ARCHITECTURE · June 7, 2026
You escaped model lock-in. They moved it to your context.
Keeping the model swappable was the win of the year — you can change providers with a one-line config now. So at Build 2026 Microsoft calmly relocated the lock-in to where you can't swap it: your organization's context. Work IQ, Fabric IQ, Foundry IQ — your company's memory, permissions, and meaning, living inside a vendor's interpretation of your business. As one analyst put it: you can swap the brain. You may not be able to swap the memory. Here's the new trap, and how to keep the thing that actually matters portable.
A few days ago I argued that the model is a commodity you should keep behind a clean seam, so that swapping providers is a one-line change and no vendor owns the part of your system you most depend on. That's still true, and it's still the right move. But this week made the other half of the story impossible to ignore: the big platforms heard "the model is commoditizing" loud and clear, and they've already moved the lock-in somewhere you can't swap with a config value.
At Build 2026, Microsoft introduced Microsoft IQ — a stack of context layers for agents: Work IQ for your Microsoft 365 signals, Fabric IQ for your business data, Foundry IQ for app and agent context, Web IQ for fresh grounding. On the surface it solves a real problem: agents are useless without context about your actual business. Underneath, it's the most elegant lock-in strategy I've seen in years — and it works precisely because the model stopped being one.
The brain got cheap, so they're selling you the memory
Here's the shift, stated as plainly as I can. The old lock-in was infrastructure: compute, storage, databases, deployment pipelines. The new lock-in is organizational memory, tool permissions, grounding behavior, and the agent runtime that ties them together. One write-up put it better than I could:
A model-agnostic context layer can still be a context lock-in. You may be able to swap the brain. You may not be able to swap the memory.
That sentence is the whole post. Yes, you won the right to change models freely — and the platforms conceded it without a fight, because they realized the durable hold was never the model. It's the layer that knows your org: who's who, which document is canonical, what "approved" means in your company, which permissions gate which data, how your business's entities relate. Once your agents depend on Work IQ semantics, Microsoft 365 permissions, Fabric ontologies, and whatever ranking logic decides which internal fact matters, you've built — in the words of that same analysis — on a vendor's interpretation of your organization. That's still lock-in. It's just lock-in you encoded yourself, one helpful integration at a time.
Why context is so much stickier than a model
A model swap is mechanical: same prompt in, comparable answer out. Context is the opposite — it's accumulated. The longer your agents run on a context platform, the more of your company's meaning gets poured into that vendor's shapes: its ontology format, its permission model, its definition of an entity. Migrating away isn't editing a config; it's reconstructing your organization's entire semantic layer somewhere else. That's why the platforms are happy to let the model go. They kept the part that compounds.
And it's not only Microsoft playing this game from the other direction. SAP's 2026 API policy now forbids using its APIs to feed autonomous or generative AI systems — a reminder that whoever holds your business data holds your agents by the throat. The lock-in war of 2026 isn't about models. It's about who owns the context the models run on.
What to actually do about it
You can't avoid using context platforms — agents genuinely need grounding, and building all of it yourself is rarely the answer. The goal isn't purity, it's keeping the part that compounds under your control. A few principles:
- Own your source of truth, even when you rent the convenience. The deterministic data and rules your agents ground on should live somewhere you control — a boring database you own, not only a vendor's proprietary context graph. Mirror into their layer for convenience; don't let it become the only copy.
- Treat your context schema as an asset to keep portable. Your ontology — how your business defines its entities and relationships — is the thing with real gravity. Keep a vendor-neutral definition of it that you could re-point at a different runtime, the same way you kept the model swappable.
- Watch the seams you can't see. The new lock-in hides in permissions, ranking logic, and grounding behavior — the parts that quietly decide what your agent "knows." Ask, for anything you adopt: if I left this platform, what would my agents forget, and could I rebuild it?
- Apply the same test you apply to models. I keep asking of a provider: if they doubled the price tomorrow, how long to move? Ask it of the context layer too. If the honest answer is "we never could," you didn't escape lock-in. You upgraded it.
The bottom line
The story everyone told this year — the model was never the moat — was right, and the platforms believed it faster than their customers did. They gave up the commodity and quietly fortified the thing that actually holds you: your own organization's memory, rebuilt inside their walls.
So enjoy your one-line model swaps; they're real and they're good. Just don't mistake them for freedom. The question that decides whether you're independent isn't "can I change the model" anymore. It's "do I still own the context when I walk out the door" — because the brain was always rentable, and the memory is the moat now. Keep yours.
Comments
No comments yet
Sign in to join the conversation.
Be the first to share a thought.