Owning Your AI Starts With Being Able to Leave Your Vendor
AI-generated illustration

Owning Your AI Starts With Being Able to Leave Your Vendor

Zeta42 · 26 September 2026

80% of surveyed UAE executives say moving core AI systems to another vendor would take at least six months. Owning your AI starts with deciding what you must control.

The lock-in is already here

Ask UAE executives how hard it would be to change AI supplier and the answer is now on record. In a July 2026 IBM study cited by Fast Company Middle East, 80 per cent of surveyed UAE executives said moving their core AI systems to another vendor would take at least six months, and 88 per cent said switching their primary AI provider or model would be difficult.

Lock-in is rarely chosen. It builds up as a tool becomes part of how the business runs. The Gulf's debate about sovereign AI is usually framed around nations and data centres, but the same question applies to a single company in Abu Dhabi: which parts of your AI do you need to control, and can you keep working if a supplier changes?

Owning the building is not the same as control

At national level, Gulf governments are building data centres and developing their own models, yet the chips come from foreign suppliers and global cloud companies remain central to their operations. Farid Zahran, Senior Managing Director, AI and Digital Transformation at FTI Consulting, doubts that complete technological independence is realistic. "No country owns the full AI stack," he says. What matters is where sensitive data is stored, which laws govern it, who operates the infrastructure, and who owns the models and applications that process national information.

The article puts the company version in one line: a company in the Gulf can keep its AI data inside national borders and still rely on an external vendor to run the system. Data residency tells you where the data sits. It does not tell you who holds the keys, or how long a move would take.

Agents make leaving harder

An AI system that answers customer questions is fairly simple. An agent that handles invoices, approves requests or works inside a company's own software is a different matter. Rotem Alaluf, Founder and CEO of Wand AI, says organisations must consider who controls an agent's identity, permissions, memory and records of previous actions. Over time, these systems build up knowledge of how the business operates. If that knowledge stays tied to a foreign platform, switching providers could mean losing more than access to a software product.

Businesses, he says, should be able to change providers, inspect an agent's actions and revoke its permissions without rebuilding their operations from the beginning. His resilience test asks whether losing one provider means "friction or paralysis" for the economy. Put the same question to a single company and, on the IBM figures, many would not like the answer.

"Sovereignty does not mean eliminating external dependencies; it means deciding what those dependencies are allowed to stop."

That line, also from Alaluf, is the most useful sentence in the debate.

Run the sensitive work on your own network

Muhammed Khalid, CEO and Founder of Abu Dhabi-based AIREV, puts the data question plainly: "Foreign chips are not the problem. Being forced to send your data to someone else's cloud to process it is." Businesses keep more control, he says, by running AI on their own infrastructure.

Zahran suggests sorting AI work by sensitivity. National security systems, citizen information and critical infrastructure would run on nationally managed infrastructure with encryption keys held domestically, while less sensitive commercial applications could keep using global cloud services hosted in the Gulf. Using multiple vendors, adopting models that organisations can run themselves and negotiating clear exit rights can reduce the risk of depending on a few providers, he says.

A company can make the same split. A rented model drafting marketing copy carries little risk. Contracts, payroll and board papers belong on a model the organisation runs itself, which is practical at office scale. That is what Zeta42's AI infrastructure work is for: desk-side AI computers that hold and run real models on the client's own network, so nothing leaves the building.

Own the parts that could stop you

None of this argues against global models or cloud services. Alaluf says the region can use them while still controlling the systems that turn them into productive capacity. Yasser Shawky, Vice President EMEA South at Informatica, argues for a governance layer above whichever provider is in use, so that a government can swap providers without rebuilding its underlying data architecture.

For a UAE organisation, settle two things before an AI system goes live. Keep each agent's permissions, memory and action records in a form you can export and inspect. Make sure access can be revoked in one step. The agents Zeta42 builds work within limits the client sets, and every action is logged, because that record should belong to the business rather than to whoever hosts the model.

Fast Company Middle East closes on the right test: can a government or business enforce its rules, switch suppliers and keep a critical system running without losing access to its data, models or accumulated knowledge? Make sure the answer is yes before the agents are embedded.

Source: fastcompanyme.com

AI InfrastructureSovereign AIVendor Lock-InOn-Premise AIOpinion

From Zeta42

Related programmes

  • Service

    AI infrastructure

    AI models running on-premise for data residency: desk-side AI computers, a teaching server and storage, installed on your own network.

  • Service

    Government and enterprise

    Executive briefings and department cohorts built around your own tools and files, for government and enterprise teams across the UAE and GCC.

Keep reading

Related articles