Ethical Tech
AI Vendor Lock-in: The Ethics of Depending on AI, and How to Depend on It Less
A fintech lost its AI access overnight. Uber burned a year's coding budget in four months. Builder.ai died and took its customers' source code with it. What I own, what I rent, and what I am doing about it.
12 Jul 2026 · 10 min read · By Sophie Kazandjian
In April, every employee at an Argentine fintech called Belo opened their laptop and found their Claude account suspended. All sixty of them, at once. The email cited a breach of the usage policy without naming the policy, the conversation or the user, and the only way to appeal was a Google Form. Integrations and chat histories went with the access. It came back fifteen hours later, once the story had spread far enough to embarrass someone, and the explanation was that an automated system had produced a false positive. Underneath the founder's post, other customers said they had been waiting on the same form for months. His own conclusion was that you should never put your eggs in one basket.
Sixty people is not small by the standards of most of my clients. If a company that size can lose its working tools before lunch, so can a coach with a laptop.
Why I left Meta, and the five conditions I set
I left Instagram, Facebook and LinkedIn, and I wrote down why. Meta stripped out its fact-checkers days before the inauguration, and Amnesty warned that the change put vulnerable communities at greater risk of violence. Researchers caught Meta's Android apps covertly tracking users' browsing, in incognito, through a local network loophole that Google said blatantly violated its own principles. The European Commission fined the company two hundred million euros for a consent model that turned privacy into a paid privilege.
I also set five conditions for any platform I would be willing to build a business on. No ads, no tracking, no data selling. Open source and transparent. Community-owned or nonprofit. Decentralised, so that no single billionaire can change the rules overnight. No manipulative algorithms.
Then I moved to Mastodon, which has 1.8 million monthly users, from Instagram, which has billions. I gave up reach on purpose, and I said at the time that carrying on had started to feel like quietly going along with it.
That was distribution. This is production, where the work happens, and where I have never applied the same test to myself.
The four ways an AI vendor can hurt you
They suspend you
Belo, above. An automated system, a vague email, a Google Form.
They withdraw the model for reasons that have nothing to do with you
Anthropic cut the coding startup Windsurf off from its models with under five days' notice, because a rival was buying the company. Windsurf had offered to pay for the capacity. Last month the US government ordered Anthropic's newest models switched off worldwide for most of a month. Nothing I had built broke, because none of it calls a model to run. A client mid-migration who needed that model for three weeks would have found out what the dependency costs.
They put the price up
Uber's engineers, encouraged by an internal leaderboard ranking teams by AI usage, burned the company's entire 2026 coding budget in four months, with individual engineers running up between five hundred and two thousand dollars a month. Uber capped them at fifteen hundred. Its chief operating officer then admitted publicly that he could not draw a line between the token spend and anything a passenger would notice. Microsoft has been cancelling its direct Claude Code licences. Anthropic has added a credit meter for agent tools, billed at full API rates. OpenAI has taken model choice away from its cheaper tiers.
They die
Builder.ai raised more than $450 million, was backed by Microsoft and the Qatar Investment Authority, and reached a valuation of over a billion dollars. In May 2025 a creditor seized $37 million from its accounts and the company went into insolvency within weeks. Its customers lost their applications, their data and their source code, because all of it lived on Builder.ai's servers. The final insult was that Builder.ai was never really AI. The Wall Street Journal had reported in 2019 that human engineers were doing most of the coding. Hundreds of businesses lost their software to a company whose product was largely a story about itself.
Why this keeps happening
Cory Doctorow's sequence goes like this. A platform is good to its users while investors are paying. Then value is clawed back to serve business customers. Then it is clawed back again for shareholders. Nobody leaves, because the cost of leaving grew quietly while everyone was enjoying themselves.
Uber is his cleanest example. For a decade the rides were cheap because investors were funding them, the market learned to depend on them, the competition thinned out, and then the price found its real level. Uber did not turn an annual profit until 2023. The company that taught the world how to train a market on subsidised prices did not see it coming when the same play was pointed the other way.
Generative AI is at the end of stage one. No subscription has ever covered the compute behind it.
The lock-in works differently from Facebook's, which is what makes it hard to argue with. Facebook held people through their friends. What holds you to a model is habituation, the workflows you tuned, the instructions you wrote, and a capability gap that is real. The best model is better. So the line I usually reach for, that the European alternative is nearly as good, is not one I can use here without checking first.
Build-time or run-time: the question to ask about anything you own
Two kinds of dependency get muddled, and they behave completely differently.
Build-time dependency means the model was there while the thing was made and is gone while it runs. This website was rebuilt in two days and is now static files on Cloudflare, which is the difference between owning a website and renting one. The Workers run. The client systems run. If every model I use went dark tomorrow, none of them would notice. What I bought was speed.
Run-time dependency means the system calls a model every day, to classify or route or summarise or draft. It inherits every price rise and every outage its vendor has, and if I built it for you, you inherit them from me.
If someone built you a tool in the last two years, ask them which kind it is. If they cannot tell you, that is your answer.
The environmental cost of AI data centres
In May, Anthropic took over all the computing capacity at Colossus 1, a data centre in South Memphis owned by Elon Musk's xAI. Colossus is the site that ran up to thirty-five gas turbines without permits for the best part of a year, in a majority-Black neighbourhood already carrying decades of industrial pollution. Lawyers acting for the NAACP put the unpermitted capacity at around 421 megawatts, comparable to a whole power plant, and said the emissions likely made xAI the largest industrial source of smog-forming pollution in the city. Boxtown, next door, has a cancer risk four times the national average. Researchers at the University of Tennessee, analysing satellite data for TIME, found peak nitrogen dioxide concentrations near the site had risen by seventy-nine per cent. The promised water recycling plant was delayed, so the machines are still cooled with Memphis drinking water.
Anthropic did not build that. Anthropic moved into it, with all of it already public. When I ask Claude to debug a component, some of that work may be running on those racks.
The company is also building its own sites, fifty billion dollars' worth, in Texas, New York and Louisiana, and it has promised that the ones it builds will not push up local electricity bills. The promise does not cover the capacity it rents, and it rents a great deal.
Mistral's first cluster sits at Bruyeres-le-Chatel in the Essonne, on a nuclear grid, with closed-loop cooling and a site water figure close to zero. Training Mistral Large 2 still produced around 20,400 tonnes of CO2 equivalent and consumed 281,000 cubic metres of water. We know because Mistral published a peer-reviewed lifecycle study with ADEME and Carbone 4, which no American lab has done. The nuclear plants supplying that grid consume water at their own cooling towers, so the footprint moves rather than disappearing.
Be careful with the league tables that follow from this. Mistral often appears at the dirty end of them, because its number is the only one published. Everyone else withheld theirs, and the ranking rewards them for it.
Is it ethical to use AI at all?
My usage is a rounding error. Nobody in Boxtown breathes differently because a consultant in the Gard cancels a subscription. If causing the harm were the whole test I would be acquitted, and so would everybody, which is why it is not the whole test.
The real objection is consent. Boxtown did not agree to host the turbines. The writers whose work trained the model were not asked. Buying the output of an arrangement like that makes you part of it, whatever your own contribution measures. If you think that settles the matter, the answer is refusal, and refusal costs speed and quality rather than anything deserving the word suffering. Some people have made that choice and they are not wrong.
I have not made it. So the only defence left is that staying produces something leaving wouldn't, and that is the most abused sentence in professional ethics. Everyone who has ever been compromised has claimed they were changing it from the inside. It counts only if the influence is exercised and the exercise costs something.
How to reduce your dependency on an AI vendor
Five things, and you can start any of them this week. None of them is new to this journal. I have made the same argument about automation, about databases and about hosting. This is the version that applies to the model itself.
Audit what you have
Go through every tool and system in the business and mark each one build-time or run-time. The run-time ones are your exposure. Most people find fewer than they feared and are surprised by one.
Get the contract clauses
If a supplier builds you something that calls a model, the agreement should carry a rate cap, a notice period before any pricing change, and an explicit right to export your data, your configuration and your prompts in a usable format. If they will not write that down, you have learned something. Builder.ai's customers had none of it, which is why they lost their source code along with the company.
Own the repository

Whatever gets built for you belongs in a repository you control, with the documentation inside it. Architecture, conventions, deploy process, and the reasoning behind the decisions that look arbitrary six months later. This is the next thing I am building across every project I hold. It means any other developer can pick up the work, and so can any other model. It also means a client can take the repository elsewhere without me. Most studios do not document properly, and the reason is not laziness. The undocumented build is the retainer. I cannot tell people to keep their exits cheap while quietly holding mine shut.
Route the work
Nothing says you must send every task to the same model. The routine end of my work, article pages built from prose I have already approved, data files updated, images converted, redirects written, does not need a frontier model. The hard fifth might. Splitting those apart shrinks the dependency from everything to something specific.
Set a price ceiling now
Decide the monthly figure at which the practice stops working, while the answer is still theoretical rather than a bill. Uber found its number in April, four months too late.
If you are in the EU or selling into it, the AI Act obligations that land on 2 August give you a reason to write all of this down anyway.
None of this makes you independent. It makes leaving possible, which is a different and more achievable thing.
Is Mistral good enough to replace Claude?
Mistral's flagship models ship under Apache 2.0. The weights are published, which means anyone can serve them: Mistral itself, a European host like Scaleway or OVH, or your own hardware if the model is small enough. If Mistral triples its prices or suspends my account on a Friday afternoon, the model does not leave with them. Belo had no such option. Publishing the weights answers my fourth condition completely.
That is not the same as running it at home. The flagship has 675 billion parameters and needs a data centre. The small models run on a workstation, and those are the ones that would take the routine end of the work, with no vendor in the loop at all.
The hard fifth is different. Multi-file, stateful, unforgiving of a single misplaced quote, and I do not write code, so when a model gets something subtly wrong I cannot see it. That is where the dependency actually lives.
How much worse the European models would be at that, I do not know, because in a year I have never sat down and found out. I chose the better tool, told myself the gap was too wide to give up, and never measured the gap. Arthur Mensch says plainly that his company does not yet have the best models, and a new open-weight family entered early access this month, so any number I quoted today would be stale by autumn.
My five conditions still stand. The tool I pay for every month meets two of them. The one I have been calling worse meets three and a half, and I have never tested it.
So that is the next project, and I am writing it down here so that I have to do it. Every system I hold gets its documentation set, written into the client's own repository. Then I run the same builds through a European open-weight model and publish what breaks.
What I cannot tell you is what I will do if the test goes against me. If the open-weight models cannot handle the difficult fifth of the work, the choice stops being theoretical. I can keep paying a company whose compute runs through a Memphis neighbourhood that never agreed to host it. Or I can hand my clients slower and more expensive work in the name of a principle they never asked me to hold on their behalf. Neither of those is a position I would enjoy defending, and one of them is going to be mine.
FAQs
- What is AI vendor lock-in?
It is the point at which leaving your AI supplier costs more than staying, even when the terms get worse. With social platforms the lock came from your audience being there. With AI models it comes from habituation, the workflows and instructions you have tuned, and a real capability gap between the best model and the alternatives.
- What is the difference between build-time and run-time AI dependency?
Build-time means a model helped make the thing, and is absent once it runs. A static website built with AI assistance carries no ongoing exposure. Run-time means the system calls a model every day to classify, route, summarise or draft, so it inherits every price rise and outage its vendor has. If you commissioned a tool and cannot tell which kind it is, ask whoever built it.
- Can an AI company really cut off my access without warning?
Yes. In April 2026 an automated system at Anthropic suspended every account at a sixty-person fintech, with no explanation and a Google Form as the only appeal route. Access returned after fifteen hours. Other customers replying to the story said they had been waiting on the same form for months.
- What contract clauses protect against AI vendor lock-in?
A rate cap, a notice period before any pricing change, and an explicit right to export your data, your configuration and your prompts in a usable format. Ownership of the repository and the documentation should sit with you, not the supplier. Builder.ai's customers had none of this, and lost their source code when the company went into insolvency.
- Is Mistral a serious alternative to Claude or ChatGPT?
For European businesses, it answers the sovereignty question in a way the American labs cannot, because the flagship models are published under Apache 2.0 and can be served by anyone, including you. It trails the frontier models on the hardest reasoning work. Whether that gap matters depends entirely on what you actually do with the tool, which is a question best answered by testing rather than assuming.
- Does using AI make me complicit in the harm from data centres?
Individual usage is a rounding error, so causation is not the test. The stronger objection is consent: the communities hosting these facilities were not asked, and neither were the writers whose work trained the models. Refusal is a legitimate answer and it costs speed and quality. Continuing is also defensible, but only if it comes with rules that occasionally cost you something.