What does AI vendor lock-in actually look like?
AI vendor lock in is the point where leaving your supplier means rebuilding your process from scratch. It rarely arrives as a decision. It accumulates: the machine runs on their account, the logic lives somewhere you cannot see, your data has been reshaped into their format, and the only person who understands the thing invoices you monthly.
None of that is necessarily malicious. Plenty of it is just how a build goes when nobody asked the question at the start. But the effect is the same, and the effect is that the price of your renewal is set by how expensive it would be to leave.
Why does it matter more with AI than with other software?
Because the machine ends up holding your process, not just your records.
When you leave a bookkeeping package, you export the ledger and import it somewhere else. Painful, survivable. When you leave an AI build, the thing you lose is the encoded version of how your business makes decisions: the rules, the exceptions, the tone, the escalation logic, all the judgement that was extracted from your people and turned into something operable. If that is not yours, you have paid to have your own process taken into custody.
That is the asymmetry worth understanding before you sign anything.
What should you actually own?
Six things. Ask about each one explicitly and get the answer in writing.
- The account. The machine should run on infrastructure in your name, that you pay for and can log into. Not on your supplier's account with your workload inside it.
- The code and configuration. Whatever encodes the logic, in a repository you have access to, today, not on request.
- The data. Yours, exportable in a usable format, at any time, without a fee and without a notice period.
- The prompts and rules. These are the distilled version of your process and they are the most valuable artefact in the build.
- The documentation. Enough that a competent third party could take it over. This is the real test.
- The keys. Your model provider accounts, your integrations, your credentials.
Our position is stated on the site as your keys, your machine, and it is meant literally rather than as a slogan.
How do you test a supplier's answer?
Ask one question: if we parted company tomorrow, what exactly do we have?
The answer tells you everything. A supplier who can describe the handover in concrete nouns, the repository, the account, the documents, the export, has built something you own. A supplier who talks about how unlikely that scenario is has answered a different question, and you should notice.
A second useful test is to ask for the documentation now rather than at the end. Documentation written at handover is written by someone leaving. Documentation written as you go is a control.
Is a proprietary platform always wrong?
No, and pretending otherwise would be dishonest. Sometimes a packaged product is exactly right, and the lock in is a fair price for not having to build anything.
The distinction is what is inside it. A standard product doing a standard job, where your process is unremarkable and the vendor is stable, is a reasonable trade. A platform holding logic that is specific to how your business competes is a different proposition, because that logic is the thing you would be paying to rebuild.
Ask yourself which one you are buying. If the answer is that the machine encodes something only your business does, own it.
What about the model itself?
You will not own the model, and you do not need to. What matters is that it is replaceable.
Models are components and they change constantly. A well built machine treats the model as a part it can swap, so that when a better or cheaper one arrives, or a provider changes its terms, you change a setting rather than rebuild. A machine welded to one provider's specific behaviour is a fragile machine regardless of who owns the code.
This is also a practical reason to care about the surrounding engineering rather than the model, a point we make in ChatGPT or a custom AI build.
What should the contract say?
That you own the deliverables, that data is exportable on demand, that documentation is a deliverable rather than a courtesy, and what happens on termination.
Also worth agreeing: who holds the accounts, what notice applies, what handover assistance is included, and whether ongoing fees buy maintenance or merely permission to keep using it. Those are ordinary commercial terms and a supplier who resists writing them down has told you something useful for free. Business.gov.au covers contract basics, and a lawyer reading a short agreement is cheap.
Ask before you sign
Lock in is easy to avoid at the start and expensive to unwind later. The whole defence is six questions asked before money moves.
We build on your accounts, hand over the code and the documentation, and put the terms in writing before anything starts. If you want to see how that is set out, read our method or get in touch and ask us the parting question directly. It is a fair one and we would rather you asked it.
Further reading on securing the accounts you will now own: the ACSC has practical, plain guidance for small business.