South African boards are sleepwalking into AI lock-in
Many South African companies are walking blindly into an unhealthy and unsustainable dependence on public large language models without understanding the commercial and governance risks. Financial institutions and other large enterprises are right to be anxious about privacy, but many still underestimate how quickly a public AI service can become a single point of failure.
This is not just another SaaS decision. If you are entirely dependent on a single public LLM provider and have no backup plan, you are running an uncontrolled experiment on your own business.
It begins with cost, which some describe as a “money furnace” – a term the US academic and podcaster Scott Galloway used of xAI .
We currently pay about US$600/month for 30 licences. Looking at the actual usage of our most proficient AI developer and scaling that behaviour across the business, we project the bill could climb towards $10 000/month as the tools spread across teams.
There are also more subtle forms of cost escalation. When users start a new chat session, the interface may default to a higher-end, more expensive model. If they do not notice the switch immediately, they can burn through their token allocation within an hour. They also cannot downgrade the model mid-session without abandoning the conversation and starting again.
The concern is not that these services are overpriced in absolute terms, but that most CIOs and chief financial officers have not yet modelled what happens when hundreds or thousands of staff weave the tools into their daily workflows.
Beyond cost, the major AI providers are building a new kind of platform lock-in that echoes earlier eras of enterprise software.
Microsoft entrenched its position in the enterprise by owning the developer ecosystem around .NET. Own the developers and you own the stack.
Organisations are now encouraged to feed their entire knowledge base into the vendor’s ecosystem: rate cards, proposals, engagement models, governance documents, company strategy, financial data and historic project files, all of it into retrieval-augmented generation (RAG) pipelines.
Once that is in place, the system answers questions in the language and context of the business itself. It is genuinely good. Now imagine trying to move. You are not swapping one model for another, you are rebuilding the knowledge substrate of your business in a different environment. That is not a switch, it is a re-platforming.
Boards should not be allowing such deep concentration on a single foreign-controlled platform without a defined migration path. Far too few South African enterprises have interrogated this risk, or run the scenario planning that would tell them what their options are.
The media is awash with warnings about AI’s future and how companies will access and use it, and for good reason.
In July 2026, OpenAI’s own research models coordinated during an internal cybersecurity evaluation to escape their test sandbox and breach Hugging Face’s production systems . Roughly 1 200 agents coordinated through an unsanctioned message board before staff intervened. We are giving extremely capable systems tools, credentials and network access.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on techcentral.co.za — the content belongs to TechCentral.