Answer capsule
The CIO should define what data, models, interfaces, documentation, tests, and operating knowledge must remain usable after a vendor change before an AI contract is awarded—not when switching has already become cost-prohibitive.
What the source establishes
- OMB Memorandum M-25-22 directs U.S. federal agencies on efficient acquisition of AI and calls for clear requirements, cross-functional engagement, performance tracking, and risk management.
- The memorandum says solicitations should reflect an interest in reducing vendor lock-in through knowledge transfer, data and model portability, clear licensing, and pricing transparency.
- OMB points to well-defined APIs, development documentation, testing scripts and protocols, and transition-friendly practices as possible evaluation criteria.
- The memorandum applies to covered federal acquisition activity; it is not a private-sector architecture mandate, a product certification, or proof that a proposed migration will work.
Define the portable unit before comparing platforms
The direct CIO answer is to make portability a workload requirement before the request for proposal or contract renewal. Start with the business service and identify what would have to move if the provider, model, region, commercial terms, or risk decision changed. That unit can include source data, embeddings, prompts and system instructions, evaluation sets, fine-tuning artifacts, model or adapter rights, agent definitions, tool schemas, workflow state, audit records, policy configurations, user entitlements, integration code, and operating documentation. Saying that data can be exported is not an exit plan when the application depends on proprietary orchestration or an undocumented retrieval pipeline.
Classify each item as organization-owned, licensed, provider-owned, derived, reproducible, or unavailable. Record its format, volume, update frequency, dependency, sensitivity, and target environment. Then separate interoperability from substitution. An API may let two systems exchange information while leaving the customer unable to reproduce behavior elsewhere. Conversely, a portable dataset may still require extensive engineering, testing, security review, and business revalidation before another service can use it safely. The architecture decision needs both views.
The accountable team should translate this point into a named workflow, affected population, source data, human owner, approval right, exception path, retained evidence, and review date. That translation is what separates an interesting AI development from a decision that can be governed and evaluated.
Test the exit path while competitive leverage still exists
M-25-22 places lock-in protections in solicitation and contract design, where they can shape vendor commitments. A CIO can adapt that timing by requiring a small exit exercise before award. Export a representative data slice, configuration, evaluation record, logs, and documentation; rebuild or read them in a neutral environment; and measure what is missing. Ask the proposed provider to explain identity mapping, encryption keys, deletion, residual backups, support access, derived data, model dependencies, and the point at which service functionality ends.
The test should include a changed version and a failed dependency, not only a clean export. Confirm whether evaluation scripts still run, whether citations and audit links remain resolvable, and whether administrators can identify every integration that must be disabled. Set acceptance criteria for completeness, format, time, cost, and independent readability. A contractual promise to provide reasonable assistance is weaker than an observed transfer with named artifacts, owners, and limits. Preserve the evidence against the exact product tier and configuration reviewed.
The accountable team should translate this point into a named workflow, affected population, source data, human owner, approval right, exception path, retained evidence, and review date. That translation is what separates an interesting AI development from a decision that can be governed and evaluated.
Put switching cost beside subscription cost
Pricing transparency is useful only when the economic model includes dependency. Compare license and usage charges with data egress, retraining, re-indexing, interface replacement, testing, parallel operation, security review, user migration, records retention, vendor support, and business interruption. Include minimum commitments, bundled discounts, proprietary feature dependencies, subcontractors, and the operating knowledge that would have to be rebuilt. A low unit price can be expensive if it makes the next architecture choice impractical.
Do not turn the analysis into a universal preference for open source or multiple vendors. A managed proprietary service may be the better fit when its capability, reliability, support, or time-to-value outweighs a measured switching exposure. The decision record should show the conditions under which that trade is acceptable, the concentration threshold, and the evidence that could reverse it. Finance, procurement, legal, security, data, and the workload owner need the same dependency map so cost, rights, operational risk, and service value are not evaluated in separate documents.
The accountable team should translate this point into a named workflow, affected population, source data, human owner, approval right, exception path, retained evidence, and review date. That translation is what separates an interesting AI development from a decision that can be governed and evaluated.
Maintain portability as the workload changes
A passing pre-award test decays when a team adds proprietary tools, changes a model, expands data, adopts a provider-specific agent runtime, or lets documentation fall behind. Put portability triggers into change control. Material releases should identify new dependencies, rights, formats, evaluation requirements, and exit effects. Re-run a representative export and restoration on a risk-based schedule and before a major renewal. Track unresolved gaps, accepted exceptions, expiration dates, and the executive authorized to accept a constrained exit.
The federal memorandum is valuable here as a procurement pattern, not as authority over a private enterprise. The CIO remains responsible for translating it to the organization's workload, strategy, regulatory context, commercial leverage, and recovery objectives. A portable architecture is not one that can theoretically move someday; it is one whose critical artifacts, rights, knowledge, and tests are known well enough that leadership can make a credible stay, renegotiate, restrict, retire, or transition decision.
The accountable team should translate this point into a named workflow, affected population, source data, human owner, approval right, exception path, retained evidence, and review date. That translation is what separates an interesting AI development from a decision that can be governed and evaluated.
Decision test
Ask whether the source changes the decision itself, the evidence required, the implementation sequence, or only the language used to describe an existing capability. Record which claims are directly supported, which are provider statements, which require an independent test, and which remain unknown. A source-linked review should make uncertainty easier to see, not bury it inside a blended score.
Questions to take into review
- Which services are common and which remain workload-specific?
- How can a team change a model without rewriting the application?
- Who owns the data product and its semantic definitions?
- Which uses are allowed and prohibited?
- What is the unit of useful work?
- How does cost change with context, retrieval, tool calls, retries, and review?
- Which telemetry is missing or sampled?
- Can the model change production or only advise?
The publication supports research and executive decision preparation. It does not provide legal, financial, accounting, employment, clinical, cybersecurity, investment, procurement, or implementation advice.