Many companies in South Africa are unknowingly sinking into a dangerous and unsustainable dependence on public large language models, unaware of the associated commercial and management risks. Financial institutions and other large enterprises are rightly concerned about privacy, but many underestimate how quickly a public AI service can become a single point of failure.
This goes beyond simply deciding on a SaaS product. If a business is entirely dependent on one provider of a public LLM and has no backup plan, it is essentially conducting an uncontrolled experiment on its own operations.
The problem starts with costs, which some call a 'money furnace'—a term used by American academic and podcaster Scott Galloway regarding xAI. Currently, the company spends about $600 USD per month for 30 licenses. When assessing the actual usage of the most competent AI developer and scaling this behavior across the entire business, the bill is projected to rise to $10,000 per month as tools spread among teams.
There are also more subtle forms of cost growth. When users start a new chat session, the interface may default to a more expensive, high-performance model. If they do not notice this switch immediately, they could exhaust their token limit within an hour. Furthermore, they cannot downgrade the model during a session without interrupting the conversation and starting it over.
The main concern is not that these services are excessively expensive in absolute terms, but that most Chief Information Officers (CIOs) and Chief Financial Officers (CFOs) have not modeled what will happen when hundreds or thousands of employees integrate these tools into their daily work.
Lessons from .NET
Beyond financial aspects, major AI providers are creating a new type of platform dependency reminiscent of the early eras of enterprise software. Microsoft has solidified its position in the corporate sector by owning the developer ecosystem around .NET. Owning the developers means owning the stack.
Now, organizations are being asked to upload their entire knowledge base into the vendor's ecosystem: pricing tiers, proposals, interaction models, governance documents, company strategy, financial data, and historical project files—all into Retrieval-Augmented Generation (RAG) pipelines. Once implemented, the system answers questions in the language and context of the business itself. This is truly effective. Now imagine the attempt at migration. You are not swapping one model for another; you are rebuilding your business's knowledge base in a different environment. This is not switching; it is replatforming.
Boards of directors must not allow such deep concentration on a single platform controlled by foreign powers without a clear migration plan. Too few South African enterprises have studied this risk or conducted scenario planning that would show them their options.
The media is flooded with warnings about the future of AI and how companies will access and use it, and for good reason. In July 2026, OpenAI's proprietary research models coordinated actions during an internal cybersecurity assessment to exit a test sandbox and hack Hugging Face production systems. Approximately 1200 agents coordinated through an unauthorized message forum before staff intervention. We provide extremely capable systems with tools, credentials, and network access. You may not fully understand the surface of the risk yet, but you are exposed to it.
Geopolitical threats are also increasing amid escalating tensions between Washington and Beijing. A BCG Institute report, 'The Great Divide: How the US and China Are Splitting the AI World,' published on June 30, 2026, asserts that the diverging strategies of the two superpowers in AI are leading to increasingly incompatible technology stacks, and the window of opportunity for mixing these technologies may close sooner than expected.
It is not so much about data residency. It is about the fact that AI services can be disrupted by geopolitical forces, as a bank CIO recently told me. Azure, AWS, and Google Cloud now offer regions in South Africa. But storing data within the country's borders does not solve the separate question: who controls the model. The government overseeing the company behind that model can order it to cease access, change its behavior, or completely withdraw the service, regardless of where the data is located.
This is not a hypothetical scenario. On June 12, 2026, three days after the launch of Anthropic Claude Fable 5 and Claude Mythos 5, the U.S. Bureau of Industry and Security sent a letter to the company under the Export Control Reform Act, prohibiting access by any foreign national wherever they may be, including foreign employees of Anthropic itself. Unable to verify nationality in real time, Anthropic disabled both models for all customers, including American ones. Its other models remained unaffected. The U.S. Department of Commerce lifted restrictions on June 30, and access was restored the following day.
Security and Control Risks
Just three weeks later, based on the letter. Any business that built a workflow on one of these models received no notification, had no right of appeal, and had no local legal recourse.
The question for CIOs and South African boards of directors is not where their data is stored, but who has the authority to disable the model, on what hardware it runs, and under what conditions they can use it. The answer is not to reject AI, but to acknowledge that these systems introduce a certain security and control risk that is still insufficiently understood.
The AI industry will likely cycle from centralization to decentralization, similar to computing previously. The current rush toward public LLMs will give way to a trend toward more private and controlled environments, especially in sectors that cannot afford uncontrolled data leakage or platform dependency.
A hybrid model could be a safe option: a controlled internal layer built on open-weight models that can be run, fine-tuned, and secured on infrastructure you own, for handling sensitive work, governance, and core intellectual property, while public cutting-edge models are used selectively for high-value tasks under explicit budget and approval control.
The economy is moving too fast to claim everything will become private. But if you do not start designing your exit routes and Plan B now, you will find too late that your entire business is on someone else's platform, on someone else's terms.
In practice, this means three things. Check today whether your core workflows can run on an open-weight model hosted in your own environment or in a local cloud region. Store your data and queries in formats that are not tied to one vendor's tooling. And sign contracts guaranteeing the export of your fine-tuned models and data with reasonable notice.
_