
AI vendor lock-in: how to keep your decision logic when the platform changes
89% of executives believe they could switch AI vendors within a month. Of those who tried, 58% hit failure or unexpected effort. The lock-in is in the rules, not the API.
The reasonable assumption is that AI vendors are interchangeable. They all take text in and give text out. If one gets expensive or falls behind, you move.
Enterprises tested that assumption and found the opposite. Andreessen Horowitz interviewed 100 enterprise CIOs across 15 industries in 2025 and found companies running multiple models, but for capability reasons rather than portability. One buyer described what actually happened:
“All the prompts have been tuned for OpenAI. Each one of them has their own set of instructions and prompts and details… changing models is now a task that can take a lot of engineering time.”
— Enterprise CIO, quoted by Andreessen Horowitz
Switching got harder as the work got more serious. That is the finding that matters, and it points at where the lock-in accumulates. It is not in the API. Anyone can change an endpoint in an afternoon. It is in the instructions, the exception rules, the escalation thresholds, the evaluation criteria, the accumulated corrections that turned a generic model into something that understands how your business decides.
That is the part you thought you owned.
Most executives believe they can leave. Most who tried were wrong.
A survey of 542 US C-level executives and decision-makers at organisations with active paid AI vendor contracts, fielded by the panel firm Centiment between 30 January and 6 February 2026, put the belief and the experience side by side.
89% believed they could switch between AI vendors within a month. Of the executives who had actually attempted a migration, 58% experienced failure or significant unexpected effort.
The same survey found more saying ending their AI services would disrupt key business functions or describing themselves as completely reliant on their AI vendor:
The survey was commissioned by Zapier, which sells integration tooling. It also published its panel, its dates, its screening and its margin of error, which is more than most, and two independent outlets reported it without endorsing it.
Twenty-seven percent completely reliant, and eighty-nine percent confident they could leave within a month. Both numbers describe the same executives.
The layer underneath you moves on somebody else’s schedule
Here is the part that requires no survey and no analyst, because the vendor publishes it.
OpenAI’s deprecations page states its notice policy: at least six months for generally available models, at least three months for specialised variants, and for preview models, retirement “with much shorter notice, such as 2 weeks.”
Then read what happened to fine-tuning, which is the mechanism most companies were told to use to make a model their own.
On 7 May 2026, organisations that had never run fine-tuning lost the ability to start. On 2 July 2026, organisations that had not run inference on a fine-tuned model in the previous 60 days lost it too. From 6 January 2027, existing active customers can no longer create new fine-tuning jobs at all. And inference on your existing fine-tuned models continues only “until the base models are deprecated.”
So a company that invested in fine-tuning as its differentiator now has an asset whose useful life is set by a third party’s roadmap, and the capability to create more of them is being withdrawn on a schedule it did not agree to.
For anyone running plants, this needs no translation. It is a supplier discontinuing a tooling line you built your process around, on their timetable, with your production plan as your problem.
No contract clause recovers that. Architecture does.
And the ground keeps moving above it too
The model layer is not just changing hands, it is changing hands repeatedly.
Stanford’s 2026 AI Index reports that the US and Chinese models “have traded places at the top of performance rankings multiple times since early 2025,” and that the top four companies now sit within 25 Elo points of one another on human-preference rankings. Leadership is a temporary condition.
The economics move as fast. MIT FutureTech’s 2026 analysis, built on the largest assembled dataset of benchmark-running prices, found that the price for a given level of benchmark performance falls roughly 5 to 10 times per year, while at the same time the price of running frontier models is rising 3 to 18 times per year as models get larger and reasoning demands grow. Both are true. Whatever calculation justified your current model choice will be wrong within a year, in one direction or the other.
Enterprise buying reflects that. Menlo Ventures’ survey of around 500 US enterprise decision-makers in November 2025 put one provider at 40% of enterprise LLM spend, up from 12% two years earlier, while another fell from 50% to 27% over the same period. Treat share-of-spend estimates from a venture firm as directional. The magnitude of the swing is the point.
There is a further wrinkle worth knowing. The same Stanford report notes that the benchmarks everyone uses to make these decisions “face growing reliability and gaming concerns, with error rates up to 42% on widely used evaluations.”
Which means the only evaluation criteria you can actually trust for your own business are the ones you built yourself, against your own work. That is not a philosophical point. It is an asset, and we will come back to who owns it.
What you actually own, according to the contracts
The major providers are generous and consistent on one thing. You own your inputs and you own your outputs. OpenAI’s services agreement assigns to the customer all of its right, title and interest in the output. Anthropic’s commercial terms say the customer retains rights to its inputs and owns its outputs.
Now read what happens at the end. Anthropic’s terms, in ten words: “Upon termination, Customer may no longer access the Services.”
You own the outputs. You lose the machine that produced them. There is no export right, no portability commitment, no transition assistance obligation.
And here is the gap that should concern a multi-site operator more than either of those. Search the published terms of any major provider for language covering prompt libraries, agent configurations and evaluation sets, and you will find nothing. Fine-tuned models are barely addressed. The specific assets that encode how your business decides, the ones that took two years and a hundred corrections to build, are not named as assets at all.
We looked for legal analysis of this. One law firm’s 2026 guidance on AI contract architecture advises that “the contract should address whether the customer owns the fine-tuned model, has a license to it, or simply has the right to use it during the term,” which is sound and incomplete. It says nothing about prompt libraries, agent configurations or evaluation sets.
There is no substantive published analysis, legal or academic, on who owns those things when a contract ends. That is not a gap in our research. It is a gap in the field, and it is currently being resolved by default in favour of whoever hosts them.
(Contract terms quoted are current as of the dates published by each provider and are revised frequently. Check the live text before relying on any of it.)
A regulator looked at this, and nobody is coming
The adjacent, more mature market has already been examined with statutory powers.
The UK Competition and Markets Authority concluded a market investigation into cloud infrastructure in July 2025 and found, in its own words, that technical and commercial barriers “lock customers into their initial choice of provider.” Its supporting evidence is stark: fewer than 1% of customers switch provider each year, and multi-cloud remains uncommon among small and medium customers.
What switching actually takes came from customers testifying to that inquiry. One large supermarket said even the simplest workloads take more than a month to port and the most complex can take over a year.
“12 months and tie up approximately 1000 employees.”
— Financial institution, testimony to the UK Competition and Markets Authority
The European Union reached the same conclusion and legislated. Under Article 29 of the Data Act, providers of data processing services may charge only reduced, direct-cost switching fees for a transition period, and from 12 January 2027 they may impose no switching charges at all. A legislature examined this market and concluded that switching costs were structurally anti-competitive enough to require abolition by statute.
Then there is what happened next in the UK. Kip Meek, who chaired the CMA inquiry that produced that finding, resigned a year early in March 2026 after the regulator declined to act on his own group’s recommendations. His words to the press: “I’m still concerned that the pace is going slowly.”
The official who investigated lock-in with compulsory powers, found it real, and then quit because nothing was being done.
This is cloud infrastructure rather than AI platforms, and the analogy should be stated rather than assumed. It is also the closest thing to a controlled experiment anyone has: a more mature version of the same market structure, examined by a regulator, with the answer already in.
The lesson for anyone planning next year’s capex is simple. No remedy is arriving from outside on a timescale that matters. The only lever available is your own architecture.
Own the content, rent the containers
Which brings us to the principle, and to what it means in practice.
Think of the stack as three layers.
The access layer, where your people and your agents actually work day to day, built on whichever tools fit each task. Replaceable by design.
The layer you own permanently. Your business rules. Your decision logic. Your ontology, meaning the definitions of what a job, a load, a work order, a placement and a non-conformance actually are in your company. Your escalation thresholds. Your evaluation criteria, the tests that tell you whether a given model is doing your work acceptably. This is the layer that took years to accumulate and that no vendor can rebuild for you.
The platform layer, wherever models and compute run. Also replaceable, and, on the evidence above, replacing itself whether you participate or not.
Own the content. Rent the containers. The tools change, the models change, the pricing changes twice a year. The layer in the middle is the only part that is genuinely yours, and it is currently the part most companies are storing inside somebody else’s product.
There is real evidence that this layer does work rather than merely sounding tidy. A peer-reviewed benchmark published through the ACM tested identical questions against an enterprise SQL database directly and against a knowledge-graph representation of the same data with an ontology and mappings on top, a threefold improvement with no change to the underlying data:
The authors worked at a company selling knowledge-graph tooling, the question set was small and the model is now several generations old, so take the direction rather than the decimals. The mechanism is the finding: the same data, described in your own terms, produces materially better decisions.
“The data moves, but the meaning is lost in translation.”
— Continuous Delivery Foundation, a Linux Foundation project
That is what a migration costs when the meaning lives in the vendor’s platform rather than in yours.
Worth noting the tension honestly. The best-articulated version of this idea in the market belongs to a platform vendor whose own documentation describes its ontology as sitting “on top of the digital assets integrated into” its platform. The concept is right. The ownership model is exactly the thing to avoid.
What about open standards
They are real, they are new, and they are not yet a substitute for owning the layer.
The Model Context Protocol began as one company’s specification in late 2024 and moved into neutral governance under the Linux Foundation’s Agentic AI Foundation in December 2025, alongside contributions from several of the largest platform providers. That is genuine multi-vendor governance, roughly nine months old as of writing. The Agent-to-Agent protocol followed a similar path.
Adoption is harder to assess honestly. Every MCP adoption statistic currently circulating traces back to content farms citing each other, and no credible independent measurement of enterprise adoption exists yet. So the honest position is that the governance is real, the portability is unproven, and an academic survey of the four competing agent protocols concluded they are complementary rather than substitutable, which means adopting “the standard” is not one decision.
Build for these protocols. Do not treat them as the answer to who owns your decision logic.
What to do about it
Five questions, and any executive can ask all of them this week.
- If your primary model provider doubled its price next quarter, what would move and what would break?
- Where do your evaluation criteria physically live, and who else can read them?
- Which of your business rules exist only as prompts inside one vendor’s console?
- If the contract ended on Friday, what would you still have on Monday?
- Who inside your company can explain the decision logic without opening the vendor’s product?
If the answers are uncomfortable, the remedy is structural rather than contractual. An operating system built for your organisation alone puts the rules, the context and the evaluation frameworks in a layer you keep permanently, with the tools above and the platform below both swappable. It starts with a charter phase that maps what actually needs rebuilding, and it starts at $40,000.
The charter phase is eight weeks and it produces something usable on its own: a written map of every core process worth rebuilding, prioritised, and a working operating core for the first wave to plug into. Compare that against the financial institution that told the CMA a platform migration would take twelve months and a thousand employees. The charter is what makes that number never apply to you.
That is the deepest of the three ways in, and most companies should not begin there. The sequence that works is the one described in the difference between a pilot and a proof-of-concept: prove one workflow with a baseline and a real decision point, then widen. This layer becomes urgent at the point where the same question gets asked differently at every plant, branch or site, and where the answer has quietly become the property of a company you do not control.
It is the same pattern as every industry that runs the physical world. The tools arrive where they demo well. The value accumulates somewhere nobody is looking at, and then somebody else owns it.
Most companies find the list is longer than they expected, and considerably shorter than it will be a year from now.
Get StartedWhat is AI vendor lock-in?
Dependence that accumulates in the layer above the API rather than in the API itself: prompts, instructions, exception rules, escalation thresholds, agent configurations and evaluation criteria that were tuned to one provider over time. Andreessen Horowitz's 2025 survey of 100 enterprise CIOs documented enterprises finding that changing models had become an engineering project rather than a configuration change, precisely because the decision logic had been welded to one vendor.
Can you really not switch AI vendors easily?
Most executives believe they can. A February 2026 survey of 542 US C-level executives found 89% believing they could switch within a month, while 58% of those who had actually attempted a migration reported failure or significant unexpected effort. In the adjacent cloud market, the UK Competition and Markets Authority found that fewer than 1% of customers switch provider each year and concluded that technical and commercial barriers lock customers into their initial choice.
What do you actually own under a standard AI vendor contract?
Your inputs and your outputs, which the major providers assign clearly. Beyond that, very little. Anthropic's commercial terms state that upon termination the customer may no longer access the services. No major provider's published terms address ownership or export of prompt libraries, agent configurations or evaluation sets, and there is no substantive published legal analysis of who owns those at contract end.
Do open standards like MCP solve this?
Partly, and not yet. The Model Context Protocol moved from one vendor's specification into neutral governance under the Linux Foundation's Agentic AI Foundation in December 2025, which is real multi-vendor stewardship. But no credible independent measurement of enterprise adoption exists, and an academic survey of the four main agent protocols found them complementary rather than substitutable. Protocols move data between systems. They do not decide who owns the meaning.
What should sit in the layer a company owns?
Business rules, decision logic, the ontology defining what each core entity actually means in that company, escalation thresholds, and evaluation criteria. Evaluation criteria matter more than they appear to: Stanford's 2026 AI Index reports error rates of up to 42% on widely used public benchmarks, which makes a company's own tests the only trustworthy basis for judging whether a model is doing its work acceptably.
SOURCES (16)
- Andreessen Horowitz, "How 100 Enterprise CIOs Are Building and Buying Gen AI in 2025", May 2025
- Zapier (fielded via Centiment), "AI vendor lock-in survey", 30 Jan-6 Feb 2026
- OpenAI, "API deprecations page", current as of August 2026
- Stanford HAI, "Artificial Intelligence Index Report 2026, Chapter 2", April 2026
- MIT FutureTech, CSAIL and Sloan, "The Price of Progress: Price-Performance and the Future of AI (arXiv:2511.23455)", 24 March 2026
- Menlo Ventures, "2025: The State of Generative AI in the Enterprise", December 2025
- OpenAI, "Services Agreement", effective 1 January 2026
- Anthropic, "Commercial Terms of Service", effective 17 June 2025
- National Law Review, "Contract Architecture: Core AI Clauses for Vendor Agreements (Mayukh Sircar, Ward and Smith)", 23 June 2026
- UK Competition and Markets Authority, "Cloud Infrastructure Services: Final Decision Report", 31 July 2025
- EUR-Lex, "Regulation (EU) 2023/2854, the Data Act, Article 29", n/a
- The Register, "Cloud inquiry chair quits CMA (Kip Meek, reported by Paul Kunert)", 4 March 2026
- ACM (GRADES-NDA), "A Benchmark to Understand the Role of Knowledge Graphs on LLM Accuracy for Enterprise SQL Q&A (Sequeda, Allemang, Jacob)", n/a
- Continuous Delivery Foundation, "MCP Connects Tools, CDEvents Provides Meaning", 21 August 2026
- The Linux Foundation, "Linux Foundation Announces the Formation of the Agentic AI Foundation", 9 December 2025
- arXiv, "A survey of agent interoperability protocols: MCP, ACP, A2A and ANP", May 2025


