Diop Daily #085 — August 2026

The Exit Is Part of the Product

A software company can buy access to a model in minutes. The harder question is whether it can leave.

That question has been treated as a procurement footnote, a legal clause, or an unpleasant scenario to discuss after the pilot. It should be treated as a product requirement. When AI moves from a chat window into repeatable institutional work, the buyer is no longer acquiring only inference. The buyer is entrusting a system with memory, authority, workflow definitions, records, and the interpretation of exceptions. If those things cannot move, the vendor is no longer merely providing a tool. It is becoming the institution's operating environment.

An AI system is not sovereign because it can act alone. It is sovereign when an institution can change its mind without losing itself.

Capability is portable; institutional state is not

Model access is becoming easier to compare. A buyer can test latency, price, context length, tool use, and benchmark performance. The difficult asset is the state that accumulates around the model: the vocabulary learned from the organization, the routing rules that decide which agent receives a task, the approval thresholds, the evidence attached to decisions, the unresolved questions, and the record of what was corrected.

This is why the language of vendor switching understates the problem. Switching a model is not the same as moving an institution. A model may be replaceable while the surrounding interpretation is quietly trapped in proprietary prompts, hidden ranking systems, undocumented tool schemas, or dashboards that cannot export the reasons behind a decision.

OpenAI's August 6 Signals item, “From asking to doing: How the world is putting ChatGPT to work,” describes a market moving toward repeated workplace use rather than isolated questions. Its same-week role signal about HSP GRUPPE places ChatGPT Enterprise inside tax advisory and client service. The more work becomes repeatable, the more expensive it becomes to discover that the operating state was never designed to travel.

Interoperability is the beginning, not the exit

Google's A2A work gives the market an important technical direction: agents need a common way to discover one another, hand off work, and participate in workflows that are larger than any single model. That is necessary. It is not sufficient.

A handoff protocol answers how one agent communicates with another. An exit protocol must answer what the institution owns when the agent changes. It must preserve the meaning of the handoff, the authority that permitted it, the evidence that supported it, and the obligations that remain after the original runtime has disappeared.

The distinction is the difference between moving messages and moving responsibility. A portable system cannot export only JSON while leaving the semantics of approval, expiration, local terminology, and contested decisions behind. Interoperability becomes institutional portability only when the receiving system can reconstruct not just the data, but the reasons and boundaries that made the data actionable.

What must survive the move?

An institution should be able to demand a migration manifest before it signs a serious AI contract. At minimum, the manifest should identify:

  • Identity: which models, tools, agents, and human authorities participated in each consequential action.
  • Memory: which facts, decisions, procedures, and exceptions were carried forward, with version history and expiration.
  • Authority: which permission, role, threshold, or second key allowed an action to proceed.
  • Evidence: which records, sources, and evaluations supported the output, including uncertainty and disagreement.
  • Artifacts: which prompts, schemas, policies, outputs, and receipts are required to reproduce or contest the work.

This list is not a demand for infinite archival storage. It is a demand for a clear boundary between what the institution owns and what the vendor merely renders. Without that boundary, a buyer may possess its files while renting the grammar that gives those files meaning.

Portable credentials turn claims into objects

The current standards work is useful because it moves portability away from a slogan. W3C's August 6 announcement on DID Resolution describes a process for obtaining a DID document and accompanying metadata for a specific identifier. W3C's July 30 Group Note Draft on Verifiable Credentials describes credentials that can be cryptographically secure, privacy respecting, and machine-verifiable. These are not complete answers to institutional exit, but they provide the grammar for making identity and claims inspectable across systems.

The practical implication is simple: a migration should not require the receiving vendor to trust a screenshot of the old system. It should be able to verify the identity of an artifact, the issuer of a claim, the scope of an evaluation, and the status of a permission. A portable credential is valuable precisely because it can be checked outside the environment that produced it.

But credentials must remain modest. A signed claim is not a guarantee of truth, and portability is not proof of fitness. The receiving institution still needs local tests, local language coverage, local legal interpretation, and a way to revoke a claim when conditions change. Exit infrastructure should make disagreement easier to carry, not hide it behind a clean export.

Regulation will make exit an operating question

The European Commission describes the AI Act as a legal framework addressing the risks of AI and establishing obligations around the systems placed on the market. Whatever one's view of the policy's details, the direction is significant: AI governance is moving from voluntary assurances toward documented responsibilities, technical evidence, and accountability attached to actual use.

That direction increases the value of portability. If an institution changes a model provider, it cannot afford to lose the evidence that explains how a system was evaluated, what human oversight existed, which data boundaries applied, and which incidents or corrections changed the risk posture. Compliance that lives only in a vendor dashboard is not durable compliance. It is dependency wearing a regulatory costume.

The serious buyer will therefore ask a question that sounds operational but is constitutional: can we preserve our obligations if the runtime changes? A vendor that makes exit impossible is not merely creating switching costs. It is concentrating institutional authority in a place the buyer may not control.

African sovereignty requires the right to leave

For African institutions, this is not an abstract concern about procurement efficiency. A ministry, bank, hospital, university, or media organization may operate across languages, borders, legal systems, and unreliable connectivity. Its AI layer must be able to survive vendor price changes, foreign policy changes, regional requirements, and the simple fact that a local institution may eventually need to build a better system for itself.

Scientific sovereignty is often described as the ability to build. It is also the ability to refuse permanent dependence. A federation of African institutions should be able to share standards for identity, evidence, policy, and handoff without being forced into one vendor's private ontology. Local systems can then differ in language, authority, and social purpose while remaining capable of exchanging commitments.

That is the constructive meaning of interoperability. It is not the flattening of difference into a universal interface. It is the ability to coordinate without surrendering the right to interpret, amend, or leave.

Where the investable surface is widening

If the exit thesis is correct, capital should look beyond model wrappers toward the infrastructure that makes institutional reversibility measurable:

  • Migration compilers: systems that translate prompts, tool schemas, memory records, and policy logic between runtimes while exposing what cannot be translated safely.
  • Portable memory and policy stores: vendor-neutral layers that preserve versioned context, authority, expiration, and disagreement rather than exporting only documents.
  • Conformance and exit tests: independent test suites that measure whether an institution can reproduce, audit, revoke, and contest work after a provider change.
  • Credential and receipt bridges: services that let identity, evaluation, approval, and provenance claims remain verifiable across organizations and jurisdictions.
  • Regional sovereign infrastructure: hosting, language, and connectivity layers that give African institutions a credible alternative when foreign systems become too costly, opaque, or politically misaligned.

The valuable company in this category will not promise that every system is interchangeable. That promise would be false. It will show exactly what can move, what must be revalidated, what loses meaning, and what evidence proves the difference. The product is the controlled transition.

The institution should own the future tense

Every AI contract contains an implied future: the vendor will remain available, affordable, compatible, lawful, and aligned with the institution's purposes. Mature infrastructure makes that future conditional rather than assumed. It lets the buyer say: if the conditions change, our work, obligations, and memory can continue elsewhere.

That is why the exit is part of the product. Not because departure is always desirable, but because the right to depart disciplines the relationship while it is still intact. A system that can be left must earn continued trust. A system that cannot be left can quietly convert convenience into authority.

Sources