The First Regulators
The AI regulator you didn’t see coming was already in your client meeting
Last week, the White House told OpenAI which customers can use their next model. I wasn’t surprised.
Two weeks before that, the Commerce Department pulled Anthropic’s most capable models for entire user categories. No explanation. No timeline. Just pulled.
Everyone in enterprise software is treating this as a plot twist. I’ve been waiting for it since January.
What my customers told me first
Early this year, I sat down with a group of customers to understand what they needed from us as we rearchitected our platform for AI agents. Expected to hear about features. Response times. Integrations.
What I heard: trust. Security. A privacy track record that could hold up when their most sensitive client data is inside the model.
Not talking points. Hard requirements. Specific questions about where data flows, what gets retained, who has access to what. And then one question I didn’t expect: which company is actually running the AI.
One customer said it without hesitation. Don’t pick that model provider. Their CEO keeps talking about human extinction. We don’t trust him.
I didn’t argue. I wrote it down.
No benchmark comparison. Just a direct statement about a CEO’s public behavior and what it signals about the company behind the model.
They’d already made the call. Just waiting to see if I had too.
Why clients got there first
Regulators ask: what’s the risk to the system?
Clients ask: what’s the risk to me?
And in professional services, where a managing partner’s name is on every client deliverable, that second question gets answered faster, with more urgency, than any government review board.
Thomson Reuters asked thousands of PS professionals the same question this year. 85% of clients want their firms to disclose which AI they’re using. Fewer than one in three actually know. That gap is exactly where trust gets destroyed quietly, before anyone has to call it a crisis.
The clients asking hard questions about model providers in January weren’t being paranoid. They were pricing in risk before the market did.
Government just caught up.
The treadmill
Here’s the part nobody in enterprise software wants to say out loud.
Worst model is always the current one.
Everything ahead will be more capable. More regulated. More expensive. And the useful shelf life of each generation keeps shrinking. One major provider launched a new flagship model this month at double the previous pricing — ten days’ notice before existing plans stopped covering it. Another provider’s most powerful models got pulled by a federal agency for users in certain geographies. No warning.
Model providers are in a capability race. Capability attracts regulation. Regulation restricts access. Restricted access creates pricing power. Pricing power funds the next leap. Repeat.
You’re not picking a vendor. You’re picking a treadmill. Speed gets set by people who aren’t thinking about your renewal cycle or what you committed to a client last quarter.
Open source is a real alternative. I looked hard at it. But the economics of running it at enterprise scale aren’t obvious enough yet for me to stake the platform on. Watching closely. Not ready.
What we actually decided
When we made our model decision, I kept returning to the same questions. Which provider meets the security and privacy requirements our customers named explicitly? Which one extends the infrastructure we’ve already committed the business to? What happens to our clients if that provider changes pricing overnight, or if a government agency decides their models can’t reach certain markets?
If you haven’t asked yourself all three, you haven’t made a decision. You’ve let your engineers make one for you.
One answer covered all of them.
We chose the provider already powering our infrastructure. Not the highest benchmark score. The one our customers would accept — and the one we could defend out loud when asked.
We use a different provider internally for employee productivity. That’s a different trust context. My team’s workflows aren’t client deliverables. Different bar.
The question behind the question
When a managing partner at a 200-person AEC firm asks which AI powers your platform, they’re not asking a technical question. They’re asking whether your judgment about risk is something they can rely on — the same way they rely on your judgment about everything else you do for them.
Most SaaS CEOs are treating model selection as an engineering call. Their clients stopped treating it that way sometime last year.
Government caught up this week.
Your clients were the first regulators. They made the call before any of this was a headline. Before Washington.
Only question is whether you were listening then — or starting now.
