How to spot vendor lock-in before you sign
Buying sovereign from a global provider relocates the data, not the dependency. What VMware taught us, and three questions to ask before you sign.
The AI Sovereignty Paradox
Are you too building your next decade’s AI infrastructure on yesterday’s "safe bet"? CIOs and buyers are currently making significant AI procurement decisions under intense pressure. The default instinct in these high-stakes moments is to run to the dominant market winners. But as history shows, what feels like operational convenience today often compounds into a massive strategic liability tomorrow.
To understand where the AI stack is heading, we have to look back at an example of 1/the most expensive lessons in enterprise IT history: The Virtualization Trap.
Between 2005 and '20, enterprises globally standardised on VMware virtualization. The rationale seemed solid: their tools were effective, talent was abundant, and there was a general belief that "nobody gets fired for buying VMware".
Then, Broadcom acquired VMware in 2023. Overnight, licensing costs increased 300% to 1000% for many customers. Enterprise CIOs who had gone "all-in" discovered they were trapped because their entire operational stack was hardwired to VMware APIs.
This was another historical pattern: Operational convenience ➔ Market dominance ➔ Pricing power ➔ Trapped IT.
Yet today, we are watching this exact same playbook being unfold in the AI infrastructure stack in front of our eyes. How ?
The Sovereignty Paradox
While organisations are starting the become aware of the importance to reduce their US CLOUD Act (and other) legal exposures and it’s risks on business continuity, on data privacy and business resilience, they are still running to buy "sovereign clouds" and "AI factories" from global tech giants.
But a landmark Stanford HAI report exposes the fundamental Sovereignty Paradox: "While these commercial offerings provide localized data hosting and regulatory compliance, they often merely reconfigure, rather than eliminate, dependencies on foreign providers."
Your liabilities are still not mitigated, your customer’s privacy not rescued, your company’s IP still left in the open to grab… You could ask: Is your entire AI strategy tightly coupled to a single vendor's proprietary chips, closed software, or black-box APIs: congratulations you too have not achieved sovereignty. You have simply purchased a customized, very expensive lock-in. Well, you are not alone, the pitfalls are everywhere.
The Beltug Sovereignty Test: 3 Q to ask
It should not be that difficult: To help buyers avoid "sovereignty washing," Beltug published a crucial digital sovereignty checklist (see comments).
This checklist will help your procurement teams when auditing any cloud or AI supplier:
- The Legal & Jurisdictional Boundary
- Operational Continuity
- Technical Portability
The real question is: Can you explain, control, and defend the entire stack your model runs on?
Time to stop buying sovereignty-washing. Audit your vendors today before the lock-in becomes irreversible.
We don't publish on a schedule. We publish when there's something worth your inbox.
Get the next one.
No weekly filler, no vendor hype. Just the numbers, the shifts, and the evidence, when we have them.