AI Lock-In
AI Lock-In

Aaron Levie asked 20 enterprise IT leaders across banking, media, finance, and healthcare one question: will you have any vendors in 3-5 years without a good API? The answer was unanimous. No.

The API layer is becoming table stakes. Every model company will have one. Every SaaS vendor will expose one. Competing on the API itself is already over.

So where does lock-in actually come from?

The framing I keep hearing centers on data. Your proprietary data is your moat. Your embeddings are your moat. I think that misses where the gravity sits.

Jaya Gupta argued in early April that the scarce asset in enterprise AI has shifted from intelligence to permission. Not access to a smart model, but the right to let that model act inside real systems: merging code, touching production, opening tickets, triggering workflows across tools.

I run R&D at Typeface, so I'm not a neutral observer here. But this matches what I see in every large deployment conversation. The governance layer on top of the model is always the hard part.

Every enterprise that adopts AI at scale builds approval workflows, compliance rules, escalation chains, and audit trails around the model's actions. Who approves a production deployment triggered by an agent? What happens when an automated action conflicts with a compliance hold?

Those decisions compound into a structured history of who decided what, when, and why. After a year, an enterprise has accumulated thousands of governance decisions shaping how AI operates inside its specific environment.

Now try switching vendors.

You can export your data. You can migrate your embeddings. You cannot export the decision history that taught the system how your organization works. Every approval chain, every exception, every compliance ruling has to be rebuilt from zero. That is the switching cost nobody is talking about.

The historical pattern is clear. Google built the tracking economy, then became the company writing privacy rules for what came after. Microsoft owned the identity layer, then sold the security stack defending that surface. AWS moved computing to the cloud, then built the compliance tooling enterprises needed to operate safely there. The company that sold the capability was always best positioned to sell the governance layer on top.

AI compresses that sequence. The capability and governance layers are arriving simultaneously, from the same companies. And unlike AWS, which did not get smarter the longer you ran workloads on it, AI systems learn your organization's patterns the longer they operate. The context compounds.

The enterprise AI competition comes down to who accumulates the richest governance history, because that history is the one artifact you cannot take with you when you leave.