Your Business Continuity Plan Has an AI Gap
Most small business continuity plans were written with a fire, a flood, a theft and a dead server in mind. They are usually sensible documents. They also almost never mention the assistant three people now use to write every quote, because nobody procured it, nobody put it on the systems list, and it arrived after the plan was last opened.
AI dependencies fail in three ways your plan does not cover
| Failure | What makes it different |
|---|---|
| Outage | Familiar, and several providers can be down at once |
| Degradation | Answers get worse, nothing is declared, nobody notices for weeks |
| Deprecation | Permanent, short notice, and not a disaster scenario at all |
Degradation is the one nothing in a traditional plan addresses. Systems in a continuity plan are up or down. A model that has been updated and now handles your document format slightly worse is neither, and the failure shows up as a gradual rise in corrections nobody connects to a cause.
Deprecation is not an emergency and has the same effect as one. Google began removing Google Assistant from Android phones and tablets on September 4, and its own notice was explicit that once availability is removed you can no longer use or switch back. A product being retired on schedule is not in anybody's risk register, and it takes the capability away just as permanently as a failure would.
Find the real dependencies in ten minutes
Ask the team which AI tools they use, with no blame attached. Then ask the question that actually matters: what would you do tomorrow if this stopped working.
Most answers will be some version of go back to doing it the old way, more slowly. Those are conveniences and they need nothing from your plan. You are looking for the one or two where the honest answer is that the work would stop, or that nobody currently knows the old way.
That second condition catches more businesses than the first. A quoting process that ran on a template and a calculator two years ago is now a process nobody has done manually since, and the knowledge went with the habit.
Four additions to the plan
1. List AI tools as systems. If it is load-bearing, it belongs on the same list as your accounting package, with an owner and a note on what depends on it. Most of these never made it onto a systems list because nobody raised a purchase order.
2. Write the manual path for each dependency, and test it once. Not a paragraph saying revert to manual. The actual steps, and one person actually doing it once a year. An untested fallback is a sentence, not a plan, which is the same argument as testing your backups rather than trusting that they run.
3. Add a degradation check. One line in a monthly review: has anyone noticed output getting worse. That is the only detection mechanism most small businesses will realistically operate, and it beats nothing by a wide margin. The systematic version is in watch what it does, not what it says.
4. Keep a deprecation column. For each tool, whether you have a contract or a free account, what notice you would be entitled to, and what you would do instead. Free products owe you nothing, which we set out in free AI tools and what they cost your business.
Why a second provider is a weaker hedge than it looks
The standard advice is to keep a second AI vendor configured. It is reasonable advice and it covers a narrower case than people assume.
Multiple major providers have been disrupted within hours of each other, and a hedge that fails at the same time as the thing it was hedging is not a hedge. It also does nothing for degradation, since a second model that is merely different is not obviously better, and nothing for a deprecation that removes a capability rather than a supplier.
Keeping switching cheap is still worth doing, and for different reasons: pricing moves, quality moves, and the lock-in argument in hedging against model lock-in holds on its own. Treat it as commercial flexibility rather than as your continuity answer. The continuity answer is the non-AI path, covered in when your AI provider goes down.
The free part
One of these costs nothing and is worth more than the rest combined. Once a year, have someone do the most AI-dependent task in your business entirely by hand, and time it.
You find out whether the manual path still exists, how long it actually takes now, and whether anyone remembers it. Businesses that run that exercise usually discover the fallback they assumed they had needs an hour of work to be real, and an hour is a much better price than finding out during the outage.
Frequently Asked Questions
What is a business continuity plan?
A written description of how the business keeps operating when something it depends on stops working, and how it recovers afterwards. For a small business it is typically a few pages: what could interrupt us, how long we could tolerate each interruption, what we do in the meantime, and who decides. Most were written with fire, flood, theft and hardware failure in mind, which is why AI dependencies tend to be absent from them.
Why do AI dependencies need separate treatment in a continuity plan?
Because they fail in ways the plan was not written for. A server either works or it does not. An AI service can degrade rather than stop, returning worse answers without any outage being declared. It can also be deprecated on a month’s notice, which is not a disaster scenario at all but has the same operational effect. And several providers can be unavailable at once, which makes a second AI vendor a weaker hedge than it appears.
Should we have a backup AI provider?
It helps and it is not the control people assume. A second provider covers a single-vendor outage, and it does nothing for a correlated one, which has happened. The stronger question is whether each AI-dependent step has a non-AI path, even a slow one. If quoting still works with a template and a calculator when the assistant is down, you have continuity. If nobody remembers how, you have a dependency.
What is the difference between an outage and a deprecation?
An outage is temporary and everyone knows about it. A deprecation is permanent and usually announced with a short notice period, after which the tool is gone and cannot be switched back on. Google removed Google Assistant from Android phones and tablets starting September 4, 2026, with its own notice stating that once availability is removed you can no longer use or switch back. Continuity plans handle the first case and rarely mention the second.
How do we find our AI dependencies?
Ask the team, without blame, which tools they use to do their jobs, then ask a second question that matters more: what would you do tomorrow if this stopped working. The second answer tells you whether it is a convenience or a dependency. Most businesses find one or two steps where the honest answer is that the work would simply stop, and those are the only ones worth planning around.
Test the fallback before you need it
We map what your operations actually depend on, check whether the manual path still works, and write the part of your continuity plan that nobody has updated since AI arrived.
Related Articles
Your Team Is Doing Business on WhatsApp
Does Your Business Have an AI Policy? Half Don’t
Deepfakes Are a Business Threat Now: How to Defend
Ajan leads the ChatGPT.ca team: 200+ custom GPT builds and automation projects for 50+ businesses across 20+ industries. Based in Markham, Ontario. PIPEDA-compliant solutions.