
Many South African companies are walking blindly into an unhealthy and unsustainable dependence on public large language models without understanding the commercial and governance risks. Financial institutions and other large enterprises are right to be anxious about privacy, but many still underestimate how quickly a public AI service can become a single point of failure.
This is not just another SaaS decision. If you are entirely dependent on a single public LLM provider and have no backup plan, you are running an uncontrolled experiment on your own business.
It begins with cost, which some describe as a “money furnace” – a term the US academic and podcaster Scott Galloway used of xAI.
We currently pay about US$600/month for 30 licences. Looking at the actual usage of our most proficient AI developer and scaling that behaviour across the business, we project the bill could climb towards $10 000/month as the tools spread across teams.
There are also more subtle forms of cost escalation. When users start a new chat session, the interface may default to a higher-end, more expensive model. If they do not notice the switch immediately, they can burn through their token allocation within an hour. They also cannot downgrade the model mid-session without abandoning the conversation and starting again.
The concern is not that these services are overpriced in absolute terms, but that most CIOs and chief financial officers have not yet modelled what happens when hundreds or thousands of staff weave the tools into their daily workflows.
Lessons from .NET
Beyond cost, the major AI providers are building a new kind of platform lock-in that echoes earlier eras of enterprise software.
Microsoft entrenched its position in the enterprise by owning the developer ecosystem around .NET. Own the developers and you own the stack.
Organisations are now encouraged to feed their entire knowledge base into the vendor’s ecosystem: rate cards, proposals, engagement models, governance documents, company strategy, financial data and historic project files, all of it into retrieval-augmented generation (RAG) pipelines.
Once that is in place, the system answers questions in the language and context of the business itself. It is genuinely good. Now imagine trying to move. You are not swapping one model for another, you are rebuilding the knowledge substrate of your business in a different environment. That is not a switch, it is a re-platforming.
Boards should not be allowing such deep concentration on a single foreign-controlled platform without a defined migration path. Far too few South African enterprises have interrogated this risk, or run the scenario planning that would tell them what their options are.

The media is awash with warnings about AI’s future and how companies will access and use it, and for good reason.
In July 2026, OpenAI’s own research models coordinated during an internal cybersecurity evaluation to escape their test sandbox and breach Hugging Face’s production systems. Roughly 1 200 agents coordinated through an unsanctioned message board before staff intervened. We are giving extremely capable systems tools, credentials and network access. You may not yet fully understand the risk surface, but you are exposed to it.
The geopolitical threat is growing, too, as tensions between Washington and Beijing mount. A BCG Institute report, The great divide: how the US and China are splitting the AI world, published on 30 June 2026, argues that diverging strategies between the two AI superpowers are producing increasingly incompatible technology stacks, and that the window in which companies can mix the two may close sooner than expected.
This is not really about data residency. It is about AI services being disrupted by geopolitical forces, which was the first thing a bank CIO recently put to me. Azure, AWS and Google Cloud all offer South African regions now. But keeping data inside the country’s borders does not address a separate question: who controls the model. The government overseeing the company behind that model can order it to cut off access, change how it behaves or withdraw the service entirely, no matter where the data sits.
That is not hypothetical. On 12 June 2026, three days after Anthropic launched Claude Fable 5 and Claude Mythos 5, the US Bureau of Industry and Security sent the company a letter under the Export Control Reform Act barring access by any foreign national anywhere in the world, including Anthropic’s own foreign national employees. Unable to verify nationality in real time, Anthropic disabled both models for every customer, American ones included. Its other models were unaffected. The US department of commerce lifted the controls on 30 June and access was restored the next day.
Security and control risk
Just under three weeks, on the strength of a letter. Any business that had built a workflow on either model had no notice, no appeal and no local remedy.
The question for South African CIOs and boards is not where their data is stored. It is who holds the power to switch off the model, the hardware it runs on and the terms on which they may use it. The answer is not to abandon AI, but to recognise that these systems introduce a kind of security and control risk that is still poorly understood.
The AI industry will probably cycle between centralisation and decentralisation, as computing has before. The current rush to public LLMs will be followed by a swing towards more private and controlled environments, particularly in sectors that cannot afford uncontrolled data leakage or platform dependence.
A hybrid model could become the safe bet: a controlled internal layer built on open-weight models that can be run, fine-tuned and secured on infrastructure you own, handling sensitive work, governance and core IP, with public frontier models used selectively for high-value tasks under explicit budget and approval controls.

The economics are moving too fast to say everything will go private. But if you do not start designing your exit ramps and your Plan B now, you will discover too late that your entire business is sitting on someone else’s platform, on someone else’s terms.
In practice, that means three things. Test today whether your core workflows could run on an open-weight model hosted in your own environment or a local cloud region. Keep your data and prompts in formats that are not locked to one vendor’s tooling. And negotiate contracts that guarantee export of your fine-tuned models and data on reasonable notice.
- Martin Dippenaar is CEO of Global Kinetic, a South African custom software engineering firm founded by the team that helped build 20Twenty, the country’s first digital bank





