If switching model providers requires code changes, if audit data lives only in a vendor UI, or if prompt updates need redeployments, the architecture has become difficult to replace. Those are governance signals as much as engineering signals because they reveal where control has been absorbed into proprietary layers.
Why This Matters for Security Teams
Hidden lock-in is rarely announced as a product feature. It shows up when security controls, audit evidence, and operational knowledge become trapped inside one AI platform’s proprietary workflows. For teams managing models, prompts, agents, and secrets, that matters because replaceability is a governance property: if controls cannot move with the workload, the platform has absorbed risk ownership.
This is why signals like vendor-only audit trails, non-portable prompt logic, and provider-specific integrations should be treated as architecture warnings. NHI governance is especially exposed here because identity, secrets, and authorisation are often embedded into platform defaults rather than held as separable control layers. NIST’s SP 800-53 Rev 5 Security and Privacy Controls remains useful as a baseline for assessing whether records, access, and accountability can be enforced independently of a single interface.
NHIMG research on the Ultimate Guide to NHIs underscores that control-plane sprawl is usually where portability erodes first, long before a formal exit becomes necessary. In practice, many security teams encounter lock-in only after audit requests, incident response, or provider changes make the dependency impossible to ignore.
How It Works in Practice
The clearest signals appear where the platform owns both execution and evidence. If prompts, policies, evaluation logs, and approval history are only available through one UI, the team cannot independently validate decisions or export a clean control history. If the model provider changes, but every prompt template, tool binding, and routing rule must be rewritten, portability has already been lost.
Practitioners should look for these conditions:
- Model switching requires application code changes instead of a provider-agnostic interface.
- Audit logs are visible only in a vendor console and cannot be exported in usable form.
- Tool access is bound to platform-specific secrets or identity wrappers.
- Prompt edits require redeployment, which makes policy updates slow and risky.
- Evaluation and safety settings cannot be versioned outside the vendor stack.
That pattern matters because it turns governance into a subscription feature rather than an organisational control. A more resilient design keeps workload identity, secret issuance, policy evaluation, and logging under the team’s own control plane, even if the platform provides the model runtime. Emerging practice is to separate the policy decision point from the model provider and to treat credentials as short-lived, task-scoped artefacts instead of embedded configuration. This is consistent with the direction of the McKinsey AI platform breach, where platform-layer dependence amplified the blast radius of control failures, and with NIST AI Risk Management Framework guidance that stresses governable, testable AI processes.
These controls tend to break down when the platform bundles identity, orchestration, and logging into a single managed service because the organisation loses independent verification and exit leverage.
Common Variations and Edge Cases
Tighter integration often improves developer speed, requiring organisations to balance convenience against future control loss. The tradeoff is real: a fully portable stack can feel slower at build time, but it reduces the cost of audits, provider changes, and incident containment later.
Some lock-in is obvious, but the harder cases involve soft dependencies. For example, a team may still export data, yet the exported logs are missing enough context to reconstruct who approved an action, which prompt version ran, or which tool chain was invoked. Best practice is evolving here, and there is no universal standard for this yet, but current guidance suggests treating exportability, replayability, and evidence completeness as first-class requirements rather than nice-to-haves.
Another edge case is multi-provider abstraction that looks portable while hiding deeper dependency in safety filters, proprietary embeddings, or vendor-specific policy languages. The DeepSeek breach is a reminder that operational secrecy and control quality can fail together when the platform itself becomes the control boundary. For teams assessing risk, the question is not whether a platform has integrations, but whether the organisation can still enforce policy, preserve evidence, and rotate control without platform consent.
When prompt governance, identity binding, and audit retention all depend on proprietary primitives, the platform may still be usable, but it is no longer easy to leave.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Hidden lock-in often starts with opaque secrets and identity bindings. |
| OWASP Agentic AI Top 10 | LLM-03 | Prompt and tool governance can become vendor-locked in agent platforms. |
| CSA MAESTRO | TRUST-02 | Vendor-bound audit and policy layers reduce trust boundaries. |
| NIST AI RMF | AI RMF addresses governable, testable AI processes and accountability. | |
| NIST CSF 2.0 | PR.AC-4 | Access and accountability controls should not depend on one vendor UI. |
Map every model and agent dependency to portable NHI controls before adopting vendor-specific identity wrappers.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org