Osmos Global Publication · Osmos Perspective
Procure AI With an Exit Route
A technology agreement should preserve the ability to change suppliers without losing operational knowledge.

The switching cost is not just the licence
An AI-enabled building platform can accumulate asset mappings, validated faults, operator feedback, configuration and workflow history. These records may become more valuable than the interface itself. If they cannot be recovered or interpreted at contract end, the buyer risks losing operational knowledge along with software access.
NIST’s incident-response guidance includes supplier responsibilities and lifecycle considerations [NIST]. Hong and Li highlight the documentation needed to understand and reproduce building-AI work [HONG]. Neither is a substitute for a contract. Together they support making knowledge continuity a procurement requirement.
Define what the organisation needs to retain
Specify the data, metadata, configuration and history required to continue the service. Distinguish the buyer’s records from supplier intellectual property. The organisation may not need ownership of a proprietary model, but it may need usable data exports, model-version history and an explanation of decision-relevant outputs.
Clarify access during transition. A right to receive data after termination is weak if operational access ends before the next provider can validate it. The contract should define the transition period, support responsibilities and commercial treatment, with legal advisers resolving the applicable terms.
Figure 1. Choose the authority boundary explicitly Original Osmos Global conceptual framework, 2026. Categories are not a maturity score. Prepared 1 September 2026.
What this means: More accurate predictions do not automatically justify more control authority.
Expose hidden dependencies
List cloud services, integrations, specialist subcontractors and proprietary point mappings. Ask what happens if one dependency changes price, becomes unavailable or is replaced. A supplier’s assurance that it can manage everything is not equivalent to a tested continuity arrangement.
Review model updates as a lifecycle issue. Changes can alter outputs, evaluation results or workflow behaviour. Agree how material updates are notified, tested and accepted, and whether the buyer can retain a supported version while resolving a problem. Avoid treating all software updates as operationally neutral.
Make exit a rehearsal, not a promise
During implementation, export a bounded dataset and ask an independent internal team to interpret it.
Verify identifiers, timestamps, units, relationships and quality flags. Try to reconstruct a completed operational event from detection through action and verification. The test reveals gaps while the supplier still has a clear obligation to fix them.
The same exercise can support incident recovery. If the organisation cannot understand its own exported history, it may struggle to investigate a failure or challenge a disputed benefit claim. Portability is therefore part of assurance as well as commercial leverage.
Illustrative decision rehearsal
An illustrative supplier transition reveals that historical alerts can be exported, but the reasons engineers accepted or rejected them cannot. The incoming provider receives events without the knowledge that made them useful. It may reopen resolved issues, repeat false alarms or lose the basis for earlier decisions. The gap is informational, not simply a file-format problem.
Define a representative transition record before signing. It should include the asset identity, supporting evidence, decision, action and verification status, with relevant timestamps and ownership. Ask the supplier to show how those elements are retrieved together. If some proprietary interpretation cannot be transferred, record the limitation and its operational consequence.
The first commercial review should examine whether the agreed export remains usable after software updates and additional integrations. Portability tested only at initial deployment can degrade as the system becomes more customised. Assign an owner to maintain the exit plan alongside the service plan.
Finally, separate continuity requirements from negotiating ambition. Demands that are impossible to fulfil or unrelated to the service can delay procurement without protecting the organisation. Focus on the knowledge, access and transition support needed to maintain safe operations and evaluate prior claims. A practical, tested exit route often strengthens the ongoing partnership because both sides understand which information the customer must be able to rely on independently.
Balance openness with realistic protection
The aim is not to demand every proprietary component or eliminate legitimate supplier rights. It is to preserve enough continuity, transparency and control to manage the service responsibly. Requirements should be proportionate to criticality and reviewed by procurement, operations, IT and legal specialists.
Osmos proposes that no decision-critical platform reach final acceptance until its exit route has been demonstrated. This is a recommendation, not an established legal rule. A good agreement makes both collaboration and separation workable, protecting the building’s operating knowledge when commercial relationships change.
Source notes
[NIST] Alexander Nelson, Sanjay Rekhi, Murugiah Souppaya and Karen Scarfone. Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile. National Institute of Standards and Technology, 2025-04-03. Section 2; Table 2 GV.SC-05/08; Table 3 RC.RP. DOI: 10.6028/NIST.SP.800-61r3. Accessed 1 September 2026.
https://csrc.nist.gov/pubs/sp/800/61/r3/final
[HONG] Tianzhen Hong and Han Li. Good practices for documenting AI-based studies on energy and buildings. Energy & Buildings / Elsevier; author copy hosted by Lawrence Berkeley National Laboratory, 2026-01-20. Sections 2, 3.1–3.6 and 4; pp. 1–4. DOI: 10.1016/j.enbuild.2026.117043. Accessed 1 September 2026. https://eta-publications.lbl.gov/sites/default/files/2026-06/1-s2.0-s0378778826001039-main.pdf
Editorial and visual note
This is original Osmos Global analysis informed by the cited publications. Reported findings are distinguished from Osmos recommendations and illustrative scenarios. Source findings and trademarks remain attributable to their owners. Original visual designs do not imply endorsement by source organisations. The content is general research and does not replace site-specific professional advice.
Cite this
Osmos Global Research & Knowledge Centre (2026). Procure AI With an Exit Route. Osmos Perspective, Osmos Global. https://www.osmosglobal.org/articles/procure-ai-with-an-exit-route
Keep reading

Smart-Building Pilots Need an Operating Owner
An experiment becomes useful only when someone owns the decision it is meant to improve.
1 Sept 2026 · Osmos Global Research & Knowledge Centre · 5 min read

An Alert Is Not a Maintenance Outcome
Analytics creates value through verified correction, not the number of faults displayed.
1 Sept 2026 · Osmos Global Research & Knowledge Centre · 5 min read

Sensor Coverage Is Not Data Quality
Connected points need identities, context and a known level of trust before they can support decisions.
1 Sept 2026 · Osmos Global Research & Knowledge Centre · 5 min read
Download this paper
The full PDF, formatted for circulation. Downloads are for members, so that we know who our research reaches.
Discussion
Add what you are seeing on the ground.
