All insights
EN · AI Strategy & Transformation

How to assess AI vendor lock-in before hiring a partner

Evaluate portability, dependencies, rights, economics and exit readiness before hiring an AI services partner—and test transition before a larger commitment.

A modular AI system crosses a portability bridge, carrying data, code, tests, documentation and operations into a new environment.
AI Exit Readiness Proof-8 tests whether transition preserves artifacts, functional equivalence and operating continuity. · Generated with OpenAI

The safest way to reduce AI vendor lock-in is not to ban every proprietary technology. Require an executable exit before contracting: a dependency inventory, clear rights to data and artifacts, usable export formats, documentation, predictable costs and a transition test. A provider may use proprietary services when they create value, but it must show how the buyer retains meaningful choice.

Treat portability as an architecture and operating requirement, not a boilerplate clause at the end of the agreement. The NIST AI RMF calls for policies addressing third-party AI risks and contingency processes for failures in external data or systems. The UK Sourcing Playbook connects supplier exit planning to successor mobilization or insourcing. In AI, the scope includes models, prompts, evaluations, derived data, tools, observability and operating knowledge.

The MAKINAI AI Exit Readiness Proof-8

Score each area from zero to four. Zero is missing; one is a sales promise; two is a described mechanism; three is a reviewable artifact; four is a mechanism tested in your environment. Require at least 24 out of 32, no zero and passage of all five mandatory gates. Lock weights before proposals arrive so an impressive demo cannot obscure structural dependency.

  • Dependency map — models, clouds, vector stores, tools, APIs, identity, licenses and subcontractors.
  • Data portability — inputs, outputs, metadata, embeddings, logs, evaluations, history and retention rules.
  • Application portability — code, prompts, configuration, workflows, schemas, infrastructure as code and tests.
  • Rights and access — ownership, licenses, secrets, repositories, accounts, keys, documentation and admin access.
  • Functional equivalence — outcomes that must survive component replacement even when implementation changes.
  • Exit economics — egress, migration, rebuild, licenses, support, dual running and internal capability.
  • Operating transition — owners, milestones, continuity, incidents, training, retesting and communications.
  • Evidence and updates — rehearsals, versioned inventory, gap report and triggers to refresh the plan.

Five mandatory gates

Reject or clarify any proposal that cannot return essential data and artifacts in a usable form; keeps critical repositories and accounts exclusively under provider control; does not disclose dependencies and subcontractors; leaves exit charges without a verifiable formula and cap; or refuses a transition rehearsal proportionate to risk. A strong average score cannot compensate for these gaps.

Lock-in is not binary. It can be technical, economic, contractual, operational or knowledge-based. A model may be replaceable while prompts, evaluation suites and feedback data remain undocumented. An architecture may be modular while only two provider employees can operate it. Score each dependency separately and identify who accepts the residual risk.

What belongs in the dependency map

Require a register connecting each business function to its supporting component: model, endpoint, retrieval layer, database, tool, queue, policy, library and environment. For each item, record owner, region, version, processed data, permission, SLA, cost, alternative and replacement impact. Update the register whenever the system changes, not only at final handoff.

NIST notes that risk can arise from both a third-party component and how it is used. A substitute therefore does not need identical code; it needs to preserve essential decisions and controls. Define observable outcomes such as minimum quality, latency, unit cost, audit trail, permissions, failure recovery and human intervention.

Exportable data does not equal a portable system

Request real export samples during selection. CSV or JSON may carry records without relationships, context, prompt versions, provenance, policy or human judgments. Require a data dictionary, schema, stable identifiers, timestamps, source and transformation documentation. Verify how personal data, secrets and licensed content will be deleted or retained at exit.

The European Commission explains that the Data Act requires open interfaces and commonly used, machine-readable exports for certain data-processing services. This is a useful reference for global buyers, but it does not replace market-specific legal advice or guarantee full AI-system portability. Buyers still need system-specific artifacts and acceptance criteria.

Compare the total economics of dependency

The lowest initial price can hide the highest switching cost. Model three scenarios: replace one model, replace a central platform and terminate the services partner. Include egress, engineering, revalidation, observability, overlapping licenses, training, downtime and post-exit support. Separate provider-controlled fees from cloud and platform prices.

Request unit rates, volume assumptions and a cap for exit assistance. Document which artifacts are already included in standard delivery fees. The goal is not free migration; it is preventing basic documentation, operational access or the buyer's own data from becoming leverage when the relationship ends.

Run a paid exit rehearsal

Before a large commitment, fund a two-week exercise using a noncritical slice. Export data and configuration, recreate the flow in a buyer-controlled account, replace one component, run the acceptance suite and produce a runbook. The provider records elapsed time, failures, manual steps, costs and outcome differences. Do not request a complete migration as unpaid work.

Use the same exercise for finalists. Score artifact completeness, time to restore the flow, functional equivalence, candor about limitations and internal-team independence. A mature provider does not promise perfect portability; it distinguishes what transfers, what must be rebuilt and which deliberate dependencies create enough value to justify their exit cost.

Make the trade-offs explicit

  • Managed service versus autonomy: lower operating burden now versus deeper dependence on external people and process.
  • Integrated platform versus modular architecture: speed and consistency versus granular replacement.
  • Proprietary versus open model: capability and support versus control and hosting options.
  • Standardization versus differentiation: common formats ease switching; deep customization may create advantage and exit cost.
  • Provider account versus buyer account: faster start versus less control over history, limits, logs and access.

Turn the exit plan into continuous operations

The agreement should name deliverables, formats, update frequency, owners, access windows, deletion steps, assistance, charges and equivalence criteria. Refresh the exit plan when a new model, platform, integration, subcontractor or data category appears. The UK Exit Management Schedule reinforces continuous preparation so service can continue when a contract ends.

To convert these proofs into obligations, review https://makinai.co/insights/en/what-to-include-ai-services-contract-sow. For ongoing operations, see https://makinai.co/insights/en/how-to-choose-managed-ai-services-provider and, for enterprise dependencies, https://makinai.co/insights/en/how-to-choose-ai-integration-partner-enterprise-systems.

When to involve MAKINAI

MAKINAI can help map dependencies, structure the scorecard and run a technical-commercial exit rehearsal before a larger engagement. The objective is not to eliminate every dependency, but to choose deliberately where dependency creates value and preserve real alternatives where it increases risk.

Sources and references

  1. NIST — AI RMF Core · NIST

    Guidance for third-party software, data and AI risk policies and contingency processes.

    2026-08-29
  2. UK Government — The Sourcing Playbook · UK Government

    Recommends planning exit during contracting and connecting supplier exit to successor mobilization or insourcing.

    2026-08-29
  3. European Commission — Data Act explained · European Commission

    Explains switching, open interfaces and common machine-readable exports for data-processing services.

    2026-08-29
  4. European Commission — interoperability study · European Commission

    February 2026 study of open specifications for data and application portability.

    2026-08-29
  5. UK Government — Exit Management Schedule · UK Government

    Updated model responsibilities for service continuity at contract exit.

    2026-08-29
Making connections

Continue exploring

AI Strategy & Transformation

How to define AI provider governance and performance management before hiring

Read insight
AI Strategy & Transformation

How to evaluate an AI consulting ROI business case before hiring

Read insight
AI Strategy & Transformation

Boutique AI firm, global consultancy, or systems integrator: how to choose

Read insight
Related capability

AI strategy & transformation

An AI transformation consultancy should answer four questions before recommending technology: where business value exists, which capabilities and data are required, how risk will be controlled, and who will operate the change. MAKINAI connects those answers in an executable plan with priorities, owners, metrics and scale decisions.

Explore this capability