AI Lock-In, Open Source and Sovereignty Collide | The Open Current Ep 3
### AI Lock-In Raises New Questions About Control
AI lock-in is becoming a central issue as enterprises decide which models, platforms and AI stacks they will trust. In this episode of The Open Current, Alan Shimel and Margaret Dawson examine whether AI is creating another public-cloud-style lock-in cycle. The discussion connects open source, sovereignty, data control and vendor influence into one larger enterprise technology debate.
Margaret argues that AI lock-in is hard to separate from data ownership. Many AI platforms are still black boxes. Enterprises may not fully know where their data goes, how it is used, or whether it becomes part of future model training. That uncertainty makes control and choice more important as AI moves deeper into business workflows.
### Open Source and Sovereignty Meet the AI Stack
The conversation also explores the role of open source in AI. Alan and Margaret discuss concerns around model marketplaces, open-weight models, proprietary platforms and the possibility of major vendors controlling important access points. They compare today’s AI market to earlier technology waves, including public cloud, GitHub, Red Hat and Kubernetes.
Sovereignty is another recurring theme. The episode looks at data sovereignty, AI sovereignty and the need for organizations to understand where their technology runs. For global enterprises, those issues affect compliance, risk and long-term flexibility.
### Composability Becomes the Alternative
The Open Current episode also looks ahead to KubeCon and the collision of Kubernetes, AI workloads and sovereignty. Margaret notes that AI workloads are containerized workloads. That makes Kubernetes and cloud native platforms part of the larger AI lock-in conversation.
The larger takeaway is that AI lock-in is not only about one model. It is about the full stack around the model. That includes agents, protocols, security controls, data access and operational tooling.
For technology leaders, the path forward is open composability. Enterprises need components that can be swapped, integrated and governed across vendors. Without that flexibility, AI systems could become another generation of black-box platforms that are difficult to leave once they become embedded.
Transcript
" Margaret, welcome. It's great to see you again. How are you?
I'm good. It's always great to see you. The sun is out in Seattle, so it never stops here.
Well, that's a good day. I know. It is a good day.
But I got to commend you, though. You're always so coordinated. You got your act together, Margaret.
You know, I wish I could be like you. I'm a marketing leader. Don't you know this is our job?
Like, the sub-job of a CMO is always being coordinated, on brand, right, ready to go at any given moment. You always are. Even though I'm supposed to be neutral.
I get it. This is a neutral podcast, so I should probably wear a different color. I got you.
But still. Well, no, it's okay. I just admire the- Thank you ...
forethought. If I put on a shirt and pants, I think I blow my cover today. I mean, I'm glad you're dressed.
Is that what you want me to say? Because I didn't have words- Yeah, baby ... so I'm really, yeah.
Wow ... it's Thursday, so I do my Shimmy Says on Thursdays. Oh, okay.
So I try to get dressed for that. I mean, we do only see you from the waist up, so- You ne- I don't, don't look down ... don't laugh.
Don't. No, no, no. No, but- This is a family show, Alan.
I got it. But two days ago, I had to do it very early in the morning with someone from Europe. Uh-oh.
And I said, "You know what? Do I really need pants? They're only going to look here.
" And I was like- See, don't go back to those days of COVID, like, where we just know people were like that Remember those days? Exactly. Well.
Mm-hmm. Anyway. Okay.
Let's jump into it. We've got a lot to talk about in this episode, Margaret. So Margaret, we've got a lot to talk about in this episode three, and the overriding kind of theme is, is AI creating kind of the mother of all lock-ins?
And there's a lot of aspects to this locking in, if you will. And really, I think when we peel it back a little bit, we're going to hit on three things. We're going to hit on open source.
Mm-hmm. And part of open source is choice. Mm-hmm.
Right? Mm-hmm. We're going to hit on sovereignty.
Yep. And there's all of these different flavors of sovereignty, data sovereignty, AI sovereignty, et cetera. And then we're going to talk about control, right?
And control of data, but control of employees. I've been reading and I wrote a couple of stories about, you want to call it shadow AI or whatever, but- Mm-hmm ... we'll jump into it.
But Margaret, when I ask you, what's to fear about lock-ins here, around AI? What jumps out at you? I mean, the thing that, and you and I talked about this before, is that I feel like it's public cloud a little bit all over again, in that we have a few players that have become dominant very, very quickly.
They are mostly black boxes. I mean, I think people are waving their hands to open source and doing all the right things and saying all the right things. But at the end of the day, as I always say, if you can lift up the hood and see what's making the car work, great.
If you can't lift up the hood or you look it up and all you see is the ether, a big black box, then that's when you need to be concerned. And all those things you just said bump into each other, right? If we have fewer players controlling any main category, if those players are mostly proprietary, if you can't know for sure what is happening to your data when you are working with those models, then all of that is concerning.
And it's data residency, it's data protection, it's data sovereignty. It's like you said, I love that you said control because I think control and choice are kind of two sides of that teeter-totter. And I think about this all the time, and it's how do we maintain that open ecosystem, the ability to move our data across models or still keep ownership of our data, what we allow that model to have access to, while still making sure we're getting the intelligence and the support and the actions that we need from it?
It's a really hard question. I've got three things I'd like to touch on there with you. First of all, big news today, NVIDIA, besides having just an amazing blowout quarter, it hasn't been confirmed, but everyone's reporting they're buying Hugging Face for about- Yep ...
$13 billion. $150 million revenue, $13 billion price tag. Billion dollars, yeah.
Right. Yeah. That's a nice multiple.
But my open source friends, to say the least, my open source friends, though, are a little up in arms. They're a little concerned. NVIDIA is, let me say up front, NVIDIA's done nothing predatory.
NVIDIA has been almost a model open source supporter to this point. Yep. But to the point you were making, they now control a throttle point where a lot of people, this is how they accessed, over two million- Well, let's look and see what they do.
The analogy I can think of immediately is when Microsoft purchased GitHub, if you remember that. Exactly. Mm-hmm.
And the one thing Microsoft did that was very smart is they kept it standalone. I mean, you could almost say IBM's acquisition of Red Hat, they did the same thing. It's like, this is going to be a separate shop.
Whether that lasts forever or doesn't last forever, let's not get into that analysis at this point. But there are things that NVIDIA could do that signal to the market that we're keeping this open, we're keeping it true to its open source roots. So we'll see if that happens.
I mean, I do believe NVIDIA is doing a lot of very positive things in the open source ecosystem. So if HuggingFace stays truly open, that will be interesting. I think you'll see someone come in to fill the vacuum, because that always happens.
You saw it in any technology that has been open and becomes potentially more closed, somebody fills that gap immediately with a new open source project. So we'll see kind of where that demand comes from, or if all of this comes to fruition. But I'm always an optimist, and I want to say that all the signals I see from NVIDIA are that open source is important.
I mean, a lot of companies that are open source companies have very strong partnerships with them. And as I said, I'm not saying they will, but you know how open source people are. They get real sensitive when you start talking about taking choice away- Yes ...
and closing stuff. The next piece of this control thing, Margaret, is at an enterprise level. Seeing a lot of stories about companies that want to start putting as part of the employment agreement you sign- Mm-hmm ...
that you can only use the approved models for your open source work, right? Yep. Because they don't want IP being uploaded to models.
That's right. As they say, it's a valiant effort, but are they shoveling sand against the tide? I mean, there's another reason for that.
It's not only IP, which I think is something you should be thinking about, because I think what you're giving the agents access to is important. And it's a catch-22, right? Because you're also asking the agents to do more and more on behalf of your company, humans, et cetera, and if you limit their access, are they actually going to provide the full ROI?
So this is, like, a daily thing. I mean, even Salesforce, should this AI tool have access to Salesforce? So it's not even IP, it's customer names, it's PII.
There's a lot of things that you need to be careful about. Because again, going back to the black box, if it's not truly open, do we know what's happening to our data? We know that agents can act out.
We know that they can hallucinate. We know they can go rogue. What's keeping them from maybe breaking out of the box and sending all your customer data somewhere?
Which is a nightmare, even with or without AI. So I think that we have to consistently think about the access. I mean, I always think about going back to, why don't we just give all the agents access control rules like we do with humans, right?
And I think that's what we're getting to. We're kind of going back to security 101 back in my networking days. Yeah, we are.
Right? And so giving them a persona, giving them access control rules, and then kind of monitoring what happens to that data. But I think this is still early days, and there is a cost benefit to doing what you're saying as well.
Like, a lot of companies are standardizing, be it- OpenAI or Anthropic and Claude or Gemini or whatever, because increasingly those companies are doing enterprise agreements. They're learning how to do B2B. And they're saying, "Oh, you can do all you can eat for this," because they know it's going to be just like, again, I hate going back to the cloud analogy, but it's an easy one to do.
At some point, the budget cuts off, so how do they get that enterprise license? Let me bring up the third point about control I wanted to ask you about, and this goes back to the HuggingFace thing too. If you look at the leading LLMs on HuggingFace.
Mm-hmm. I don't know, seven out of 10 or something like that are open-weight models from China. Hmm.
And it's funny, the examples you brought up about an agent gone rogue, that's an agent gone rogue. It's almost innocent. It wasn't really the intent- Right ...
to take anyone's data or whatever. And I'm not saying these open-weight models from China are intending to steal anyone's data, but there are plenty of people who do think that. And so when we talk about lock-in, we talk about control, we talk about data sovereignty.
SUSE is a different company, though you're here in the US, they're a European-based company. They play around the world. You have a huge Asian APAC install base.
Do you hear concerns about the open-weight models around the world? Not really. That hasn't become an issue as much because I think most enterprises or public sector are using the main models, right?
They're using the big ones, or they're growing their own. They're building their own. Yeah.
So I think there, I'm sure is hesitation or there's concern, but it's almost not coming up because they're not even considering that as an option. So I think there's a lot of people that are looking to those models for agility and speed, but I think increasingly we're going to see more and more people building their own models that are much more customized and specific to what they're trying to do, and I think that's still early days and that's just going to become bigger and bigger. And whether they want to share those on the GitHub of models or if that becomes more of their own internal customized model, I think we're going to see a lot of that over time, which will be very interesting.
If it's really going to be open source, what starts to become interesting is if an industry or a company in an industry creates that customized model and then open sources it. So other people in the industry. We haven't quite gotten to that point yet.
I think people are still very nervous or holding onto things that they're building for their specific use case. I envision a day, though, where there's a marketplace. Well, HuggingFace is a marketplace.
Yeah, I don't see how-- We're almost there. You could say that I think we're going to be pretty close. Yeah.
Yeah. I could even see every main model having their marketplace of more customized, refined models for certain use cases, certain industries- Right ... certain sectors or whatever.
Well, we saw that, I think it was Google this week came out with special Gemini editions for legal work and I think finance. And I think that is the future. And we also saw this week Apple come out with Mac Mini, new Mac Mini, Mac Studios that really, you could get 512 gigs of memory on these things, of RAM.
And at that level, with those M6 processors, you can run some serious models. Well, you're seeing that from all of the Silicon companies, too, whether it be NVIDIA or AMD or whatnot, that they're building everything from the developer system to massively scalable systems for data center or whatever, and everything in between. So this personal AI or whatever you want to call it, I think that's becoming real today.
I think this goes back to that's kind of the open source model. Developers are playing with stuff on their desktop in these massively powerful and mostly expensive machines. But then when you want to put that into production or you want to make that an enterprise application, there needs to be that move to a secure, stable, controlled- Yeah ...
environment. So, there's a lot of similarities, I think, to open source. But again, most of those systems are what I would call proprietary systems.
They definitely are. And you talk about expense, there's expense and there's expense. The Apple Studio with the 512 gigs of RAM loaded up like that, I think is about $20,000.
Yeah, something like that. Which is probably-- But the NVIDIA Spark machines and all that, these are $120,000, some of them. So there's an order of magnitude difference.
20 grand, you know, I- I think even the little one, the little Spark I think is around 6K, because we were just looking at that. Oh, is it? Yeah, but that doesn't have anywhere near 512 gigs of RAM.
No. That's just a toy, I guess. That's a toy compared to it.
But nevertheless, I've got to ask you to put your SUSE hat on for a second. Do you see SUSE working with any of these- Oh ... developer boxes and going to market?
So what I would say is in some ways we already are, because I'll just say my favorite saying, which is AI workloads are containerized workloads, because you know how much I love saying that. Mm-hmm. Or I could say containers or Linux, either one of those is my favorite thing to say.
But we have Rancher Desktop in the community that many developers are already using with these systems. Right. So, our job as an enterprise software company is to leverage that richness.
If developers are already using Rancher for their Kubernetes and container management with those AI systems, then again, when it becomes production ready, our job is to say, okay, now move to the supported stable version of Rancher, and then you get all this other stuff around it and observability and blah, blah, blah. So, I think that has been our main model, and we know that developers love to play. They love Linux, they love Kubernetes, and so I think that's just going to follow that same pattern that we do with every other kind of containerized workload, and how it moves from the developer playing and building to, okay, now it needs to become enterprise ready.
I did a Techstrong gang earlier this morning, and we were comparing the world right now compared to when Microsoft was the evil empire. And they're not anymore. " But look, I lived through the Microsoft evil empire.
It was never that evil to me, but there were people who nevertheless said that. Are we overly concerned with lock-in? Let me put it to you that way.
I think that's an oxymoron. I don't think you can be overly concerned with lock-in. We are still seeing people struggling with lock-in from systems from that era, I'll just put it broadly, and they can't get out of it, just because their systems are so locked in.
It takes a long time to release yourself from a proprietary system if the applications that you are using in its infrastructure or other platforms, moving all the stuff off that or migrating is not easy. Now maybe with AI over time, that becomes easier, and so that becomes less of an issue. So maybe AI actually helps us not get locked into AI.
That would be ideal, and I think that's possible. Because creating these tools, we look at all the stuff that MCP can do. I think there's a lot from an integration, migration, modernization, where AI can provide a lot of help in that area as opposed to so you're not getting locked in.
But I- I think we should be concerned. I'm always concerned when things are growing so fast, and we just can't keep track of how our data is being used and leveraged. We could go back to early Google.
Their model became advertising. Facebook, their model became advertising. When your model is making money from someone's data, then you are not incentivized to protect that data.
And I'm not saying they don't. I'm a huge fan of both those companies. But I'm just saying, in general, you look at the business model.
When it comes to AI, you say, okay, what are they using that data for? Are they selling that data? You know what?
When you talk about these model people, they're not selling the data, Margaret, they're training on the data. Correct, but- They are hungry for data ... how is that not selling it?
But I am then paying money, and my prompts are going out and leveraging that data to give me answers. So are they selling the data or not? Well- It's a question.
Maybe not. How would you answer that? Well, no.
It's like, okay, so you fed me grain that I somehow processed into meat. And it became meat that you ate, so yeah. Okay.
Let me give a totally ridiculous analogy based on that one. So I'm gluten free. I'm celiac.
Mm-hmm. Which a lot of Irish people are by descent. And, for a while, I was getting really sick every time I would eat a really nice steak.
" And I was like, "I don't know. " He's like, "Well, think about it. How much beef, especially in the United States, even if it's grass-fed, at the last minute before slaughter, they shove it full of grain, and fatten it up.
" So if we use that as a, that'd be more of a metaphor of AI. Are they feeding these models full of data? And I go in and try to get it, and my data's still being shared with all these people because they're aggregating it or whatever.
It doesn't work perfectly, I don't think, but you know what I mean. So it's great. I get where you're going.
No, no, but hey, I- It could start to make you sick. Right. I smell what you're cooking, I think is the thing here.
Oh. But it's true. That's what's going on here.
They're all desperate for training data. I don't know if you saw this story. All of these rare book places in Europe started getting crazy orders, 5,000, 10,000 books.
They just wanted books. And someone tracked where they were being shipped. They were being shipped to Las Vegas, to an Amazon facility, where they had a machine that ripped the spine off and fed the pa-- These are rare books that aren't in print anymore.
They're ripping the spines off and feeding the pages into scanners to train the models. And then throwing away the paper. Is this true?
This sounds like one of those conspiracy theory stories. You know what? No.
I didn't see it on some strange news channel. Okay. I'll get you the stories.
This is a real true story. Real true stories. Real true stories.
This is not fake news. You heard it here. Right.
No, this is not fake news. That's how valuable training data is. To scan it, why do they have to break the spine?
That sounds like a lot of work. Because how else can you scan in mass? Either way- I see ...
this- I see. Yeah. They break off the spine, they take all the pages and feed it into a scanner.
So at least the content of these rare books is preserved, but they just ruined a beautifully- Oh, you, the optimist. I'm trying to understand. But I guess this is a point.
So now we've broken some beautiful thing, that we were supposed to maintain its historical beauty, I guess, or whatever value, so we can feed these models. That's a good question you're bringing up. What is the appetite?
Where do we stop? Because it almost becomes like what's that musical? " It almost becomes like that- Oh, the "Little Shop of Horrors" ...
" It was a plant. I love that show. Anyway- Mm-hmm ...
but it's kind of like that, where these models are like the- But they really are doing that to the spine of the books. Right. It wasn't even the spine of the books.
What we're talking about is the insatiable need for more and more data. More. So go back to your first question.
" Certainly, this whole lock-in thing is not going away. It's tied into open source. It's tied into sovereignty.
Maybe it was Audrey. Oh, Seymour was the man. Seymour.
Feed me, Seymour. Feed me, Seymour. That's what I remember.
Maybe the plant was Audrey. Maybe I don't even know the plant's name. Could be.
Seymour was the- Well, this is what happens. Feed me, Seymour ... this is what happens.
See, I said Stanley. You're erroneous. That was close.
Stanley, Seymour. That was close. But that's not the plant's name.
I thought it was Harvey. I'm sorry, Paul. I have to apologize.
The plant is named Audrey, which I don't remember that. There you go. Now, I said Harvey, Seymour, Stanley.
They all sound like guys down here in Boca. I'm not touching that. No, don't touch it.
I am not touching that. Leave it alone. Okay.
Go back to your analysis. We got a lot of friends. All right.
This is perfect. Let's go back to the lock-in. I'm so glad we're going sideways.
Okay, now we're onto the Alan Margaret Show. Now it's real. Okay.
I got it, my friend Murray. We have all kinds of people like that here. Oh my, Murray.
But anyway- That is a great name, Murray ... my friend Murray Siegel is a friend. He's a- So I think those should be the names of these models.
Why are we making the models like Gemini? We should call it Murray. Claude was a good name.
Yeah, Claude. That sounds very futuristic. Yeah, but you've got Sol and Terra and Luna.
Yeah. They're going for the auras the next one after that. Did I tell you that I renamed my Alexa?
Did you? This is relevant. It's AI.
They're trying to make it more- Yeah. So you only had so many options. Yes.
But I chose Ziggy, and it's like this really- Oh ... kind of, I don't know if I should say sexy, but very approachable, lovely man's voice. Yeah.
" He's like, "You got it. " Really? Oh.
" So it's not just the name, it's a personality that goes with the name. It's a persona. Yeah, you can choose- Right.
Persona ... " Yeah, I know. I'm like, oh, God.
Yeah, no, she's a Valley girl. I raised three children. I don't need to listen to that.
Now we're in the Margaret. Yes, now you got me going. I've got to go home and- Okay, bring it back.
Bring it back. So data ... mess with my Alexa.
But can we go back to lock-in for a second? Can we go back to lock-in for a second? Yes.
Yes. Let's go back to lock-in and open source. We're getting closer and closer to KubeCon.
Yep. Right? We're only got two months out now.
September, October, early November, it'll be here. Any insight into what you think we might see there around lock-in and open source with AI? What's interesting at KubeCon, and you've seen this evolution, and we see this in a lot of open source shows kind of over the years.
They start really pure, very developer. It happened at OpenStack. It happened at the kind of the true open source maintainers and contributors, and then corporate starts to come in a little bit, and now it's become even, I would say, a business show, an executive show, in addition to still developers and contributors and people kind of hands on keyboards.
I think AI and Kubernetes have just crashed into each other 100%. Not only because AI workloads are going to ride on Kubernetes, but, I just think there's so much there, and so I think we're going to hear a lot. And what's interesting is there's also a sovereign day or a sovereign- Yes ...
sub-event. On Monday- Right ... day, right- Exactly ...
is the sovereign sessions. So Monday day. That special day called Monday day.
Yeah. And day zero, or day one, whatever it's called. So I think it's already happening, and it started at the last KubeCon.
So we've got Kubernetes, we've got AI, we've got sovereignty, we've got data security all crashing into each other. So I think it's just going to be, and you're going to see AI on every single booth. So we'll see all the different manifestations of that.
But I think it was already happening, so yeah, it'll be all over. Now, whether or not- People will talk about lock-in versus open source and how do we maintain that true thing, but you can see, even in the market, how many container management platforms or cloud native platforms are taking Kubernetes and then locking them down in their own platforms versus keeping them open. So why would we expect anything else to be different?
com. It's not just about the agent, it's about the models, the agent, the harness, the whole platform. Right.
" There's a whole ecosystem. Well, you got to look at the whole AI stack. I'm a stack girl.
Right. I always look at the layers there, and I think what you're bringing up is really important because it's not only the whole stack and what layers are closed versus open, but the ecosystem then around it, and the standards around it. And I said this, I think, last time that what we need to look at is the industry coming together to agree on standards like we did with USB-C, and do the same thing for MCP, for some agentic protocols, for some other ways that we're integrating, for some, I don't even know.
We can think about that and obviously the infrastructure, the application layer, all that plays into it. But I'm more concerned with the layer around that, the security protocols, the connection protocols, et cetera. What I worry about is as often as we've talked about the pain of integration for 30, 40 years, we still could never agree on a true OpenAPI standard.
Everybody wanted you to write to their own APIs and SDKs. So my fear is that we're going to get to the same thing. Oh, write to my MCP, write to my agentic protocols, write to my.
Yep. And that's when we get the mess, the complexity, and then you have a whole bunch of companies whose entire existence is just helping you connect these dots, like the Boomis and the Informaticas of old, right? Sure.
And maybe you could say, "Oh, isn't that great? " No, it's not great because it should just be open and we should be able to do that because it's all based on standards. So I'm more concerned about that than just the model itself as I think about all of the different components of the full kind of architecture or environment around it.
Yeah. I don't think the model locks you in. I think it's the whole stack that locks you in.
Mm-hmm. And we've got to make sure that when we look at that stack, the different levels, components- You got it ... can be swapped in and out.
Yeah. Otherwise, you are locked in. No, I think you- You are locked in.
You know I love composability, so I think we could almost wrap it up there is that the opposite of lock-in is open composability. And so is AI and all of the organizations going to rise to that occasion and allow you to have components that play nice with each other and interoperable and multi-vendor? Or are we going to create huge black boxes where you make a big bet?
That remains to be seen. Stay tuned. Margaret, that's a great place to end this, absolutely.
Actually, you know what? We'll be back on in two weeks with another episode, but what do you got coming up? Any exciting exotic travel or?
I do. I'm heading to Shanghai in a week because we have- Ooh ... KubeCon Shanghai that you- Yes ...
I forgot about that. So I'll be at KubeCon Shanghai for all of you. And then, we're having a SUSE Summit in Shanghai that same week, so I'll be speaking there- Oh, very nice ...
in the customers and partners. And then I head to Singapore, and we have a bunch of meetings- Cool ... and a summit there.
So yeah, I'll be in Asia for two weeks. Looking forward to it. Oh, well, enjoy it.
I loved Shanghai. Of all the cities I've been to in China, granted, I've only been to about four, but Shanghai was my favorite. But Singapore is one of my favorite places in the world, too.
And hopefully it'll be a little cooler by the time you get there. Hopefully. I don't think it will.
It's hot in the summer. It is hot. Well, compared to where I am here, it's not saying.
But anyway, Margaret, it's great having you. " This is episode three. If you haven't caught the first two, you can check them out on- Whatever ...
whatever your favorite podcast platform is. Because we're open- Or here on Techstronghold ... and interoperable.
We are open, and we don't lock you in. There you go. All right, my color-coordinated friend, thank you so much for being on here.
Thank you. See you soon. Thank you for watching.
We'll see you all soon. "

