Three AI Vendors, One Five-Hour Window
ChatGPT, Claude, and Grok all went down within roughly the same five-hour window on 3 September 2026, an alignment rare enough on its own to draw scrutiny from reporters within hours. OpenAI's status page attributed its outage to a routing error that began around 7:43am PT, with a fix implemented and monitored from about 8:17am PT and the elevated-error issue across ChatGPT and Codex resolved by early afternoon.
Anthropic's status page recorded a partial outage beginning around 9:40am to 9:41am ET, affecting Claude.ai, the Claude API, Claude Code, and Claude Cowork, with all named models operational again by roughly 12:16pm to 12:27pm ET. xAI's Grok was down across the web, the X app, iOS, Android, and two US API regions from about 9:30am to 1:07pm ET, with xAI citing a problem at its Memphis, Tennessee compute center.
What Each Company Said Caused It
OpenAI, Anthropic, and xAI each named a separate, unrelated technical cause for their own outage, not one shared failure across all three. OpenAI's cause was a routing error inside its own systems, and some Codex remote-control users had to re-pair their mobile device once service returned.
Anthropic did not publish a detailed root cause beyond describing an infrastructure issue that affected several models, including Fable/Mythos 5.1, Fable/Mythos 5, Opus 5, Opus 4.8, and Opus 4.6, before resolution. xAI was the most specific of the three, pointing to a problem at its own Memphis, Tennessee compute center rather than at a shared cloud layer.
The Question Reporters Asked: Is Azure the Common Thread?
Reporters at The Register, 9to5Google, and Decrypt asked whether Microsoft Azure was the common thread beneath all three outages, because OpenAI, Anthropic, and xAI each lean on Azure among their cloud providers, and Microsoft said Azure was not the cause when asked directly. That denial, combined with three separately reported causes, means the 3 September outages have no confirmed single shared root cause, just an open question that reporters raised and Microsoft rejected.
Google's Gemini reported no incident during the same window, which is itself informative: whatever aligned ChatGPT, Claude, and Grok, it did not extend to every major AI vendor operating that day. That detail points toward either coincidence or a narrower shared dependency that has not been named publicly.
Why 'Multiple AI Vendors' Is Not Automatically a Resilience Strategy
Running ChatGPT alongside Claude or Grok does not automatically buy an enterprise infrastructure resilience, because vendor diversity at the AI-brand level can still sit on shared cloud dependencies underneath. For two years, EU enterprises and public-sector bodies have been advised that spreading workloads across multiple AI vendors protects against vendor lock-in and outage risk, an idea that also touches the Digital Operational Resilience Act (DORA) and NIS2 obligations around third-party ICT concentration risk.
The 3 September event is a concrete, dated test of that advice. OpenAI, Anthropic, and xAI reported separate causes this time, but all three lean on Microsoft Azure among their cloud providers, and the outages landed inside the same five-hour window regardless, which is exactly the kind of simultaneity a genuinely independent set of vendors should not produce on a routine basis.
| Vendor | Outage start | Outage end | Stated cause |
|---|---|---|---|
| OpenAI (ChatGPT, Codex) | ~7:43am PT | Early afternoon PT | Routing error |
| Anthropic (Claude) | ~9:40-9:41am ET | ~12:16-12:27pm ET | Unspecified infrastructure issue |
| xAI (Grok) | ~9:30am ET | ~1:07pm ET | Memphis, Tennessee compute center issue |
What a DORA-Compliant Concentration-Risk Register Should Track
A DORA-compliant ICT concentration-risk register should map risk at the cloud layer beneath each AI vendor's brand name, not just the AI vendor itself. Listing OpenAI, Anthropic, and a third provider as three independent critical ICT third parties can understate real concentration risk if two or three of them run on the same hyperscaler, in this case Azure among other providers for all three companies involved on 3 September.
The actionable step for a financial-services firm or critical-infrastructure operator is to ask each AI vendor which cloud providers and regions sit underneath its service, then record that answer alongside the vendor's own name in the concentration-risk map. EU financial regulators assessing third-party ICT risk under DORA and NIS2 are likely to expect exactly that layer of detail now that an incident like this one has made the question public.
Read next: Nvidia's $250bn OpenAI Guarantee Fell To $120bn | Your AI Vendor Just Got a Letter From Brussels



