C3.ai
United States · c3.ai · 20 vendors
Resilience scores
- Digital Sovereignty: 75
- Digital Resilience: 9
- Financial Resilience: 4
Technology vendors
- Adobe Inc. — Technology — United States
- Anthropic, PBC — Technology — United States
- Twilio — Telecommunications — United States
- and 17 more
Services catalogue
1 service in catalogue across 1 category; runs on 20 sub-vendors.
- C3 AI Suite
Insights
Last updated 2026-09-01 · revision 2
20 direct vendors, 297 subvendors
Direct vendors by controlling owner country (sample)
- Norway: 1
- Denmark: 1
- United States: 15
Subvendors by controlling owner country (sample)
- Belgium: 2
- Russia: 1
- Poland: 3
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
C3.ai exhibits high migration readiness, primarily driven by its advanced and flexible technology architecture. The company's internal tech stack is highly cloud-native, utilizing all three major cloud providers (Amazon Web Services, Microsoft Azure, Google Cloud Platform) and Kubernetes for container orchestration. This multi-cloud, containerized approach signifies a modern, agile infrastructure that is inherently well-suited for migrations, allowing for portability of workloads and reducing lock-in to any single cloud vendor. The use of microservices-enabling technologies like Kubernetes further enhances modularity and ease of movement. Experience with FedRAMP compliance indicates a mature approach to managing complex regulatory environments, which, while potentially adding specific requirements, also suggests established processes for structured migrations. The absence of specified data residency requirements also simplifies migration planning. However, C3.ai's reliance on certain proprietary solutions such as Snowflake for data warehousing, Gurobi for optimization, SAP for ERP integration, and ServiceNow for IT workflows introduces some level of vendor lock-in for these specific functionalities. Migrating these particular components or their data could present challenges and require dedicated effort. A significant gap in the assessment is the lack of financial stability data (revenue concentration, growth history), which is crucial for evaluating the company's ability to fund and execute large-scale migration initiatives. Despite these specific vendor dependencies and the financial data gap, the foundational multi-cloud and containerized infrastructure positions C3.ai with strong capabilities for future migrations.
Compliance
10 in-scope frameworks identified; showing 3.
CCPA — Compliant
C3.ai is headquartered in Redwood City, California, making CCPA directly applicable. The company has published a dedicated California Consumer Privacy Rights notice, demonstrating awareness and active compliance efforts. The risk is Low because: (1) C3.ai primarily processes B2B enterprise data rather than large volumes of California consumer personal information; (2) the company has a published CCPA notice; (3) CCPA enforcement for B2B-focused companies with limited consumer data exposure is lower risk than for consumer-facing businesses.
Evidence: https://c3.ai/legal/ccpa-privacy-notice-for-california-residents, https://c3.ai/legal/privacy-policy, https://oag.ca.gov/privacy/ccpa
HIPAA (source) — Assessment Required
C3.ai explicitly serves the Healthcare & Life Sciences industry and markets AI applications for clinical, claims, and research data. If C3.ai's platform processes Protected Health Information (PHI) on behalf of covered entities (hospitals, health plans, healthcare providers), C3.ai would qualify as a Business Associate under HIPAA and must execute Business Associate Agreements (BAAs) and implement required safeguards. The risk is Medium because: (1) C3.ai's healthcare vertical is a stated business focus; (2) failure to comply with HIPAA as a Business Associate carries civil penalties up to $1.9M per violation category per year; (3) no public BAA template or HIPAA compliance statement was found. However, as an enterprise B2B platform, the actual PHI processing depends on specific customer deployments.
Evidence: https://c3.ai/industries/healthcare-life-sciences, https://c3.ai/company, https://www.hhs.gov/hipaa/for-professionals/covered-entities/index.html
FedRAMP — Compliant
C3.ai displays a FedRAMP badge on its company page and offers AWS GovCloud installation guides on its legal page, strongly indicating FedRAMP authorization. FedRAMP is mandatory for cloud service providers serving US federal agencies. C3.ai's customer base includes the US Army, US Air Force, DLA (Defense Logistics Agency), and other federal entities, making FedRAMP authorization a business necessity. The risk is Low because FedRAMP authorization indicates a rigorous, NIST SP 800-53-based security assessment has been completed and approved by a federal agency sponsor.
Evidence: https://c3.ai/company, https://c3.ai/legal, https://c3.ai/industries/federal, https://marketplace.fedramp.gov
Financials
Three-year financials
- 2026: revenue $250.27M, EBIT -$498.50M, equity $653.75M
- 2025: revenue $389.06M, EBIT -$324.42M, equity $838.30M
- 2024: revenue $310.60M, EBIT -$316.70M, equity $754.00M
Financial Resilience Score: 4/10
C3.ai has a strong liquidity buffer with approximately $575M in cash and marketable securities as of April 30, 2026 (boosted to ~$673M after Tom Siebel's June 2026 stock purchase) and carries no debt. This provides meaningful runway even amid the sharp business reversal. The recurring subscription base (~91% of revenue) and blue-chip customer roster including Shell, Dow, Koch, Nucor, GSK, Con Edison, Duke Energy, Holcim, U.S. Air Force, U.S. Army, DLA, Royal Navy, and NATO provide some revenue stability. However, financial resilience is materially weakened by persistent and widening GAAP losses. The FY26 operating loss of ~$498M against $250M revenue is unsustainable without either revenue reacceleration or dramatic cost cuts. Revenue declined 36% YoY in FY26, a highly unusual reversal for enterprise SaaS, signaling product-market or sales-execution issues. Operating cash burn accelerated from ~$41M to ~$190M in one year. At the current burn rate, existing liquidity funds approximately 3 years, giving limited runway if losses persist. Stock-based compensation of ~$264M in FY26 (>100% of revenue) implies heavy dilution and masks a much larger non-GAAP loss. FY27 guidance calls for further revenue contraction of 4-16% ($210-$240M), indicating the reset period will extend. Governance concerns, prior short-seller allegations, management turnover (CEO handoff back to founder Siebel), and customer concentration risks (notably the Baker Hughes alliance) further constrain resilience.
Key strengths: Strong liquidity buffer of ~$575M in cash/securities with no debt, Recurring subscription revenue base at ~91% of total revenue, Blue-chip customer roster across federal/defense, energy, manufacturing, utilities, Founder/CEO alignment via Tom Siebel's June 2026 personal stock purchase of 6.17M shares at $11.16, 98% of revenue from subscription plus prioritized engineering services
Risk factors: Persistent and widening GAAP losses (FY26 operating loss ~$498M vs $250M revenue), Sharp revenue reversal of -36% YoY in FY26, Accelerating cash burn from ~$41M to ~$190M in one year, Stock-based compensation exceeding 100% of revenue causing heavy dilution, Customer concentration risk, particularly historical Baker Hughes dependence, Management instability with CEO handoff back to founder Siebel, Prior short-seller allegations and class-action litigation history, FY27 guidance implies further revenue contraction of 4-16%, Never achieved GAAP profitability since inception
Revenue by geography
- United States: 90%
- EMEA and Asia-Pacific: 10%
Revenue by product/service
- Subscription: 90.7%
- Prioritized Engineering Services: 7.2%
- Service Fees (consulting, training, implementation): 2.1%
Workforce by country
- Global (total, FY2025): 900
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.