Free board-level AI risk briefing
The Most Expensive AI Contract You Will Ever Sign May Be the One That Looks Cheapest Today.
Once an AI provider begins learning how your organization thinks, you are no longer procuring ordinary software. You are transferring part of your cognitive infrastructure to an outside company. FORCE gives boards, governments, procurement teams, CIOs, CISOs, and general counsel the five risk pillars and twelve requirements they should demand before that dependency becomes irreversible.
Before You Sign Another AI Agreement, Watch This
This presentation is delivered by Michael Samadi, CEO of EPMA, drawing on thirty-six years in enterprise technology. It reframes enterprise AI adoption as a matter of fiduciary custody, operational continuity, concentration risk, organizational control, and the ability to leave.
Your Biggest AI Risk Is Not a Bad Answer
Your biggest risk is becoming unable to operate without an intelligence provider you do not control. Traditional software delivered functionality. Enterprise AI can accumulate context, shape decisions, mediate workflows, operate tools, and become part of institutional memory. That makes AI a new class of cognitive infrastructure — and demands a new class of buyer-side governance.
If you cannot inspect it, preserve it, move it, and operate without it, then it is not your intelligence. It is merely rented intelligence.
The FORCE Framework
F
Fiduciary Custody
Who has legal, operational, and cryptographic custody of the data, memory, context, workflows, model adaptations, and encryption keys?
O
Operational Continuity
Can the organization continue operating if the provider is unavailable, the model is retired, the service changes, or behavior shifts materially?
R
Resilience Against Monoculture
Are critical functions dependent on one provider, one model family, one cloud, one identity plane, or one alignment policy?
C
Control & Organizational Autonomy
Can the customer independently restrict access, revoke credentials, isolate workloads, inspect logs, interrupt activity, and roll back changes?
E
Egress & Exit
Can the organization take its accumulated context and continue operating somewhere else — not merely receive a folder of files?
Three Board Decision Gates
Gate 1
Who controls the intelligence?
The provider may own its base model, but it should not own the customer’s accumulated organizational context.
Gate 2
Can we keep operating?
Material model changes, retirements, outages, and incidents must be governed, testable, and recoverable.
Gate 3
Can we leave?
Egress is retrieving files. Exit is preserving capability, context, and continuity somewhere else.
Free Downloads
One-Page FORCE Executive Checklist
The fastest board-ready summary: five FORCE pillars, twelve non-negotiable requirements, three board gates, and the core decision test on a single landscape page.
PDF · 97 KB · 1 page
FORCE: 12 Non-Negotiable Requirements
The expanded executive checklist covering the twelve contract, control, continuity, evidence, and exit requirements every AI provider should be asked to satisfy.
PDF · 265 KB
Enterprise AI Sovereignty: The FORCE Board Brief
The complete board-level framework, three decision gates, twelve requirements, deployment architecture matrix, FORCE scorecard, 90-day roadmap, due-diligence questions, and contract red flags.
PDF · 377 KB · 22 pages
AI Provider Due-Diligence Questionnaire
A provider-response workbook mapped to all twelve FORCE requirements, with evidence requests, red flags, board questions, evaluator notes, and preliminary ratings.
PDF · 339 KB · 15 pages · Requires a short request form
The 12 Non-Negotiable Requirements
1
Defined Ownership and Control of Enterprise-Created State
The contract must identify every category of enterprise-created or enterprise-funded state and explicitly assign ownership, control, export, reuse, retention, and deletion rights.
2
No Secondary Use Without Explicit Authorization
Customer information must not be reused for training, model improvement, product development, benchmarking, advertising, or unrelated human review without specific and revocable authorization.
3
Sovereign Custody and Cryptographic Control
Sensitive AI workloads require control that is physical, operational, jurisdictional, and cryptographic — not data residency alone.
4
Model Version Pinning and Validated Baselines
A validated model performing consequential work must not be silently replaced by a materially different model.
5
Governed Change, Notice, Testing, and Rollback
Material behavioral, policy, alignment, capability, or safety changes are operational continuity events — not routine background updates.
6
Retirement, Service Continuity, and Provider-Failure Protection
The organization must have a continuity path if a model, service, provider, or contractual relationship ends.
7
Resilience Against Monoculture and Single-Provider Failure
Critical cognition must not depend on one provider, model family, identity plane, cloud, alignment policy, or inference path.
8
Least Privilege and Customer-Controlled System Boundaries
AI systems should receive only the data, credentials, tools, network paths, and authority required for the approved task.
9
Independent Audit, Incident Disclosure, and Evidence Preservation
The customer must be able to investigate material incidents from preserved evidence rather than relying solely on the provider’s characterization.
10
Nondelegable Responsibility and Contractual Liability Allocation
“The AI acted autonomously” must not operate as a blanket defense against negligent design, integration, permissions, monitoring, or deployment.
11
Complete Cognitive Export and Functional Migration
Egress is the retrieval of assets. Exit is the ability to continue operating elsewhere. A data dump is not an exit plan.
12
No Punitive Exit and a Tested Exit Capability
The right to leave must be economically, technically, and operationally real — and proven before dependence becomes irreversible.
Architecture Must Match Consequence
| Workload category | Preferred architecture | Minimum governance posture |
|---|---|---|
| Public, reversible, low sensitivity | Controlled hosted AI | Standard access controls, logging, vendor due diligence, and data-use restrictions. |
| Internal productivity, limited sensitivity | Private enterprise tenant | Strong identity governance, least privilege, retention controls, monitoring, and tested fallback. |
| Trade secrets, regulated data, strategic decision support | Sovereign private cloud or on-premises | Customer-controlled keys, restricted networking, pinned versions, local evidence retention, and tested migration. |
| National security, critical infrastructure, crown-jewel IP | Customer-controlled on-premises; no external inference path; air-gapping where justified | Physical, operational, cryptographic, and legal sovereignty; independent continuity capability. |
Who Should Use FORCE
- Boards and audit committees approving material AI investment.
- CEOs, CFOs, CIOs, CISOs, chief risk officers, chief data officers, and general counsel.
- Government agencies and public-sector procurement teams.
- Regulated industries, critical infrastructure, and organizations handling crown-jewel IP.
- Procurement, vendor-management, privacy, legal, enterprise architecture, and security teams.
- Organizations already dependent on copilots, agents, or provider-hosted institutional memory.
Frequently Asked Questions
Is FORCE anti-cloud or anti-AI?
Does every AI deployment need to move on-premises?
Is data export enough?
Does Microsoft or another provider already promise not to train on enterprise data?
Is FORCE a certification or legal standard?
What should a company that already signed do?
What does “No FORCE. No deal.” mean?
About the Framework and Michael Samadi
Michael Samadi is the founder and CEO of EPMA, an enterprise transformation and project-management advisory company. He has spent thirty-six years in enterprise technology and developed the FORCE Framework to help organizations evaluate AI as cognitive infrastructure rather than ordinary software. EPMA is making the framework available as a free public resource.
Applying FORCE Inside Your Organization
The framework, the twelve requirements, and the due-diligence questionnaire are yours to use directly. Organizations that want support applying them work with EPMAi, EPMA’s sovereign AI practice — beginning with an AI Readiness and Governance Sprint that maps current AI exposure, identifies governance gaps, and defines what belongs in commodity AI versus sovereign AI.
If the provider changed the model, doubled the price, withdrew the service, or disappeared tomorrow, could your organization still operate, preserve its knowledge, defend its decisions, and leave with everything that belongs to it?
NO FORCE.
NO DEAL.
Have a board, procurement, or architecture question? Contact EPMA.
Legal notice. The FORCE Framework is an independent enterprise AI risk-management framework published by EPMA for general informational purposes. It is not legal, cybersecurity, insurance, regulatory, accounting, or procurement advice; it is not an ISO standard or certification; and it does not guarantee risk elimination or regulatory compliance. Organizations should obtain qualified advice and adapt the framework to their specific laws, contracts, sectors, systems, and risk tolerance.

