Skip to content
← Back to blog
Business · 6 min read

Someone else can switch off the AI your business runs on. It happened twice this year.

AI vendor lock-in stopped being theory in 2026. Two model shutoffs in three months, what actually broke, and the 20 minute check to run on your own stack.

🔌

BlueFort AI

BlueFort AI

Photo: Troy Bridges / Unsplash

Open the tool your team lives in. The CRM, the help desk, the scheduling app, the one with the little sparkle icon that drafts replies for you.

Now ask a question you have probably never asked: whose AI is that, actually?

Most owners assume the answer is “the company I pay every month.” Usually it is not. That sparkle icon is almost always a rented engine from OpenAI, Anthropic, or Google, wired in behind the scenes. The rental has terms. And in 2026, those terms started getting pulled.

AI vendor lock-in used to be a slide in a consulting deck. This year it became two real shutoffs, three months apart, for two completely unrelated reasons. Neither had anything to do with the people using the software.

What actually happened

August 28. OpenAI told Anysphere, the company behind the coding tool Cursor, that it is ending the agreement that supplies OpenAI models to Cursor. Proposed cutoff: November 12, 2026. The trigger was a change of control clause. SpaceX had closed a $60 billion all stock acquisition of Anysphere two weeks earlier, and OpenAI said it could not be confident SpaceX would use the technology inside OpenAI’s terms of service.

Read that again. The product did not break a rule. The product got bought by the wrong buyer, and the engine supplier walked.

June 12. The US Commerce Department issued an emergency directive barring distribution of Anthropic’s two newest models, Fable 5 and Mythos 5, to foreign nationals. The rule reached foreign nationals worldwide, including inside the United States, so partial access controls were not workable. Anthropic pulled the models offline globally.

No acquisition. No contract dispute. No outage. A government letter landed at 5:21 pm Eastern and a frontier model went dark for everyone.

Two different failure modes, one shared feature: the customer was the last to know and had no vote.

AI vendor lock in, in plain English

Normal software risk is something you already understand. Your vendor raises prices, gets acquired, or goes under. You usually get a renewal cycle of warning and a weekend of pain.

AI adds a second floor to that building. Your vendor has a vendor.

In plain English: the AI feature you depend on is a sublease. Your contract is with the tool. The tool’s contract is with the model company. You have no relationship with the model company at all, and no standing whatsoever when that second contract ends. You are two contracts away from the thing doing the actual work, and you can only see one of them.

Why this is worse than a normal vendor problem

Three reasons, and the third is the one that gets people.

The notice period is not yours. OpenAI gave Cursor the maximum notice its contract allowed, roughly eleven weeks. Cursor’s paying customers got that same eleven weeks secondhand, by reading the news. There is no clause anywhere protecting the person at the bottom of the stack.

The reasons sit outside the market. Export controls. Who bought whom. A long running feud between two founders. None of that shows up in a normal vendor evaluation, and none of it correlates with whether the product is any good.

Swaps are quiet, not loud. When a model gets replaced, your software does not throw an error. It keeps working, slightly differently. Prompts tuned for one model behave differently on another. Your intake summaries get vaguer. Your draft replies get a little off tone. Nobody files a ticket for “the AI is worse now,” so it goes uncaught for months. A hard outage you would fix in a day. This you might not notice until a customer does.

Now the honest part

The Cursor story is milder than the headline. Reports put OpenAI models at a small slice of what Cursor users actually choose. Cursor’s own model and Anthropic’s Claude stay available, developers can bring their own API key, and Anthropic publicly offered to raise limits within days. The Anthropic shutoff hit a specific pair of frontier models, not the whole platform.

So this is not a five alarm fire. It is a pattern.

And you will meet the small version of it long before you meet the big one. OpenAI retired the DALL-E GPT inside ChatGPT on August 30, and retired o3 from ChatGPT on August 26. If somebody on your team had a saved workflow pointing at either one, it is simply gone. That is the everyday shape of this problem: not a $60 billion acquisition, just a thing that was there on Friday and is not there on Monday.

We wrote about the bigger version of that when ChatGPT Atlas shut down. Same lesson, smaller stakes.

What this means for you

Twenty minutes. Four questions. Do it this week.

1. List only what you would actually miss. Not every feature with a sparkle icon. The two or three where a shutdown means real work stops: the AI phone answering, the quote drafting, the ticket triage. Most businesses have fewer than three. If you already ran the pay twice audit, you have this list.

2. Ask each vendor whose model is underneath. One email: “Which model provider powers this feature, and what is your plan if that supply ends?” A vendor who cannot answer that in one reply has not thought about it either, which is the actual finding.

3. Ask whether there is a second option. The healthy answer is a vendor that already runs on more than one provider and can switch without you noticing. The answer that should worry you is silence, or a vendor whose whole pitch is being the exclusive front end for one model.

4. Keep your data portable. This is the one that actually saves you. Can you export your prompts, your knowledge base, your chat history, your custom instructions? If yes, the worst case is a bad week. If no, the worst case is starting over, and you will pay whatever they ask to avoid it.

If a workflow matters enough that a supply cut would genuinely hurt, that is also the point where running a model you control starts to make sense. We track what is actually good enough to self host in the open source LLM rankings. For most small businesses that is still overkill. For a few of you it is not.

The verdict

Not a crisis. Worth twenty minutes.

Here is the opinion, separate from the news. The AI industry has started making supply decisions that have nothing to do with product quality: acquisitions, politics, personal history between founders. The ordinary buyer at the end of that chain absorbs every one of them, with no notice and no leverage.

You cannot fix that. You can decline to build your business on a single sparkle icon, and you can favor tools that treat their model supply as swappable plumbing rather than as their whole identity. That question costs nothing to ask before you sign. It costs quite a lot to ask in November.

Reading about AI risk is free. Untangling a workflow after the engine gets pulled is not. If you want someone to map where AI actually sits in your business and what breaks if a supplier walks, that is BlueFort IT’s day job. And before you hand anything important to software you do not control, read the five limits to set first.

#ai-vendor-lock-in#ai-for-small-business#ai-risk#openai#ai-strategy

Want this kind of thinking applied to your business?

BlueFort IT helps you adopt AI safely and put it to work.

Talk to BlueFort IT