← Research
Research · Essay

What It Would Take to Leave

Exit is the test of dependence, and almost nobody has run it.

Last reviewed: 3 October 2026 · Next review due: 3 October 2027

Organisations assess AI suppliers on capability, price and security. Very few assess them on exit, which is the question that decides how much leverage they will have in two years, and the only one that can be answered today rather than guessed at.

Exit is not a prediction about a vendor's conduct. It is a measurement of your own position. A firm that can describe, in writing, what it would do if its main supplier doubled its prices or changed its terms has a negotiating position. A firm that cannot has a dependency it has not priced.

What the operators have written down#

The vendors document their own handling clearly, and that documentation is where an exit assessment starts. It states capability rather than practice: what the system permits, not what any customer has configured.

OpenAI's enterprise material states that administrators control retention, that deleted conversations are removed from its systems within 30 days unless legally required otherwise, and that workspace administrators can reach an audit log of conversations through a compliance API. Its managed-account documentation states that administrators may access submitted content, conversation history, usage metadata and security settings, and can export, audit, retain and delete.

Microsoft's Purview documentation locates Copilot prompts and responses in a hidden folder in the mailbox of the user who ran the tool, not designed for that user to reach, searchable by a compliance administrator with eDiscovery tools, and searchable until permanently deleted.

Read as an exit question rather than a privacy question, those pages say something useful. The interaction record is exportable. Whether it is portable, meaning usable somewhere else, is a different matter and neither vendor claims it.

Three things that do not travel#

The practice. The instructions, context files and saved methods that make a tool work for a particular team are written against one product's behaviour. They are the asset, they took months to accumulate, and they are the least portable thing in the stack. Where they live at all is usually one person's account.

The evaluation. A firm that has learned where a model is reliable for its own work holds something no benchmark provides. Most of that knowledge is uncodified, and the part that is codified is written in terms of one model's failure modes.

The record of judgement. Every brief, correction and rejected draft describes how the organisation's best people think. It is exportable as text. Reconstructing it as working practice inside another product is a project nobody has budgeted for, and the ownership question underneath it is unsettled.

None of that argues against depending on a supplier. It argues for knowing the size of the dependency while the decision is still reversible.

Two regulatory positions that bear on it#

Firms in regulated sectors sometimes assume an existing framework covers this. Two instruments say otherwise in opposite directions.

The United States banking agencies replaced their model risk framework with SR 26-2 in April 2026, narrowing the definition of a model to a complex quantitative method applying statistical, economic or financial theories to produce quantitative estimates, and expressly placing generative AI outside scope. The same footnote directs firms to their own risk management and governance for tools outside it. The most mature regime any sector has for machine-produced numbers has declined to carry this, which leaves the question with the firm.

The Financial Reporting Council took the other route. Its 2025 guidance on AI in audit covers traditional machine learning and deep learning models including generative AI, and brings them inside existing evidence and documentation standards without writing new rules. On explainability it declines to set a threshold, saying what counts as appropriate will vary widely by context. The FRC is explicit that it creates no new requirements and describes guidance rather than practice.

Between them they describe the position most organisations are in. The obligation to be able to account for the work does not move to the supplier, whatever the contract says about the tool.

The assessment, which takes a day#

What would settle it#

Measured switching costs: firms that have actually moved a working AI practice between suppliers, with the time and cost recorded. Nothing in this base measures it, and the organisations with the experience have no reason to publish it. The position on this page is an argument from vendor documentation and regulatory scope rather than a finding about what switching costs.

Where this sits in my own argument#

Every other page here concerns capability a firm builds in its people. This one concerns capability it rents, and the discipline is the same: a dependency somebody decided on is a strategy, and a dependency nobody decided on is drift. Asking the exit question early is cheap. Asking it after the terms change is a negotiation conducted from the weaker side.

On the practice that would have to be rebuilt, where your AI practice lives. On what delegation actually costs, the cost of delegation. On deployment decisions that are harder to reverse than they look, deployment is not a ratchet. On the configuration decision, rules before tools.

Key sources

About this research#

Written by Rahim Hirji, author of SuperSkills (Kogan Page, 2026), keynote speaker on AI and human capability, and founder of The SuperSkills Intelligence Company.

How this research works · Reviewed quarterly · Found an error? Tell me and it is corrected on the page.

Evidence review · SS-2026-393 · Graded against the published rubric · 3 operator accounts and 2 modelling studies

Cite this page

Hirji, R. (2026). What It Would Take to Leave. The SuperSkills evidence base, SS-2026-393. https://thesuperskills.com/research/what-it-would-take-to-leave. Last reviewed 3 October 2026.

An evidence review by Rahim Hirji, not peer-reviewed research. For a material claim, cite the underlying study as well; every study here carries its own permanent link.

How citations and IDs work

In this hub

Organisations and leadership

What a leadership team actually has to decide, and what to measure.

Ask the evidence
What does the evidence actually show?What should our board be asking about this?Where does Rahim disagree with the consensus?
Bring this into your organisation

If this describes something happening in your teams, say so.

Keynotes, board sessions and advisory work, drawing on research across more than 200 organisations in 30 countries. Tell me the room, the date and the shift you need. A reply within 24 hours.

Start a conversation

Topics and audiences  ·  All research

Box of Amazing

Rahim’s free weekly letter on AI and human capability

If this was useful, the weekly letter is where the thinking happens first. Most of what ends up on this site starts there. Weekly essays on AI, capability and the future of work. Read by 25,000 people, every week since 2017. Free, and one click to stop.

Opens Substack to confirm. No pitch in it, unsubscribe in one click, and nobody follows up because you read something.

Running an event, or responsible for how AI arrives in your organisation? Keynotes  ·  Advisory  ·  Boards  ·  Enquire