23.09.2026
7 min read

Switching programmes in cloud, ERP and AI fail on data, integrations and operations. Chapter VI of the EU Data Act has applied since 12 September 2025; switching fees are capped at direct switching costs until 12 January 2027. Without an exit path, the contract term buys speed and cedes pricing power for the next term of office.

Key takeaways

  • Lock-in is an operational risk. The costly tie sits in data flows, process logic and operations teams, and stays invisible while the service runs.
  • Exit costs belong before the purchase. Anyone who does not price the switch, parallel running and the rebuild underestimates the platform’s economic horizon.
  • The Data Act caps fees. It replaces neither architecture nor tested portability.
  • Speed may buy lock-in. Lock-in is acceptable if the lead stays measurable and a funded exit path is kept.

RelatedEU Data Act: Switching obligations for cloud portfolios  /  Managed services: The bill nobody opens

What is an exit path? The contractually and technically prepared switch of a platform: data portability, parallel running, funded rebuild costs, and an architecture that keeps the same switch testable on a second provider before the purchase seals the lock-in.

Inventory comes before termination

IT and business leads often treat vendor lock-in as a clause topic for legal. In daily work it is the operating model. Data paths, permissions, monitoring and the way business units close processes settle around the platform. While availability holds and the price stays within budget, there is no reason to review the arrangement. The reason comes when terms rise, when oversight demands another route, or when the product roadmap no longer carries your strategy.

The costly phase rarely starts with formal notice. It starts with the inventory. You have to establish which data sets can be extracted in full and reused, which interfaces exist only in the provider’s control plane, and which automations, roles and AI artefacts nobody has documented outside the product. The longer operations rest on managed specialist services, the more a switch resembles a rebuild, including dual running and stability risk.

Exit costs show up as overlapping terms, deferred projects, training, integrations that must be rebuilt, and uncertainty in reporting. Anyone who prices them only in an escalation negotiates with no alternative. The provider then knows the cost of standstill better than your own controlling function.

Lock-in is therefore the result of decisions that ranked speed, feature density and operational calm above the ability to leave. That trade-off can be right. It has to stay deliberate and, before the next term, sit in euros, in the schedule and in the risk report.

Cloud, ERP and AI lock in at three different points

In the cloud, lock-in gets expensive through the control plane. Identities, networks, key management, logs and managed specialised services form a mesh. Compute can be replaced relatively fast. The path on which applications authenticate, store data, distribute events and watch operations often sticks to the ecosystem. Exporting objects changes little if the application depends on the quirks of those services. Network and transfer costs can dull the economic case for a partial switch, and no generally valid euro figure exists for that.

In ERP, lock-in sits in the operational truth of the firm. Master data, document flows, permissions and custom code built up over years make the system the authoritative order of business processes. A switch means restating that order and keeping the old one readable in parallel. The licence is usually the smaller item. The larger one is the span in which parallel worlds must assert the same economic reality, including alignment with audit, control and operations teams.

AI platforms shift the tie into model access, embeddings, tool chains, evaluation data and operating knowledge of prompts, filters and quality limits. Anyone who keeps production and test data only in a provider’s closed stack buys fast analysis and gives up portability. The follow-on cost is rebuilding quality assurance, access control, business integration and traceability. That holds whatever the provider, because the artefacts stick to the operating path.

These costs arise as parallel running, export, rebuild and delayed projects. Independent benchmark figures for a single case do not exist without your own inventory. Anyone who compares only list prices for the replacement leaves out the costlier part: people, dual running and the time in which management looks at parallel truths.

The Data Act cuts fees and leaves the rebuild

Contracts describe scope, term and liability. They rarely describe an orderly exit in a form you can rely on. A notice period without a fixed data format, a test environment and help with extraction remains a mere deadline.

Data portability needs formats, completeness, repeatability and export help concrete enough that an independent team can test the claim. Parallel running needs rights, prices and capacity already written into the term. Indexation, minimum commitments and the loss of discounts on a partial exit can make a switch economically impossible, even when it is technically sketched.

The EU Data Act obliges providers of data processing services to enable a switch to another service or to the customer’s own infrastructure. Chapter VI has applied since 12 September 2025 to existing and new contracts. The notice period for a switch may be at most two months. The transition should then, as a rule, take 30 calendar days. Until 12 January 2027, switching fees may cover only the direct costs of the switch. From that date they are abolished. The GDPR (General Data Protection Regulation) also grants a right to portability of personal data.

This framework does not replace architecture. Negotiation over operating support, interfaces, test windows and the end of special terms stays a matter for the contract. Relying solely on statutory rights underestimates the gap between a legal position and a production-ready replacement. That gap shapes daily work.

Contractual strength shows in what you can prove. Anyone who may not periodically receive a full export, test it and run it against their own environment holds a right that exists only on paper. The same goes for configuration documentation, key handover and the provider’s help when historical data must be read in several passes. These duties cost concessions in negotiation. Those concessions are what count later.

When lock-in works as a loan

Lock-in to a platform can be the right call. Some dependency is the price of a market window that must not close, or of a business unit that delivers in months while a decoupled build would take years. Leadership needs a measure for that. Gut feel is not enough, because the benefit shows at once and the lock-in later.

Lock-in is acceptable when the commercial lead becomes measurable on a clear horizon, when the exit remains a funded scenario, and when the dependency sits in an area the organisation can later rebuild without losing the core of value creation. Replaceable functions may sit closer to the provider than the system that carries prices, inventory, risk or customer rights. The split must be written into the decision paper. Otherwise the next feature promise quietly erases the line.

Lock-in turns dangerous where the core system exists only in one provider’s idiom and every further custom change widens the gap to a portable state. Then speed funds the next inability to act. That weighs hardest with AI functions that sink into ERP, the customer platform or the operating path while evaluation data and business rules do not sit outside the tool chain. The exit then hits decision quality across the whole firm.

The question for the committee is the price of dependency in euros and in options forgone. If that price stands against a demonstrable lead and the exit path stays budgeted, lock-in may be chosen deliberately. If both are missing, the cheap entry is an expensive loan.

What belongs in the same paper before you sign

Before a committee signs off term, discount and go-live, the exit belongs in the same paper. State what would still run the day after notice. Name the data objects, identities and model artefacts that exist only at the provider. Record a euro order of magnitude for parallel running, export, rebuild and risk, as a range, and with the limit that it is not reliable without an inventory of your own estate. Make clear who owns the exit as a task, including a budget and a date on which portability is rehearsed.

In the first 90 days after the decision, a repeatable export belongs on the calendar, plus rebuilding the integration paths against another consumer and a drill on separating identity and keys. That work spends operations capacity. It stays smaller than an escalation in which availability, compliance and negotiation come under pressure at once.

In management control, lock-in should be run like a concentration risk: in the risk report, against thresholds and with a named owner. The guiding question is whether the firm can still price its own next years. Anyone who leaves that question to technology alone has delegated it to the provider.

Anyone who buys in the European legal space operates under a regime meant to ease switching that still does not make a switch ready to run. Global platform logic, group rules and local supervision pull on the same estate. The leadership task is to keep that tension visible in the contract, the architecture and the budget before discount and delivery date close the decision.

Frequently asked questions

When is lock-in an acceptable price for speed?

Lock-in is acceptable when the commercial lead becomes measurable on a clear horizon, the exit remains a funded scenario, and the dependency can later be rebuilt without losing the core of value creation. Replaceable functions may sit closer to the provider than systems for prices, inventory, risk or customer rights. The line belongs in the decision paper.

What must the contract include so an exit stays affordable?

Portability needs formats, completeness, repeatability and export support concrete enough for an independent team to test them. Parallel running, prices during the transition, and the logic of indexation, minimum commitment and lost discounts on a partial exit belong in the term. The EU Data Act and the GDPR set a frame and replace neither architecture nor operating support.

What do exit costs consist of?

The costs arise mainly as parallel running, export, the rebuild of integrations and quality assurance, and as delayed projects. Reliable figures for a single case do not exist without an inventory of your own data, interfaces and AI artefacts.

Header image source: AI-generated (September 2026)

Share this article:

Also available in

More Articles

25.09.2026

Artificial Intelligence Revenues Would Need to Grow by 80 Percent Annually

Benedikt Langer

4 min. reading time Stijn Van Nieuwerburgh of Columbia Business School calculates that AI investment ...

Read Article
24.09.2026

Accessibility Belongs in IT Leadership’s Architecture

Eva Mickler

7 min read Since late June 2025, the Accessibility Strengthening Act (BFSG) has applied to many digital ...

Read Article
24.09.2026

CIOs carry three numbers into the next budget

Eva Mickler

5 min read For 2026, the SAP user group DSAG finds that only 38 percent of member companies have a rising ...

Read Article
18.09.2026

Deloitte: 14 Percent of Firms Hit Their Savings Target

Tobias Massow

This article is an AI-generated translation of the German original. The German version is authoritative. 4 ...

Read Article
17.09.2026

IONOS funds AI expansion through workforce reduction

Bernhard Liebl

This article is an AI-generated translation of the German original. The German version is authoritative. 4 ...

Read Article
A magazine by Evernine Media GmbH