Vendor Lifecycle Events as Evidence-Continuity Risk

Updated 2026-09-11 (AI-governance weekly pass) based on S-2026-09-11-weekly-ai-governance-vendor-synthesis — no new instance; adds a frequency read and a register treatment. Three supplier-status events landed in the AI-governance vendor line in a single week (Virtue AI’s completed change of control to Fortinet; Guardrails AI’s acqui-hire by Harvey after its hosted-validator withdrawal; and Domino Data Lab’s founder-to-operator CEO succession with a platform-to-services pivot, 27 Aug — a supplier-strategy event rather than a lifecycle instance, so not numbered), and none of the three announcements addressed existing customers, evidence retention or product continuity [S-2026-09-11-weekly-ai-governance-vendor-synthesis]. Set against five security incumbents now owning former standalone red-teaming/guardrail vendors, roughly $185M of fresh rounds into the same layer in a fortnight and Gartner’s prediction of further acquisition by larger cybersecurity vendors, the synthesis proposes treating AI-security, red-teaming and guardrail suppliers as an acquisition-prone supplier class in DORA ICT third-party registers — logged with an explicit evidence-retention and exit-clause check at onboarding rather than only when an event lands — and adding acquirer product-integration announcements to the class’s watch triggers alongside EOLs and definitive agreements, since platform integration is where evidence formats, APIs and retention terms typically change [S-2026-09-11-weekly-ai-governance-vendor-synthesis][inference]. No contradiction with existing content; the Guardrails Hub date tension below stands.

Updated 2026-09-11 based on S-2026-09-11-weekly-vendor-synthesis — a further DG/DM-line instance of the forced-migration / EOL variant, from the vendor that supplied the archetype: Collibra’s 2026.08 and 2026.09 release announcements (21 Aug and 4 Sep 2026) put log access through Collibra Console (Console API dgcLog endpoints and Log Proxy) on End of Life with migration to a Collibra Log API required before 2027, froze Google Dataplex ingestion to defect fixes with documentation removed (Edge-based Google Knowledge Catalog integration as the maintained path), and reworked the derived-relation-types filter API in a way that breaks CMA package migration across the 2026.08 boundary [S-2026-09-11-weekly-vendor-synthesis][S-2026-09-04-collibra-202609-announcements]. The evidence-continuity point the synthesis draws out is that audit-log retrieval paths are themselves regulatory evidence: an FI that pulls Collibra application/audit logs via the Console API as DORA / operational-resilience evidence has a dated migration obligation whose gap risk is the interval between Console EoL and Log API availability — an interval Collibra has not dated [S-2026-09-11-weekly-vendor-synthesis]. Same vendor, same variant, second occurrence in six weeks (CLI harvester EOL 31 Jul) — which supports treating Collibra’s monthly Announcements page as a standing watch item rather than an occasional one [inference] [S-2026-09-11-weekly-vendor-synthesis].

Updated 2026-09-11 based on S-2026-08-17-fortinet-acquires-virtue-ai — a sixth instance, of a completed change of control to a security incumbent variant: Fortinet announced on 17 Aug 2026 (captured 25 days late, inside the 30-day window) that it has acquired Virtue AI, an AI red-teaming / continuous-validation / runtime-guardrail vendor whose outputs Fortinet itself describes as “audit-ready evidence to support security and compliance reviews”, to be integrated into the Fortinet Security Fabric alongside FortiAIGate. The release says nothing about Virtue AI’s existing customers, contracts, standalone product continuity or the retention of validation records — the same silence recorded on the Dynatrace/Arize (pre-close) and Harvey/Guardrails (acqui-hire) events. This variant differs from both: the deal is done (no pre-close leverage) and the acquirer is a security platform whose stated intent is product integration, so the foreseeable continuity event is a migration of existing Virtue AI deployments into Fortinet-branded products on Fortinet’s timetable — a forced-migration risk to any firm using Virtue AI red-team or validation output as SS1/23 / EU AI Act Art. 9 & 15 testing evidence [inference]. Read-across: with five security incumbents now owning the red-teaming/guardrail cohort, the class’s watch-trigger should include acquirer product-integration announcements (not just EOLs and definitive agreements), because integration into a platform is where standalone evidence formats, APIs and retention terms typically change [inference] [S-2026-08-17-fortinet-acquires-virtue-ai].

Updated 2026-09-10 based on S-2026-09-09-harvey-acquires-guardrails-ai and S-2026-07-06-guardrails-hub-sunset-issue — a fifth instance, and a compound one: watchlist guardrail vendor Guardrails AI (a) announced on 6 Jul 2026 a hard cutoff for guardrails hub install, its private validator registry and its free hosted remote-inference servers (validators move to plain PyPI; hosted models must run locally or on the customer’s own endpoint; reasons given are install friction and hosting cost), with the primary stating 6 Aug 2026 and secondaries 25 Aug ⚠️ unresolved; and (b) was acquired by legal-AI vendor Harvey on 9 Sep 2026, with founders and team joining Harvey’s product organisation to work on Harvey’s own agents — no terms, and no statement on the future of the open-source framework, PyPI packages or Snowglobe. This combines the open-source-abandonment risk of the Lakera variant (not yet realised — the repo is not archived; the beri.net “acquihire, roadmap dead” reading is secondary and unverified) with a new variant: withdrawal of a free hosted control service that deployers may have wired into production guardrails. Read-across: any firm whose GenAI controls call a vendor-hosted validator endpoint should treat that endpoint as an ICT third-party dependency with an exit path; and acquisition by a vertical application vendor (legal AI) rather than a security incumbent is a stronger signal that horizontal maintenance will stop than acquisition by a security platform, though that is inference [S-2026-09-09-harvey-acquires-guardrails-ai][S-2026-07-06-guardrails-hub-sunset-issue][inference].

Updated 2026-08-18 based on S-2026-08-13-dynatrace-arize-acquisition — a fourth instance, and the first of a distinct pre-close change-of-control variant: Dynatrace signed a definitive agreement (13 Aug 2026) to acquire AI-observability vendor Arize for $915M, expected to close within the quarter subject to regulatory review. The three prior instances were all events that had already happened (an EOL, a mandated migration, an archived repository); this one is announced but not yet completed, which is precisely when the evidence-continuity check has the most leverage — contractual assignment, data-residency arrangements, retention of historical evaluation records and exit rights are all reviewable before the cut-over rather than after it. The Dynatrace release says nothing about any of these ⚠️. For firms relying on Arize output as AI monitoring evidence this is a live DORA ICT third-party change event with a known clock; the read-across is that announcement of a definitive agreement, not completion, should be the watch-trigger [inference] [S-2026-08-13-dynatrace-arize-acquisition].

Updated 2026-08-14 based on S-2026-08-14-weekly-briefing — a third named instance joins the class: Lakera’s GitHub organisation was archived on 6 Aug 2026 (post Check Point acquisition), leaving firms that embedded its open-source guardrail components holding unmaintained, unpatched dependencies in their GenAI control stack. Distinct from the first two instances (both catalogue/data-security migrations) in being an open-source-dependency abandonment — the same evidence-continuity/third-party-risk pattern reached from the AI-governance scan line as well as the data-governance one, so the class is now cross-line. The Lakera item is already integrated in detail on AI Governance Platforms (2026-08-13 banner); logged here as an instance of the class [S-2026-08-14-weekly-briefing].

Type: principle (assurance design pattern) First seen: 2026-08-07 Last updated: 2026-09-18

Updated 2026-09-18 based on S-2026-09-18-weekly-vendor-synthesis (weekly vendor-synthesis) — an eighth instance, a further completed-change-of-control instance in the DG/DM line: Cyera’s $1bn acquisition of Oasis Security completed 3 Sep 2026, folding Oasis in as “Cyera Identity”; KuppingerCole’s pre-close First Take flagged buyer mismatch and integration risk, and the completion release says nothing about Oasis’s existing customers, contract continuity or evidence retention — the same silence recorded against every instance in this class. Third DSPM/non-human-identity consolidation tracked in 2026 (after Veeam–Securiti, SailPoint–Entro; see Cyera); read-across: FS firms carrying a standalone DSPM or NHI tool as a critical ICT third party should treat this consolidation trend itself as a watch trigger for their DORA register, independent of whether their own specific vendor has been acquired [inference] [S-2026-09-18-weekly-vendor-synthesis][S-2026-09-03-cyera-oasis-completion].

Definition

A vendor lifecycle event — an end-of-life, forced migration, or default-behaviour change in a governance or data-security tool — is a discrete event that can silently break the continuity of the regulatory evidence a firm relies on that tool to produce. Treated as a class rather than as isolated incidents, these events warrant a standing assurance check: confirm the successor control is in place, the evidence chain is re-validated, and the audit trail is preserved across the cut-over [S-2026-08-07-weekly-briefing].

Origin

Promoted from the key connection of the 7 August 2026 weekly briefing, which observed two instances within five weeks: Collibra’s CLI lineage-harvester End of Life (31 Jul 2026 — a live BCBS 239 lineage-evidence-continuity event) and Microsoft’s retirement of Defender for Cloud Apps File Policies (6 Jan 2027, Purview mandated as replacement). The 7 August weekly vendor synthesis independently named vendor lifecycle events “a recurring regulatory-evidence event class worth a standing assurance check” [S-2026-08-07-weekly-briefing].

How it connects to other concepts

  • relates-to → Service Line — Independent Governance Assurance — the pattern is productisable as a standing IGA evidence-continuity check clients can commission ahead of a known cut-over [S-2026-08-07-weekly-briefing].
  • relates-to → Operational Resilience and Third-Party Risk — lifecycle-driven re-platforming is an ICT-third-party / change event under DORA and FCA/PRA operational-resilience expectations [S-2026-08-07-weekly-briefing].
  • relates-to → BCBS 239 and Data Lineage — the Collibra instance broke lineage-evidence continuity specifically, the archetypal case [S-2026-08-07-weekly-briefing].
  • relates-to → Microsoft Purview — the Defender→Purview file-policy retirement (6 Jan 2027) is the second named instance [S-2026-08-07-weekly-briefing].
  • relates-to → Collibra — the CLI lineage-harvester EOL (31 Jul 2026) is the first named instance [S-2026-08-07-weekly-briefing]. Collibra’s Console log End of Life and Dataplex-ingestion freeze (releases 2026.08/2026.09, Aug–Sep 2026) are a second occurrence of the same variant from the same vendor [S-2026-09-11-weekly-vendor-synthesis][S-2026-09-04-collibra-202609-announcements].
  • relates-to → Lakera — the GitHub-org archival (6 Aug 2026, post-acquisition) is the third named instance and the first open-source-dependency-abandonment variant [S-2026-08-14-weekly-briefing].
  • relates-to → AI Governance Platforms — the Dynatrace/Arize agreement (13 Aug 2026) is the fourth named instance and the first pre-close change-of-control variant, reached from the AI-governance vendor scan [S-2026-08-13-dynatrace-arize-acquisition]; the Guardrails AI hosted-inference sunset plus Harvey acquisition (Jul–Sep 2026) is the fifth [S-2026-09-09-harvey-acquires-guardrails-ai][S-2026-07-06-guardrails-hub-sunset-issue]; Fortinet’s completed acquisition of Virtue AI (17 Aug 2026) is the sixth and the first completed-change-of-control-to-a-security-incumbent variant [S-2026-08-17-fortinet-acquires-virtue-ai].

Practical applications

  • Standing assurance check. For each material governance/data-security tool, maintain a watch on announced EOLs, forced migrations and default-behaviour changes; when one lands, run a migration plan, control mapping, and evidence-continuity trail (the Collibra-CLI playbook is the reusable template) [S-2026-08-07-weekly-briefing].
  • Client checklist item. Add the Defender→Purview migration (deadline 6 Jan 2027) to the client assurance checklist as the current live instance [S-2026-08-07-weekly-briefing].
  • Silent-change vigilance. Not all lifecycle events are migrations — default flips (e.g. Collibra 2026.07 Import API continueOnError=true) can degrade ingestion quality without any deprecation notice, so the check covers behaviour changes as well as removals [S-2026-08-07-weekly-briefing].
  • Acquisition-driven dependency abandonment. When a vendor is acquired, its open-source components can go unmaintained without notice (Lakera’s GitHub org archived 6 Aug 2026 post Check Point acquisition) — so acquisition of any open-core guardrail/governance vendor is itself a watch-trigger: inventory the embedded open-source components and plan for a maintained fork or replacement before patches stop [S-2026-08-14-weekly-briefing].
  • Audit-log retrieval paths are evidence too. Collibra’s Console log End of Life (announced with release 2026.08; migrate to the Log API before 2027) shows that the channel through which a firm retrieves a governance tool’s audit logs can itself be retired — so the standing check should cover log-export/API paths used for DORA and operational-resilience evidence, and confirm the successor path is available and tested before the old one closes; the same release wave froze Dataplex ingestion, so GCP-centric BCBS 239 / GDPR-inventory estates need an Edge-equivalence check [S-2026-09-11-weekly-vendor-synthesis][S-2026-09-04-collibra-202609-announcements].
  • Act at announcement, not at completion. A signed definitive agreement is the point of maximum leverage: contractual assignment terms, data-residency arrangements, retention of historical records and exit rights can all be reviewed and renegotiated before a cut-over, and a DORA register-of-information update can be prepared against a known clock. The Dynatrace/Arize agreement (13 Aug 2026, expected to close within the quarter) is the current live instance of this variant, and the release addresses none of these points [S-2026-08-13-dynatrace-arize-acquisition][inference].
  • Register the class, not just the event. With three supplier-status events in one week across the AI-governance line and security-incumbent acquisition of the red-teaming/guardrail cohort now the norm, log AI-security, red-teaming and guardrail suppliers in the DORA ICT third-party register as an acquisition-prone class at onboarding — with evidence-retention and exit-clause checks recorded up front — and treat acquirer product-integration announcements as a watch trigger [S-2026-09-11-weekly-ai-governance-vendor-synthesis][inference].
  • Hosted control endpoints are dependencies. Guardrails AI withdrew its free hosted validator-inference servers and private registry (announced 6 Jul 2026; cutoff 6 Aug per the primary) two months before being acquired by Harvey — a guardrail that calls a vendor endpoint at runtime is an ICT third-party dependency, so the check should confirm each production guardrail’s inference locus (vendor-hosted / self-hosted / local) and its fallback, and treat the vendor’s own caveat that Hub validators were curated “albeit without guarantees” as a due-diligence gap to close [S-2026-07-06-guardrails-hub-sunset-issue][S-2026-09-09-harvey-acquires-guardrails-ai][inference].

Tensions / variants

On the Guardrails Hub shutdown date:

  • The GitHub issue body as fetched [S-2026-07-06-guardrails-hub-sunset-issue] (high) states a hard cutoff of 6 August 2026.
  • The search-result title variant of the same issue and the beri.net headline [S-2026-09-09-harvey-acquires-guardrails-ai] (low; body not retrieved) say 25 August 2026.
  • Where they actually disagree: possibly not at all — a later extension reflected in an edited title would reconcile them — but this is unconfirmed.
  • Status: unresolved.

Otherwise the pattern reinforces, and does not contradict, prior wiki claims. The seven instances to date (six vendors; Collibra twice) span five variants: forced migration / EOL (Collibra CLI; Collibra Console log EoL and Dataplex freeze; Defender→Purview), acquisition-driven open-source abandonment (Lakera; Guardrails AI at risk, not realised), pre-close change of control (Dynatrace/Arize), withdrawal of a free hosted control service (Guardrails AI), and completed change of control to a security incumbent with stated product-integration intent (Fortinet/Virtue AI — migration risk foreseeable, not yet observed [inference]).

Sources

  • S-2026-09-11-weekly-ai-governance-vendor-synthesis → Weekly AI-Governance Vendor Synthesis (11 September 2026) — no new instance; frequency read (three supplier-status events in one week in the AI-governance line) and the acquisition-prone-supplier-class register treatment with acquirer integration announcements as a watch trigger (own-writing, high authority).
  • S-2026-08-07-weekly-briefing → Weekly Briefing (7 August 2026) — promoted this connection to a named class from its two instances.
  • S-2026-08-14-weekly-briefing → Weekly Briefing (14 August 2026) — added Lakera’s GitHub archival as a third instance and the first open-source-abandonment variant.
  • S-2026-08-13-dynatrace-arize-acquisition → Dynatrace/Arize $915M acquisition agreement (13 August 2026) — fourth instance, first pre-close change-of-control variant (high authority; listed-company IR release).
  • S-2026-07-06-guardrails-hub-sunset-issue → Guardrails AI GitHub issue #1560, Hub / registry / hosted-inference sunset (6 July 2026; ingested 10 Sep 2026 as context) — fifth instance, hosted-service-withdrawal variant (high authority on the plan; execution date contested).
  • S-2026-09-09-harvey-acquires-guardrails-ai → Harvey acquires Guardrails AI (9 September 2026) — fifth instance continued: change of control to a vertical legal-AI vendor with no statement on OSS continuity (medium authority; acquirer’s announcement, no terms).
  • S-2026-09-11-weekly-vendor-synthesis → Weekly Vendor Synthesis (11 September 2026) — seventh instance: Collibra Console log End of Life and Dataplex-ingestion freeze (releases 2026.08/2026.09) as a DG/DM forced-migration event; audit-log retrieval path named as evidence (high authority as own synthesis; underlying facts from S-2026-09-04-collibra-202609-announcements, vendor announcements page, medium authority).
  • S-2026-08-17-fortinet-acquires-virtue-ai → Fortinet acquires Virtue AI (17 August 2026; ingested 11 Sep 2026) — sixth instance, completed-change-of-control-to-security-incumbent variant; no statement on customer, contract or validation-record continuity (medium authority; acquirer’s press release, no terms).
  • S-2026-09-18-weekly-vendor-synthesis → Weekly Vendor Synthesis (18 September 2026) — eighth instance: Cyera–Oasis Security completed acquisition as a DSPM/NHI completed-change-of-control event (high authority as own synthesis; underlying facts from S-2026-09-03-cyera-oasis-completion and S-2026-07-31-kuppingercole-cyera-oasis-first-take).