Vendor lock-in and proprietary black boxes

Lock-in

Europe loves a good mystery, preferably one involving a labyrinth, a dragon, and a contractual clause written during the Bronze Age. What we mostly have are vendor systems that behave like enchanted artefacts in a Pratchettian bazaar: they work only when the vendor priests are in a good mood, they cannot be opened without voiding several warranties, and they explode on a timetable known only to themselves.

From industrial control systems to cloud ecosystems, organisations are surrounded by magnificent machinery they ostensibly own yet somehow may not touch. The code cannot be seen, the configuration cannot be adjusted, and patches arrive with the vendor’s blessing, bestowed about as often as unicorn sightings. Vulnerabilities flourish, unknown and unfixed, while customers carry on bravely clutching the risk register like a comfort blanket.

The gilded cage

The system was bought and paid for. It lives in your rack, consumes your electricity, and screams like a gremlin when it malfunctions. Yet prod it with a screwdriver and the vendor materialises like an offended wizard to remind you that you do not really own it; you rent the privilege of its presence. The contract permits use but forbids peeking inside, reverse engineering, modification, or integration with anything the vendor has not personally shaken hands with. Support costs extra. Updates cost extra. Security, though nobody says so in polite company, costs extra. When something breaks, a ticket is filed, and the fix joins a roadmap that moves at the pace of a very shy glacier. Complaints are answered with an offer of a new product line suspiciously like the current one, at twice the price, in a colour nobody asked for.

The black box problem

You cannot audit what you cannot see. Proprietary software is a sealed coffin the vendor assures you is definitely empty and definitely safe, but which you may not open, for your own protection. Questions about what the system collects, where it sends it, and whether the encryption is modern or medieval receive the practised answer that everything is proprietary information, which can be industry shorthand for held together with brittle code and prayer beads. Auditors then ask for documentation that cannot exist: no source code, no architecture diagrams, no penetration tests without vendor permission. The audit concludes the system cannot be verified, everyone nods, and the same conversation is filed for the next audit. Public CVE databases meanwhile list issues vendors have chosen not to fix, and the vulnerabilities nobody is allowed to look for are found, in the end, by the people who do not ask permission.

The ancient horrors and the modern variant

Deep in Europe’s critical infrastructure lurk control systems from the era of large beige machines smelling faintly of ozone, never intended for networks, later networked anyway with TCP/IP attached like a sticky plaster. They run long-discontinued operating systems, speak proprietary dialects known to long-retired engineers, and cannot tolerate patches. When such a vendor dies, a private equity firm often buys the carcass, sacks the staff, and sells the intellectual property to whoever fancies a bargain, leaving the only certified control system orphaned. Replacing it costs millions; continuing to run it is madness; organisations do both.

Cloud is the same play with better catering. Free tiers lure, platform-specific features hold, and one day the prices creep up and leaving turns out to involve a migration so convoluted it should come with a Minotaur. Export tools crawl, integrations need rewriting, staff need retraining, and procurement does the maths and quietly signs the renewal. The specifics differ by provider:

The open door few walk through

Open source alternatives exist: transparent, auditable, modifiable, often strong on security. Many organisations recoil anyway, because there is no corporate scapegoat to sue, no glossy brochure, no reassuring brand, and procurement teams can fear responsibility more than risk. Ironically, plenty of proprietary systems contain vast amounts of open source under licensing restrictions; customers pay for the privilege of ignorance. Regulators, for their part, often speak in noble generalities about appropriate technical measures, and a vendor can comply with the letter while trampling the intent. Attackers, meanwhile, get on with the job.

The clerk’s brief

From the clerks, for the Patrician’s eyes

Compiled July 2026. Newest first; older material settles into the exit file at the end. The clerks observe that every entry below concerns an exit: priced, blocked, regulated, or attempted. None concerns an exit completed.

November 2025: The dependency acquires a supervisor

On 18 November 2025 the European supervisory authorities designated the first 19 critical ICT third-party providers under DORA, placing the cloud and software providers on whom European finance depends under direct oversight. For the first time, concentration itself is treated as the risk, not merely each firm’s contract with it. The clerks note that the Union has begun supervising the cages, which is not the same as opening them, but does mean someone now counts the occupants.

October 2025: The watchdog runs out of colours

CISPE’s European Cloud Competition Observatory issued its third report on Broadcom’s VMware licensing in October 2025, assigning a red alert, its most severe rating, over unilateral, market-distorting programme changes, as reported by The Register. The pattern under scrutiny: acquire the incumbent, terminate longstanding licences without much notice, and reprice the captivity. The clerks admire the business model in the way one admires a well-executed heist.

June 2025: Two governments try the door

Denmark’s Ministry of Digitalisation announced in June 2025 it would replace Microsoft Office with LibreOffice, citing dependence rather than cost, in the same week Schleswig-Holstein confirmed its own migration. These are the most watched lock-in exits in Europe precisely because they are so rare, and because everyone wants to know the true price of the door. The clerks are keeping a separate page for what the migrations cost against what the renewals would have, and expect it to be quoted for a decade either way.

May 2025: The captivity is priced

CISPE members reported VMware licensing cost increases of 800 to 1,500 per cent to the European Commission following Broadcom’s acquisition, as reported by The Register in May 2025 alongside the observatory’s second report. An increase of that size is not a price adjustment; it is a measurement of how expensive the exits are believed to be. The vendor, the clerks note, has simply published its estimate of the Minotaur.

The exit file

The mechanism has not changed since the file was opened: certification freezes systems, contracts forbid inspection, and acquisition events reprice the dependency overnight, with the ECCO watchdog documenting the Broadcom case since February 2025. What is new is the legal scaffolding around it: the Data Act, applicable since September 2025, sets a framework for switching between data-processing services, and DORA’s November 2025 designations put systemic providers under supervision. The clerks’ standing assessment: the law is slowly making exits a right, while economics keeps making them a project, and rights that cost millions to exercise are exercised mainly in press releases.