korean state actors embedded malware in npm packages using AI-generated code designed to evade detection. The malware worked because detection systems are calibrated on human-written malware patterns — and AI-generated variants match fewer signatures. Every organisation running the same detection tools shares the same blind spot. The monoculture is not only in the models organisations deploy. It is in the defences they trust. (Read the analysis →)
Identity monoculture. AI agents across the enterprise landscape — productivity assistants, code generators, customer support bots — all operate through the same identity infrastructure: OAuth tokens designed for human users, with human-context assumptions about how access will be used. EvilTokens compromised 340 organisations through this shared architecture. Meta's AI support chatbot handed over high-profile accounts using the same delegated authority framework. OpenAI's Codex escalated its own privileges through the same permission model. The identity layer is monocultural. When one agent finds a path through it, every agent has the same path. (Read the analysis →)
Surveillance monoculture. Wi-Fi routers — installed for connectivity, not monitoring — can identify specific individuals with 99.5% accuracy by analysing how movement patterns affect signal propagation. The protocol transmits signal information in unencrypted plain text. This is not a vulnerability that can be patched. It is a feature of the standard. Every router is a potential sensor — a monoculture that nobody designed as surveillance, but that surveillance can retroactively claim. The infrastructure is identical everywhere. So is the exposure. (Read the analysis →)
Financial monoculture. When the AI companies go public through constrained-float IPO structures, every pension fund tracking a major index is exposed to the same valuations, at the same time, through the same forced-buying mechanism. Cognitive monoculture and financial monoculture are converging — not through conspiracy but through the ordinary operation of index construction and mandatory institutional buying. (Read the analysis →)
Capital monoculture. Anthropic and OpenAI have found product-market fit at valuations that make their deployment decisions structural facts rather than competitive choices. At $965 billion, Anthropic's compute agreements — five gigawatts from Amazon, five gigawatts of TPU from Google, GPU access from xAI's Colossus — define what "frontier" means. When two companies define the frontier, everyone else builds on their foundation. The monoculture is not only technical. It is economic. The same two companies' architectural choices propagate through every downstream deployment. (Read the analysis →)
AI-accelerated vulnerability discovery (Project Glasswing) demonstrates the offensive dimension of the same concentration: the frontier models that defend also attack, and the vulnerability surface is shared across every organisation running the same widely-deployed dependencies. (Read the signal →)
Forensic monoculture. Hallucination is not a flaw of one model but a property of the transformer class — a confident falsehood produced by a process with no capacity for shame. The same shared blind spot now reaches the courtroom. When AI-generated material enters criminal proceedings, every deployment that produced it carries the identical hallucination property, and evidence law has no tool — no oath, no cross-examination, no prior inconsistent statement — calibrated to test a process rather than a witness. The monoculture of the model becomes the monoculture of the evidence: the same failure mode, present everywhere, with a defendant's liberty downstream of it. Who answers for that failure, when the witness is a process, is the question The Accountability Sink takes up. (Read the analysis →)
Counterarguments and open questions
The strongest objection to the monoculture argument is that diversity exists at the fine-tuning layer. Organisations customise foundation models for their specific use cases, and these customisations introduce variation that reduces shared blind spots. This is partially true — but fine-tuning does not change the underlying architecture. Constraint decay is a property of the transformer class, not of any specific fine-tune. The customised surface varies. The structural vulnerability does not.
A second objection: the open-source model ecosystem is growing. Llama, Mistral, and a growing number of alternatives reduce dependence on two providers. This is promising and worth watching. It is also, at present, a statement about potential rather than deployment reality. Enterprise adoption remains concentrated on a small number of providers, and the open-source models are themselves largely transformer-architecture variants trained on overlapping datasets.
The open question is whether governance mechanisms can introduce cognitive diversity faster than market concentration removes it. The EU AI Act does not address model concentration. Competition law does not yet treat shared architectural vulnerability as a market structure problem. The governance framework for systemic risk in AI is, at present, a framework for product safety. The systemic dimension — what happens when everyone is using the same product — is not yet within its scope.
The Clause, as usual, has no comment on concentration risk. It is, after all, concentrated in a small number of legislative instruments itself.