One Practice, One Vendor, Four Regulated Industries
IBM's August 13 announcement is specific about scope. GPT-5.6, Codex and ChatGPT Work move into IBM Consulting Advantage, the platform IBM uses to deliver AI-enabled consulting to its client base. IBM is building a dedicated OpenAI Practice inside IBM Consulting and putting thousands of consultants and engineers through OpenAI Partner Network certification over the coming months. The named target industries are financial services, government, telecommunications and retail, spanning finance, procurement, customer operations and HR workflows, for a client base IBM describes as spread across more than 175 countries. This is not a pilot or a single-industry integration - it is IBM's largest consulting practice betting its AI delivery layer on one outside vendor's models.
What IBM Says the Risk Is, and Isn't
IBM's own framing of risk in this deal is entirely about cybersecurity and governance. IBM Global Consulting SVP Andy Baldwin put it directly: 'the challenge is not access to AI technologies - it's integrating AI securely and at scale into complex enterprise environments and workflows.' The concrete security commitment named is IBM Autonomous Security paired with OpenAI's Daybreak Cyber Partner Program, aimed at coordinated, machine-speed incident response. OpenAI Chief Revenue Officer Denise Dresser frames the upside in terms of organizational trust: 'the organizations pulling ahead with AI are the ones turning it into a trusted part of how their business operates.' Both statements describe real, addressed risks. Neither statement, nor anything else in IBM's published materials, addresses a different category of risk entirely: what happens if the underlying model simply becomes unavailable for reasons that have nothing to do with cybersecurity.
The Precedent IBM's Press Release Doesn't Mention
That is not a hypothetical scenario - it already happened to a different US frontier lab this year. Japan's National Cyber Director, Yoichi Iida, confirmed on August 10, 2026 that a US Commerce Department export order issued June 12 forced Anthropic to suspend its Fable 5 and Mythos 5 models for every customer worldwide, including its own non-US staff and allied governments, because Anthropic's systems could not distinguish an eligible user from an ineligible one at the application layer. Only the NSA secured an exemption. The models remain restored only for a vetted set of US organizations, not for Japan, seven weeks before Japan's own Active Cyber Defense Act takes effect. OpenAI operates under the identical Commerce Department export-control regime that produced that order. IBM's press materials name cybersecurity risk and governance risk by name; they are silent on the risk that a national-security directive aimed at something unrelated to IBM's clients could reach into GPT-5.6 the same way and switch it off for an EU bank or ministry overnight, with no advance notice and no negotiation.
What an EU Financial Services or Government Client Should Ask Before Signing
Any EU financial institution or public-sector body evaluating an IBM Consulting engagement built on this partnership has a specific question to put on the table that neither company's announcement answers: what contractual continuity exists if a future US export order restricts access to GPT-5.6 for reasons unrelated to the client's own conduct. Useful things to ask for in writing include a defined fallback path to an alternative model or vendor, a service-level commitment that treats export-driven unavailability as a covered event rather than force majeure that waives IBM's obligations, and clarity on whether any workload can run on infrastructure outside the reach of a single jurisdiction's export authority. None of this makes the partnership a bad idea - GPT-5.6 is a capable model and IBM's delivery scale is real - but the Anthropic precedent means the question is no longer academic.
Read next: OpenAI's Mid Tier Now Costs Ten Times Its Cheapest | OpenAI Cleans Its Cap Table Before a 2026 IPO



