Warnings from chip and technology execs this week that AI demand is overwhelming global memory supply serve as a stark reminder for businesses that IT infrastructure should not be taken for granted.

While much of the public debate has focused on the impact on consumer devices, the greater risk may lie in the back offices of businesses, where rising costs and delayed infrastructure can disrupt operations, investment plans, and growth.

Cloud infrastructure now sits at the heart of modern business. Research from the OECD has repeatedly shown that digital infrastructure underpins productivity growth, innovation, and competitiveness across advanced economies. At the same time, the scale of demand being driven by AI is unprecedented. Recent research from Forrester shows that the rapid expansion of AI workloads is putting acute pressure on compute and memory availability. With supply concentrated among a small number of manufacturers, infrastructure costs are rising, and capacity is becoming harder to secure.

What this means for businesses is that cloud computing is no longer insulated from the physical constraints of global supply chains. As demand for memory-intensive AI workloads accelerates, rising costs and longer lead times are feeding directly into operational decisions. Public cloud providers are better placed to absorb some of that shock, having secured components years in advance through long-term, bulk purchasing agreements. Private cloud environments, by contrast, are more directly exposed to price volatility and supply delays.

For organizations running critical systems outside the hyperscale platforms, that exposure translates into higher costs, postponed projects, and difficult trade-offs about where and how fast they invest. In practical terms, this exposure is already shaping day-to-day decisions. Server refresh cycles are being extended, AI pilots are being reconsidered, and supplier negotiations are becoming more complex. Procurement teams are spending longer securing capacity, often at higher and less predictable price points. Technology and finance leaders are having to balance immediate cost pressures against longer-term transformation goals, frequently opting for caution despite knowing that delay itself carries strategic consequences.

The challenge for business leaders is that this is not a short-lived disruption. Pressure on memory supply could persist for at least the next two years as AI demand continues to outpace new capacity. Few organizations can afford to put major transformation programs, data center exits, or AI initiatives on hold for that long.

Waiting carries its own costs, from delayed productivity gains and rising operational spend to the risk of falling behind competitors that adapt faster. For most businesses, the question is how exposed they are if they do not find a way to manage.

The practical response is to design for resilience rather than assume a return to abundance. That means reducing dependence on single cloud models, building flexibility into infrastructure choices, and ensuring workloads can move as conditions change. In an environment of volatile costs, socio-economic instability, and constrained supply, resilience is a commercial necessity.

Importantly, this reassessment is not being driven by industry alone. Regulators are increasingly treating dependence on cloud and third-party technology providers as a systemic resilience issue. In the UK, for example, a new Critical Third Parties regime overseen by the Bank of England, the Prudential Regulation Authority, and the Financial Conduct Authority brings major outsourced technology services under direct regulatory scrutiny. The logic is clear. Disruption at a small number of critical providers has the potential to cascade across firms, markets, and, ultimately, the wider economy.

While the regime is focused initially on financial services, its implications are much broader. It reflects a growing recognition that cloud infrastructure now underpins core business operations across sectors, from payments and logistics to healthcare and public services. Regulators are no longer asking whether organizations use the cloud, but whether they understand and can manage the risks that come with its dependence.

For business leaders, that shift should tell its own story. When regulators start talking about cloud resilience in terms of financial stability and systemic risk, it is clear that the cloud has become more than just an IT concern. Almost certainly, the next phase of cloud adoption will be shaped by realism, with business risk, compliance, and economics built into the decision-making process more than ever before.

Looking ahead, the defining feature of modern organizations will be how they respond to sustained constraint, not temporary disruption. As discussions at Davos this year have made clear, resilience and growth are no longer opposing ideas.

In an AI-driven economy shaped by physical limits (from memory chips to energy and infrastructure), organizations that treat resilience as part of their growth strategy will move faster, not slower. Memory shortages are unlikely to disappear overnight. What will change is how seriously businesses plan for them. Those that adapt early will be better placed to deploy AI at scale, manage costs, and maintain momentum. Those that do not risk discovering that infrastructure, once ignored, has become their biggest strategic bottleneck.