Skip to content

Vendor lock-in in 2026
A golden padlock or a bunch of keys

Broadcom's VMware business grew 29% year on year while most large enterprises say they are cutting back on VMware. SAP is moving the line from licences to data, and open source can change its licence overnight. A column on the cost of staying with a vendor and the terms of leaving its platform.

On 2 September Broadcom reported that its infrastructure software segment - VMware, for the most part - brought in 8.75 billion dollars in the quarter, up from 6.79 billion a year earlier. That is 29% growth. In February CloudBolt published a survey in which 86% of large North American companies said they were actively reducing their VMware footprint. Roughly 4% had walked away completely.

The two numbers don’t contradict each other, and together they describe vendor lock-in in 2026 better than any definition. Announcing an exit costs nothing; for as long as the migration lasts, the licence still has to be renewed.

I am not writing from a neutral position. SNOK partners with SAP, UiPath, SUSE, Lenovo, Microsoft and Google Cloud, so every day we hold both the padlock and the keys: we implement platforms that bind customers for years, and we help customers loosen those bonds. So I won’t point you in any direction. I will defend one claim: a dependency chosen deliberately and priced before the decision is an architectural decision, while an accidental one reveals itself at renewal.

Cover image generated by AI from a photograph of the author.

VMware under Broadcom: customers announce their exit, revenue keeps climbing

After closing the VMware deal in late 2023, Broadcom stopped selling perpetual licences and moved to per-core subscriptions. In March 2025 a distributor told partners that the minimum order would rise to 72 cores and that late renewals would carry a 20% surcharge. After the backlash, heise reported, the core minimum was dropped and licences can still be bought from 16 cores - but the signal of how fast the terms can shift has stayed with customers. In January 2026 Broadcom closed its cloud service provider programme to most partners.

The pushback has moved to the courts. Rijkswaterstaat, the Dutch agency that runs tunnels, locks and bridges on VMware, won two years of support from a court in The Hague in 2025 so it could migrate. Tesco is suing Broadcom, VMware and Computacenter in the UK. The European Commission sent Broadcom a formal request for information in February 2026, and in August the EU General Court refused Broadcom’s bid to suspend it. In late August the VDDK, a library many migration and backup tools rely on, disappeared from public download. Broadcom has not commented, so what we know comes from users and trade press.

In September 2025 Broadcom CEO Hock Tan said more than 90% of the top 10,000 customers had bought VMware Cloud Foundation - and added, in the same breath, that this does not mean they have deployed it. Vendors rarely separate purchase from deployment this clearly themselves.

There have never been more VMware alternatives: Proxmox VE, Nutanix AHV, Red Hat OpenShift Virtualization, Microsoft Hyper-V and Azure Local, HPE Morpheus VM Essentials, SUSE KVM. For SAP shops the list gets short quickly. SAP HANA in production is supported on VMware vSphere, SUSE KVM and Nutanix AHV, and not on OpenShift Virtualization. Gartner expects about a third of today’s VMware workloads to run elsewhere by 2028, warns that a full migration takes three years or more, and cautions that anyone switching purely to save money may be disappointed.

I don’t know who funds that gap more - those who stay, or those who haven’t managed to leave yet. I do know that a gradual reduction means two platforms, two teams and two contracts for several years. If that is the path we choose, I’d rather price it now than at the next renewal. First, though, it is worth settling honestly whether we were dependent on VMware, or on the fact that for years nobody had to change anything.

SAP: the line moves from licences to data

The timeline is well known. SAP ECC mainstream maintenance ends in 2027 and extended maintenance runs to 2030 at extra cost. The 2033 date that circulates as an “ECC extension” applies only to customers who move to SAP ERP, private edition - in practice RISE with SAP - before the end of 2030. On premise, the wall is still 2030.

In July 2023 Christian Klein said SAP’s new innovations would not be available to on-premise ERP customers or to those hosting on hyperscalers. In May 2026 SAP partly reversed course: most SAP Joule assistants and agents will reach ECC and S/4HANA on premise, but only for customers who have committed the majority of their landscape to migration. AI on premise has become a term of the migration contract.

The bigger shift concerns data. SAP Note 3255746 has long restricted the use of the ODP-RFC interface for pulling SAP data into third-party tools. In 2026 the restriction stopped being words in a note: according to Qlik, Matillion and Theobald Software, SAP introduced technical enforcement, with a temporary opt-out until the end of 2026. A data warehouse from another vendor is still possible, but the road to it runs through SAP’s own options.

The German user group DSAG asked its members about the new SAP Business Suite vision in its 2026 investment report. For 62% it is a weak basis for investment planning or none at all, and 70% name SAP licensing and contracts as a challenge.

One data model from finance to logistics and a single vendor responsible for security patches and legal localisation such as Poland’s KSeF e-invoicing are real value, and many companies knowingly pay for it with dependence. I’d argue that for many firms, standardising on SAP was one of the cheapest decisions of the past twenty years.

Data ownership is what occupies me most here. If the vendor decides which interface may carry data out of the ERP, part of the decision about your data warehouse or AI platform is made outside the company. 2033 has a price too: postponing costs money, and someone should put a number on it before the deadline starts making the decision for us.

UiPath: open protocols, a closed centre

UiPath is opening its platform to the outside world. Maestro orchestrates agents built with LangChain, Anthropic or Microsoft, the platform speaks MCP and A2A, and in autumn 2025 the company announced partnerships with OpenAI, NVIDIA, Google, Microsoft and Snowflake. At the same time, since May 2025 UiPath agents are billed in Platform Units, and orchestration, queues, credentials, audit logs and the whole operational history of your processes stay in Orchestrator.

An open protocol does not make assets portable. A workflow written in XAML with UiPath activities won’t convert to another platform; it has to be rewritten. The same is true of Power Automate, which ties automation to Entra ID and Dataverse, and of Blue Prism with its own package format.

The “open source” alternative deserves a careful read of the licence too. n8n ships under the Sustainable Use License, which allows use only for internal business purposes and is not an OSI-approved open source licence. Robot Framework, Temporal and LangGraph do carry OSI licences, though LangGraph’s hosted platform is a commercial product.

In automation, the path is chosen in practice at the first deployment. Once rewriting your processes costs more than several years of licences, changing platform stops being a real option, however many protocols it supports. MCP opens up integration, but orchestration and consumption-based licensing stay with the vendor.

I wrote more on where the robot ends and the agent begins in Agent or a repackaged bot.

Open source can close the door too

In 2023 HashiCorp moved Terraform from MPL 2.0 to the Business Source License, and the community answered with the OpenTofu fork. In 2025 HashiCorp became part of IBM in a 6.4-billion-dollar deal. Redis dropped its BSD licence in 2024, which gave rise to Valkey under the Linux Foundation, then returned to open source in 2025 by adding AGPLv3. Elastic made the same round trip. In August 2025 Broadcom moved most Bitnami images to an unmaintained legacy repository and kept the full catalogue in a paid tier. In April 2026 the MinIO repository was archived with a note saying it is no longer maintained.

Open source changes the kind of dependence you carry. You depend less on a licence and more on whether anyone in your organisation can maintain a fork when the company behind the project changes the rules.

So the risk lies less in the licence itself and more in the business model of the single company behind a project, and in whether anyone on your team could maintain the code without it. Redis and Elastic returning to OSI licences mostly shows that the rules can change in both directions.

Cloud: an exit without fees is not an exit without cost

On paper, leaving a cloud has never been cheaper. From 12 January 2027 the EU Data Act bans switching charges for data processing services. AWS, Google Cloud and Microsoft Azure have waived egress fees for customers moving out since 2024, each with its own conditions; since September 2025 AWS gives you 90 days to finish the move.

And yet Gartner expects public cloud spending to grow 21.3% in 2026. 37signals says its cloud exit will save more than 10 million dollars over five years - a company’s own claim, not an audited figure, from a business with an unusually predictable workload. When you leave a cloud, the transfer fee is usually the small part of the bill. Replacing managed services that exist only in one provider’s cloud, reworking the architecture built around them and retraining the team cost more.

The second thread is digital sovereignty. In June 2025 a Microsoft France executive told a French Senate inquiry under oath that he could not guarantee French citizens’ data would never reach US authorities. AWS launched its European Sovereign Cloud in January 2026, starting in Brandenburg. Schleswig-Holstein moved its entire administration’s email to Open-Xchange and Thunderbird in 2025, and the International Criminal Court is moving to openDesk.

My test is whether the environment can be rebuilt outside the cloud from code, or only the data can be recovered. The 37signals calculation applies to predictable workloads, so before talking about repatriation I would check how many of those we actually have. Nor am I convinced that a US provider’s sovereign cloud with a European subsidiary solves the problem raised in the French Senate. It seems to move it one level up the ownership chain.

AI models follow the same pattern. According to Menlo Ventures - an Anthropic investor - only 11% of enterprises switched model provider within a year, even though switching is technically simple. MCP moved to a Linux Foundation-hosted foundation in December 2025, but your prompts, evaluations and data stay where you built them. I described our own experiments with locally run models in Mac Studio versus DGX Spark.

DORA and NIS2: the exit plan becomes an obligation

Since January 2025 DORA has required financial entities to hold a tested exit strategy for ICT services supporting critical or important functions. On 18 November 2025 the European Supervisory Authorities designated 19 critical ICT third-party providers, including AWS, Google Cloud, Microsoft and SAP; substitutability was one of the criteria. So the requirement is a tested exit plan from providers the regulator itself has judged hard to replace.

In Poland, the amended National Cybersecurity System Act - the local implementation of NIS2 - has applied since 3 April 2026, and the deadline for essential and important entities to register passed on 3 October. Supply chain risk management has been a statutory obligation since that day. We covered what that means for SAP systems in NIS2, KSC and SAP.

An exit plan that exists only as a document for the auditor will not survive the first real change of terms. I would also add one line that many supplier risk registers lack: the vendor changes its licensing model mid-contract.

Which path we choose

I don’t think vendor lock-in is bad by nature. Every architectural decision is a dependency of some kind - on a vendor, a community, your own team, or the one engineer who understands the configuration. Trouble starts when the dependency is accidental and you only learn its price at renewal.

Before we decide on the next platform, I want to know five things. What leaving costs, calculated today rather than on the day we need it. Who can extract the data, and in what format, without the vendor’s consent. What would have to be rewritten and what would move as it is. What happens if the vendor changes the licence halfway through the contract, and whether the contract says anything about it. And whether we have people who can run the alternative if we choose it.

Which dependency in your architecture did you choose deliberately, and which one did you only discover on the invoice?

If a decision like this is coming up for you in the next few months, I’m happy to work through it with you. At SNOK we do this as part of our IT advisory and integration work.

Sources

Topics:Othervendor lock-inVMwareBroadcomSAPUiPathopen sourcedigital sovereigntyDORAcloud
Found this useful? Please pass it on:

Get in touch