OpenAI

United States · owned by OpenAI Foundation (United States) · openai.com · 45 vendors

OpenAI is an AI research and deployment company. Our mission is to ensure that artificial general intelligence benefits all of humanity.

Resilience scores

Disruption prediction

OpenAI has a 99% probability of disruption in the next 6 months.

Partial disruption reported (last checked 2026-09-18 15:25 UTC): Elevated errors affecting ChatGPT Work mode

26 of OpenAI's 45 vendors monitored for disruptions.

Technology vendors

Services catalogue

42 services in catalogue across 8 categories; runs on 45 sub-vendors.

Insights

Last updated 2026-07-18 · revision 25

45 direct vendors, 324 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

OpenAI exhibits high migration readiness, primarily driven by its highly modern and cloud-native technology stack. The use of Microsoft Azure, Kubernetes for containerization, Python, and robust CI/CD pipelines signifies a flexible, modular, and portable infrastructure. This cloud-centric architecture, coupled with custom AI accelerators and distributed model training, positions OpenAI well for adapting to new environments or evolving infrastructure needs. Financially, OpenAI's explosive growth and projected $13B revenue by 2025 provide substantial resources to fund any large-scale migration initiatives without significant financial strain. From a regulatory standpoint, OpenAI has established strong compliance frameworks for GDPR, CCPA, and SOC 2 Type 2, and supports customer HIPAA compliance. Its global data processing capabilities, with OpenAI Ireland Limited acting as the EU data controller, and support for data processing addendums, demonstrate an ability to navigate complex data residency requirements. While the "Total Vendors: 0" entry is contradictory, the presence of 74 services with vendor HQ countries in 8 unique nations suggests a diverse vendor ecosystem. However, the "Vendor Lock-in Risk: Unknown" is a critical information gap. Without knowing the actual number of distinct vendors, contract complexities, and the criticality of each service, assessing the true extent of vendor lock-in and its potential impact on migration remains challenging. The "Assessment Required" for NIS2 and "Unknown" for ISO 27001 also represent areas where further clarity would enhance migration planning. Despite these unknowns, the strength of the tech stack and financial position significantly outweigh potential challenges.

Compliance

11 in-scope frameworks identified; showing 3.

SOC 2 (source) — Compliant

Risk is LOW because: (1) OpenAI has confirmed SOC 2 Type 2 certification for its API, ChatGPT Enterprise, and ChatGPT Team products, verified by an independent third-party auditor; (2) SOC 2 Type 2 is an operational audit covering a period of time (typically 6-12 months), demonstrating sustained control effectiveness; (3) annual renewal and penetration testing are confirmed; (4) this is the most directly evidenced compliance framework for OpenAI with explicit public confirmation from official sources; (5) SOC 2 non-compliance risk is low given confirmed certification, though scope limitations (not all products covered) warrant monitoring.

Evidence: https://openai.com/security-and-privacy/

US State AI Regulations — Assessment Required

Risk is MEDIUM because: (1) Multiple US states have enacted or are enacting AI-specific regulations (Colorado AI Act SB 205, Illinois AIAA, Texas HB 1709) that impose obligations on developers and deployers of high-risk AI systems; (2) OpenAI's models are used in high-risk contexts (employment, credit, healthcare, education) triggering state-level obligations; (3) Illinois BIPA (Biometric Information Privacy Act) may apply to any biometric data processing; (4) the patchwork of state regulations creates compliance complexity; (5) enforcement is emerging but penalties can be significant.

Evidence: https://openai.com/policies/, https://openai.com/trust-and-transparency/

FTC Act — Assessment Required

Risk is HIGH because: (1) The FTC has opened a formal investigation into OpenAI (confirmed 2023) regarding potential unfair or deceptive practices, consumer protection violations, and data privacy; (2) the FTC's authority under Section 5 of the FTC Act covers deceptive AI claims, privacy violations, and unfair data practices; (3) OpenAI's scale (hundreds of millions of users) and the sensitivity of AI-generated outputs create significant consumer protection exposure; (4) the FTC has signaled aggressive AI oversight posture; (5) potential remedies include consent decrees, civil penalties, and mandatory compliance programs.

Evidence: https://openai.com/about/, https://openai.com/policies/privacy-policy/

Financials

Three-year financials

Financial Resilience Score: 7/10

OpenAI demonstrates extraordinary revenue growth, scaling from ~$28M in 2022 to a reported $10-12B annualized run-rate by mid-2025, one of the fastest software company growth trajectories on record. The company benefits from strong market leadership in generative AI, a strategic Microsoft partnership including preferential Azure compute pricing and up to ~$13B in cumulative commitments, and ample funding runway with over $60B raised cumulatively through 2025 including a SoftBank-led round at a $300B valuation. However, financial resilience is tempered by significant unprofitability at scale, with a reported ~$5B operating loss in 2024 driven by ~$7B in annual compute spending and ~$1.5B in salaries. The company is entirely dependent on continued equity fundraising to fund operations, with no clear path to profitability disclosed. Governance instability, including the November 2023 board crisis and ongoing tension around the nonprofit-to-for-profit conversion, adds structural uncertainty. Competitive pressure from Google Gemini, Anthropic Claude, Meta Llama, xAI, and Chinese labs like DeepSeek is compressing pricing and eroding differentiation. Regulatory risks from the EU AI Act, US state-level laws, and copyright litigation (NYT v. OpenAI) could impose material costs. Overall, OpenAI has strong short-term resilience due to recent capital raises and revenue momentum, but long-term resilience depends on achieving operating leverage before capital markets tire of funding losses.

Key strengths: Market leadership in generative AI with ~500M weekly active ChatGPT users, Strategic Microsoft partnership with preferential Azure compute pricing, Revenue growth exceeding 100% YoY across multiple years, Over $60B in cumulative funding raised through 2025, Multiple monetization vectors: consumer subscriptions, API, enterprise, $300B valuation in SoftBank-led 2025 round, Strong brand and talent moat as leading AI lab

Risk factors: Unprofitability at scale with ~$5B operating loss in 2024, Extreme compute dependence (~$7B annual spend concentrated with Azure), Governance instability including November 2023 board crisis, Competitive pressure from Google, Anthropic, Meta, xAI, and Chinese labs, Regulatory risk from EU AI Act and copyright litigation, Customer concentration through Microsoft Azure OpenAI Service, Capped-profit structure complicating future fundraising, Rising cost of frontier training runs, Ongoing Elon Musk lawsuits

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report