ConceptAdvancedAI Opportunity & Model Strategy / Evaluating AI vendors as a buyer / #20
What does vendor lock-in look like when the vendor holds your embeddings?
GUARD the lock isn't the contract clause, it's who never gets asked
Alder Hotel Group is a mid-size hospitality brand with forty franchise properties. Tomas Reyes is VP of Guest Experience Product at the corporate office. Havenly is the AI concierge vendor whose model holds every guest's preference embeddings, built from years of stay history across every property.
The direct answer
Lock-in looks like this: the individual hotel properties, not corporate, are the ones who can't leave, because the guest-preference embeddings a franchisee's own repeat customers built over years live only inside the vendor's proprietary format. Reduce it by contracting for a portable export of the raw preference signals, not just the vendor's finished embeddings, before the switching cost gets too large to pay.
Do this, in order
Contract for export of raw preference signals, not the vendor's proprietary embeddings.Why: a proprietary embedding is only readable by the model that made it, so exporting it exports nothing usable.
Name which stakeholder actually can't leave, not just whether "we" could leave.Why: corporate signed the contract, but individual properties are the ones stuck if it goes wrong.
Track switching cost by year, before it crosses what you'd ever be willing to pay.Why: lock-in isn't a single moment, it's a number that grows quietly until nobody wants to look at it.
Give properties a real appeal path when the vendor's suggestions go wrong for their guests specifically.Why: without one, a property's only real option is to keep absorbing bad recommendations or quit the platform entirely.
Watch renewal pricing for a jump with no matching improvement in service.Why: a price jump with no pushback is usually the first visible sign that lock-in has already set in.
How to answer this, stage by stage
Nobody is testing whether you know the phrase "vendor lock-in." They're testing whether you can name who specifically gets stuck, and what you'd have built differently before the contract was signed.
Stage 1
Scope it to one real relationship
Say it like this
"I'll answer this for Alder Hotel Group, a forty-property hotel brand, and Havenly, the AI concierge vendor holding every guest's preference embeddings."
Why this works
Keeps "vendor lock-in" from turning into an abstract procurement lecture.
Stage 2
Say your structure out loud
Say it like this
"I'll use GUARD. Groups, who's involved. Unequal, where the power actually sits. Ability to contest, who can push back. Reduce, the design change. Detect, how you'd catch it happening."
Why this works
Signals you're going to name the power imbalance directly, not talk around it.
Stage 3
Name both people, not just "the vendor"
Say it like this
"Two groups sit on either side of this. Corporate signed the Havenly contract and can walk away in theory. The individual franchise properties are the ones whose repeat guests' preference data is actually trapped, and they never signed anything themselves."
Why this works
This is the strongest move in GUARD: naming who has the lever and who doesn't.
Stage 4
Give the one decision, before any reasoning
Say it like this
"Lock-in here looks like a proprietary embedding format with no export path. My fix is contracting for the raw preference signals to be exportable, in a portable format, from day one, not after we've already noticed we're stuck."
Why this works
This is the direct answer, said plainly, before the story does any convincing for it.
Stage 5
Prove it with the compressed failure
Say it like this
"One property tried to leave Havenly after a bad renewal quote. There was no export button for its own guests' preference profiles, so leaving meant asking every repeat guest to rebuild years of history from scratch, and the property renewed instead, at a much higher price."
Why this works
Turns "lock-in is bad" into one specific property's actual, felt choice.
Stage 6
Say how you'd detect it in production
Say it like this
"I'd track the estimated migration cost per property every year, not just at renewal, and flag any year it grows faster than the value the platform is actually delivering. That's the number that tells you lock-in is deepening before a renewal notice forces the conversation."
Why this works
Shows you'd catch this happening in production, not just recognize it after the fact.
Stage 7
Close on the one line
Say it like this
"Lock-in isn't the contract clause. It's the moment the people who never signed anything are the ones with no way out. Design the export path before that moment arrives, not after."
Why this works
Restates the direct answer in one breath, ready to hold up under a follow-up.
What happens the first time a hotel brand tries to leave?
Say a chain builds an AI concierge that learns each guest's preferences, quiet room, extra pillows, a coffee order remembered from last stay, and gets better at anticipating them the longer a guest keeps returning.
Before Havenly, a front-desk team tracked regulars in a shared notebook and a handful of memorized faces, catching maybe one in five returning-guest preferences without being told. Havenly's model, trained on years of stay history, now surfaces the right preference for roughly nine in ten returning guests before they ask.
None of these four pieces are exportable in a form any other vendor's model could read.
Here's the turn: the better Havenly's suggestions got, the more each property's guest relationships became something that only existed inside Havenly's own model. The preference data was real and valuable. It just wasn't the property's to take anywhere else.
Who never gets to push back
Corporate signed the Havenly contract and has a seat at the renewal table. The individual franchise property, whose own regular guests built that preference history, was never a party to that contract and has no lever of its own if the terms turn bad.
One side of this picture can renegotiate. The other side can only accept whatever the first side decides.
At its worst, this costs a property its own repeat-guest relationships. Not because the guests stopped coming back, but because the record of who they are and what they want lives somewhere the property can't reach without the vendor's permission.
Estimated cost to migrate a property's guest data away from Havenly, by contract year
By year three, the migration cost already exceeds what most single properties budget for a whole year of software.
The reduce step, the design change: Alder should have contracted for the raw preference signals, room temperature choices, dietary notes, request history, to be exportable in a standard format from day one, separate from whatever proprietary embedding Havenly's own model derives from them. The embedding itself doesn't need to be portable. The underlying facts it was built from do.
What I would leave alone: Havenly's actual recommendation model doesn't need to be open-sourced or handed over. A vendor is allowed to keep its own modeling approach proprietary. The problem was never that Havenly's methods were secret. It was that the raw guest facts behind those methods had no exit door at all.
The fix asks for the left panel to exist. It never asked Havenly to give up the right one.
The lesson: ask, before you sign anything, not whether your company can walk away from a vendor, but which of the people your company represents actually can't.
Now here is the same thing as a story
The short version above is what you'd say defending this call to Alder's franchise council. Read this one for what it actually looked like on the ground.
The concierge desk at Alder's downtown Denver property gets its regulars back three, four times a year, business travelers who've been staying there since before Havenly ever existed. For two years after Havenly launched, that desk had never worked better. A returning guest's coffee order, their quiet-floor request, their allergy note, all of it surfaced on the front-desk screen before the guest said a word.
Then Havenly's parent company was acquired, and the new ownership doubled the per-property licensing fee at the next renewal. The Denver property's general manager, who'd watched three years of loyal guest data accumulate inside the platform, asked what it would take to move to a cheaper concierge tool instead.
Knowledge spark: what's actually in an embedding?
An embedding is the model's own compressed, internal way of representing a guest's preferences, a long list of numbers that means something only to the model that made it. It isn't a spreadsheet of "likes quiet floor, allergic to shellfish" that another system could just read. Without the vendor's cooperation, an embedding is close to unusable anywhere else.
The answer came back fast: there was no export tool for guest preference data, only for basic loyalty-tier records already stored elsewhere. Rebuilding three years of preference history with a new vendor meant asking every regular guest, individually, to answer the same questions Havenly had learned quietly over dozens of stays.
The gap in the middle isn't a bug. It's the decision nobody wrote down when the contract was signed.
The property didn't lose its regulars. It lost the ability to prove, to anyone but Havenly, that it had ever known them at all.
The general manager renewed at the higher price. Not because Havenly's product had gotten better, but because the cost of rebuilding three years of guest memory from nothing was worse than the price increase. That renewal happened at forty of Alder's properties that same quarter, and Havenly's parent company knew it would before the new pricing ever went out.
Alder's contract with Havenly sat on the rightmost branch for three years before anyone drew this tree.
GUARD, in one screenNot a checklist for a legal review. GUARD is what tells you whose leverage actually disappeared, and when.
G
Groups. Who's actually involved.
Alder corporate, who signed the contract. The individual franchise property, whose guests' preference history is what's actually at stake.
Names both sides instead of treating "the company" as one uniform actor.
U
Unequal. Where the harm actually lands.
The property absorbs the switching cost and the guest relationship risk. Corporate absorbs neither directly, since it isn't the one whose regulars are stuck mid-relationship.
Shows the imbalance isn't abstract, it's a specific, uneven cost.
A
Ability to contest. Who never gets to push back.
The property never signed anything with Havenly directly and has no seat at the renewal table. Its only real lever is absorbing the price increase or losing years of guest history.
This is the hardest step, and the one most answers skip: naming who has no lever at all.
R
Reduce. The specific design change.
Contract for export of the raw preference signals, in a portable format, separate from Havenly's own proprietary embedding.
A real product and contract decision, not a policy memo about "data ownership."
D
Detect. How you'd know before someone tells you.
Track estimated migration cost per property every year, flagging any year it grows faster than the platform's own measured value.
Catches lock-in as a rising number, not as a surprise at the renewal meeting.
Any one of these three showing up is worth a real conversation before the next renewal, not after.
The recap, one line per letter: groups is naming corporate and the property separately, unequal is the property absorbing the switching cost corporate never feels, ability to contest is the property having no lever of its own, reduce is contracting for portable raw signals instead of a locked embedding, and detect is watching migration cost climb every year rather than waking up to it at renewal.
And if you want to be sure it really works, try it somewhere elseSame five letters, a school district's AI tutoring vendor instead of a hotel concierge. A different silenced group breaks the second story.
Cypress Unified School District uses Lumenpath, an AI tutoring platform that builds a learning profile embedding for every student, tracking which explanations actually helped each child understand a concept over several years of school. Ravi Chandrasekhar, Director of Ed-Tech, manages the district's contract. Mapped onto GUARD: groups is the district, which negotiates the contract, and the students and their parents, who never see it; unequal is that a student who struggles with Lumenpath's teaching style has no real say in switching platforms mid-year, since that decision sits entirely with the district; ability to contest is the sharpest gap here, a ten-year-old has no lever at all, and a parent's only real option is opting the child out of AI tutoring altogether, losing the personalization along with the platform.
The old decision here isn't a switching-cost problem, it's a different reversal: the district agreed to let Lumenpath store each student's learning-style profile as a single, opaque embedding with no parent-facing summary of what it actually contained. That made sense as a way to keep the interface simple for teachers. It stopped making sense the moment a parent asked, reasonably, what the system had concluded about their child, and there was no readable answer to give them, only a vector no person at the district could actually interpret.
Swap the caption and the picture holds: a parent has exactly as little leverage as the property GM did.
Lumenpath's learning-profile data volume held per student, growing by grade year
By grade seven a student's learning profile is nearly four years deep, all of it unreadable outside Lumenpath's own system, exactly the pattern the property GM's guest data followed at Alder.
Swap the trigger and it still runs.
Speed: an interviewer caps you at sixty seconds. Say "name who has no lever, then design the export path before the switching cost gets too big to pay," and stop.
Cost: there's no budget to renegotiate every existing vendor contract at once. Say so honestly, and start with the contract closest to renewal, where the leverage to ask for portability is actually still real.
The model gets better, for real: if Havenly's recommendations genuinely improve enough that no property would ever want to leave, that's still worth detecting, because a vendor that's earned loyalty honestly doesn't need a locked format to keep it.
Where people run it wrong.
They treat lock-in as purely a legal or pricing problem instead of asking who specifically has no leverage.
They assume "the company can walk away" settles the question, without asking whether every part of the company actually can.
They wait to raise portability until the renewal conversation, when the switching cost has already grown too large to use as real leverage.
How to use it live. When someone asks about lock-in, ask back: whose data is this, really, and did that person or that property ever get a say in the contract that traps it? Let that answer decide what "reduce" means here.
Flashcards (tap any card to flip it)
1 · THE FRAMEWORK
What framework fits a risk and power-imbalance question like vendor lock-in?
Tap to flip
ANSWER
GUARD: groups, unequal, ability to contest, reduce, detect. It forces you to name who has no lever, not just that a risk exists.
2 · THE PERSON
Who is this answer about?
Tap to flip
ANSWER
Tomas Reyes, VP of Guest Experience Product at Alder Hotel Group, and the general manager of its Denver property, whose regulars' preference data was trapped in Havenly's format.
3 · THE GROUPS
Name the two groups this answer says to keep separate.
Tap to flip
ANSWER
Alder corporate, who signed the Havenly contract, and the individual franchise property, whose own repeat guests' preference history is what's actually locked in.
4 · ABILITY TO CONTEST
Who never gets to push back in this story, and why?
Tap to flip
ANSWER
The property. It never signed anything directly with Havenly, so it has no seat at the renewal table and no lever beyond accepting the price or losing years of guest history.
5 · THE REDUCE STEP
What decision would you take back or design differently?
Tap to flip
ANSWER
Contract for export of the raw preference signals in a portable format from day one, instead of leaving only Havenly's proprietary embedding as the record of guest history.
6 · THE NUMBER
Fill in the blank: by contract year four, the estimated cost to migrate a single property's guest data away from Havenly reached about ___ dollars.
Tap to flip
ANSWER
140,000 dollars, up from 8,000 in year one. It climbed roughly six-fold from year three to year four alone.
7 · THE DETECT STEP
What would you watch in production to catch lock-in deepening before a renewal notice forces the issue?
Tap to flip
ANSWER
Estimated migration cost per property, tracked yearly, flagged the moment it grows faster than the platform's own measured value to that property.
8 · CROSS PRODUCT TRANSFER
Section 4 answers this same question again for a different product. Which product, and who is the silenced group there?
Tap to flip
ANSWER
Cypress Unified School District's Lumenpath AI tutoring platform. The silenced group is students and parents, who never see the contract and have no readable view into what the learning-profile embedding actually says about their child.
Check yourself Score: 0 / 0
Fill in the blank
1. Fill in the blank: the property that tried to leave Havenly found there was no ___ tool for its own guests' preference data.
Show hint
Look at the flow diagram, "Where the exit path should be and isn't."
Show answer
Export. Only basic loyalty-tier records had one; the preference embeddings themselves did not.
Multiple choice
2. Why can't Havenly's guest-preference embedding simply be handed to a new vendor?
A. It's illegal to transfer customer data between vendors.
B. An embedding is the model's own internal representation, meaningless to a different system without the original model.
C. Guests would have to consent again to any transfer.
D. Embeddings are too large to move over the internet.
Show hint
Look at the knowledge spark on embeddings.
Show answer
B. The embedding is a compressed internal encoding, close to unusable outside the vendor's own model.
True or false
3. True or false: in this story, Alder's corporate office is the group with the least ability to contest a bad Havenly renewal.
True
False
Show hint
Look at the Groups and Ability to Contest steps.
Show answer
False. Corporate signed the contract and has a seat at the table. The individual property, who never signed anything, has the least ability to contest.
Short answer, apply it yourself
4. Think of a subscription tool you use where switching would be painful. Whose data is actually trapped, and did that person or group ever get a say in the original contract?
Show hint
Ask who feels the switching cost, not just who pays the monthly bill.
Show answer
Model answer: Often the end user whose history or profile lives inside the tool, not the person or team who originally chose and paid for it.
Short answer, where it wouldn't matter
5. Name a part of the Havenly relationship where this lock-in caution genuinely doesn't need to apply.
Show hint
Look at "what I would leave alone."
Show answer
Model answer: Havenly's actual recommendation model and methods. Those are allowed to stay proprietary; only the raw guest facts behind them need an exit door.
Short answer, the number
6. If the migration cost had only reached 15,000 dollars by year four instead of 140,000, would the same reversal, contracting for raw-signal export, still be worth doing? Why or why not?
Show hint
Look at the bar chart and think about what makes a switching cost actually dangerous.
Show answer
Model answer: Yes, though with less urgency. The principle, that the party without a lever shouldn't be the one who pays the exit cost, holds at any dollar amount; it's just easier to ignore when the number looks small.
Before you close the answer
Why this works
Tests whether you'll name the specific person or group with no leverage, instead of describing lock-in as a generic contract risk that applies to "the company" as one undifferentiated actor.
Follow-up traps
"Isn't asking for raw-signal export just going to make vendors refuse to sell to you?" Response: a vendor confident in its own modeling has little reason to refuse, since the model itself, not the raw facts, is what actually gives it an edge.
"What if the switching cost is real but the property never actually wants to leave anyway?" Response: the point isn't forcing an exit, it's making sure the property isn't staying purely because leaving became impossible, which is a different and worse reason to stay.
If pressed
The cleanest fix in practice ties the raw-signal export requirement to a standard, human-readable schema (room preference, dietary flag, request history) agreed at contract signing, so "portable" doesn't quietly mean "portable into a format only Havenly's competitors happen to also use."
From U2xAI Academy
From answering questions to owning outcomes.
A live workshop where you ship a working AI agent, defend a launch decision, and walk away with a portfolio recruiters can't wave off, not just more questions to study.