Systems · Exit · Dependence
The Cost of Exit
Why Leaving a System Is Harder Than Entering One
On 29 August 2024, shortly before six in the evening, AT&T filed a complaint in New York.
The immediate dispute concerned software support. The consequences described in the filing extended far beyond it.
Across the company, thousands of VMware systems were still running. Most customers would never know they were there. Calls continued to connect, data continued to move and critical services operated as they had the day before.
Support was due to end on 8 September.
AT&T believed its contract allowed two further annual extensions. Broadcom, which had completed its acquisition of VMware less than a year earlier, disagreed. The companies continued to negotiate, but the date remained unchanged.
AT&T had already considered moving to another platform. The existence of an alternative was not in dispute.
Time was.
Nine days separated the filing from the end of support.
In court, the company argued that an abrupt interruption could place critical systems at risk and cause harm that money alone could not later repair. Broadcom rejected AT&T's interpretation of the contract and said the company had long intended to move away from VMware.
The disagreement was eventually settled.
Until then, AT&T was asking for something narrower than permanence. It wanted the existing system to remain supportable while it prepared to live without it.
Its network was still operating. Engineers remained at their posts, and the infrastructure had not visibly changed.
Only the approaching deadline revealed how much continuity rested on a relationship the company was already trying to leave.
The most powerful systems are not always those that attract the greatest number of participants. They are those around which participation becomes progressively easier to maintain and progressively harder to unwind.
Entry is visible. Contracts are signed, platforms adopted, networks joined. The decision is discrete, bounded and often celebrated.
Exit is different. It is distributed across time, infrastructure and decisions made long after the original agreement was signed. A system is rarely left in the same condition in which it was entered. By then, the participant has changed around it.
This essay introduces a concept for understanding that condition: Exit Architecture.
Exit Architecture is the structure of legal, technical, contractual and operational dependencies that determines whether withdrawal from a system remains practical. It does not prohibit departure. It changes the conditions under which departure can occur until remaining becomes the path of least disruption.
I. Exit Is a Process
Entering a system can happen quickly.
A company selects a platform. A bank joins a network. An airline orders an aircraft. The cost is calculated, the contract approved and the implementation scheduled.
What follows receives less attention.
Procedures begin to reflect the system's logic. Employees learn its interfaces. Investments are calibrated to its requirements. Other technologies are connected to it. Compliance processes assume its continued presence. Over time, the original choice becomes embedded in hundreds of later decisions that were never individually understood as decisions to remain.
Each adaptation is rational.
Together, they alter the meaning of departure.
The VMware environment AT&T sought to leave was not simply software installed on a collection of servers. It had become part of the operational layer through which other systems were maintained. Security controls, monitoring procedures, recovery plans and institutional knowledge had developed around it. Replacing the platform was possible, but replacement alone was not the task. The surrounding environment would also have to be reconstructed while the existing network continued to operate.
This is why exit cannot be understood as the reversal of entry.
Entry requires a decision.
Exit requires coordination.
The organisation must preserve continuity while dismantling the conditions that produced it. Existing systems remain accountable to customers, regulators and markets even as their foundations are being replaced. Staff must operate the old environment while learning the new one. Risks cannot be suspended during the transition. In many cases, the participant must finance both systems at once.
The alternative may be available. The capacity to reach it safely may not be.
This distinction matters because formal freedom can conceal practical dependence. An organisation may retain the legal right to leave while lacking the time, institutional readiness or operational margin required to exercise that right without serious disruption.
The cost of entry is normally visible. It is negotiated, budgeted and approved.
The cost of exit accumulates elsewhere: in every additional integration, every specialised process and every decision whose value depends on the system remaining in place.
By the time departure is considered, much of that cost has already been incurred.
II. Systems Accumulate Around Themselves
A system becomes difficult to leave not only because of what it provides, but because of what gathers around it.
The international financial network offers a clear example.
A bank that joins SWIFT gains access to a common language for communicating payment instructions with institutions across the world. The value does not lie solely in the technology. It lies in the number of counterparties using it, the compliance procedures built around it and the expectation that messages sent through the network will be recognised and processed.
A bank can communicate outside SWIFT. Alternative systems exist.
What cannot be replicated immediately is the surrounding network of institutional acceptance.
The difference becomes visible when a bank is disconnected. Its accounts may remain open. Its staff may continue to work. Its domestic systems may still function. Yet its ability to participate in ordinary international finance is reduced because counterparties, controls and settlement procedures were organised around a network it can no longer reach in the same way.
The system does not need to prevent departure. Its reach has already shaped the environment beyond it.
Commercial aviation follows a similar logic.
When an airline selects an aircraft family, it does more than acquire aircraft. Pilots are trained for a particular type. Maintenance teams receive specialised certifications. Spare parts are stocked. Simulators are purchased. Operating procedures are approved. Route planning, insurance and technical records are organised around the fleet.
Another manufacturer may offer an aircraft with comparable range and capacity. That does not make the transition simple.
The airline must introduce the new fleet while continuing to operate the existing one. Crews require new qualifications. Maintenance facilities must be adapted. Parts inventories change. Regulatory approvals must be obtained without interrupting scheduled service.
The choice remains open, but it is no longer isolated. Years of accumulated decisions move with it.
Digital infrastructure makes the pattern more visible still.
A company may begin with a limited cloud contract and gradually build applications around proprietary databases, identity systems, security services and deployment tools. Each feature improves performance or reduces immediate complexity. Each also makes the application less independent of the environment in which it was created.
The data may remain portable in principle. The architecture that gives the data operational meaning may not.
No single decision creates the dependence. It emerges from use.
This is what gives Exit Architecture its force. A system becomes harder to leave through the same process that makes it more valuable. Integration improves efficiency. Familiarity reduces friction. Standardisation lowers the cost of continued participation.
The benefits are real.
So is the structure they create.
The more completely an organisation adapts to a system, the less likely it is to possess a ready alternative outside it. Remaining becomes easier because the institution has learned to operate within the existing architecture. Leaving becomes harder because the knowledge, procedures and expectations required for another architecture have not been built.
Dependence, in this sense, is not necessarily imposed.
It is accumulated.
III. When Exit Becomes Power
Exit Architecture is broader than a contractual penalty or the direct cost of changing suppliers.
It includes the time required to migrate, the risk carried during transition, the knowledge embedded in current operations and the institutional approvals tied to the existing arrangement. It includes systems that were never purchased from the same provider but were nevertheless built on the assumption that the provider would remain.
These conditions often emerge without a deliberate plan to constrain the participant. A platform may become difficult to leave because it is widely adopted, deeply integrated and operationally effective. A network may acquire power because the world beyond it has adapted to its presence.
But once the architecture exists, it can shape bargaining power.
A supplier negotiating with a customer that can leave within weeks faces a different relationship from one whose customer requires years to migrate. A network that can be replaced without disrupting counterparties possesses less strategic importance than one around which an entire institutional environment has formed.
The relevant question is no longer whether departure is legally permitted.
It is whether the participant can absorb the transition.
This is where Exit Architecture becomes a form of power.
The organisation controlling a critical system does not need to deny access outright. It may alter pricing, support terms, technical conditions or contractual structures knowing that its customers cannot respond at the speed of the change. The participant can resist. It can litigate. It can begin building an alternative.
But it must continue operating while it does so.
Power lies in that interval.
It lies in the distance between deciding to leave and becoming capable of leaving.
The greater the distance, the stronger the position of the system already in place.
This does not mean that every deeply integrated system is exploitative. Nor does it mean that integration should always be avoided. Modern economies depend on shared networks, specialised suppliers and common standards. No complex organisation can reproduce every capability internally.
The strategic failure lies elsewhere.
It occurs when the benefits of participation are measured precisely while the conditions of withdrawal remain unexamined.
A contract may specify the cost of entry, the annual price of operation and the obligations of both parties. It rarely captures the full cost of reconstructing the organisation outside the system. That cost appears only when the relationship deteriorates, the terms change or external circumstances make departure necessary.
By then, the architecture is already in place.
IV. Sovereignty and the Capacity to Leave
At the level of states, the implications become more consequential.
A country that adopts a defence platform does not simply buy aircraft, radar or communications equipment. It enters a long-term structure of training, maintenance, software updates, spare parts and interoperability. National capability becomes connected to external supply chains and technical permissions that may extend far beyond the original purchase.
Changing platforms is possible.
It may also take a generation.
During that transition, the state must preserve readiness, retrain personnel, rebuild support infrastructure and maintain compatibility with allies. The existence of another supplier does not eliminate the risks of reaching it.
Financial systems create comparable conditions. Currency arrangements, payment networks and trade structures provide scale and stability, but they also shape the institutions that participate in them. Businesses price contracts accordingly. Banks adapt their balance sheets. Regulators develop procedures around the prevailing framework.
Leaving does not restore the conditions that existed before entry.
It requires the creation of new ones.
The same problem appears in energy, semiconductor supply chains, cloud infrastructure and industrial standards. Alternatives may be visible on paper while remaining inaccessible at the speed required by a crisis.
This is why strategic autonomy cannot be measured only by ownership.
A state may own its infrastructure and still depend on external maintenance, software, standards or specialised components. It may possess legal authority over its institutions while lacking the operational capacity to move them away from the systems on which they rely.
Sovereignty therefore includes more than the freedom to enter.
It includes the capacity to leave without producing damage greater than the dependence itself.
That capacity cannot be improvised at the moment of rupture. It must be built beforehand through redundancy, interoperability, institutional knowledge and credible alternatives that exist not only in theory but in operation.
The objective is not complete independence. For most modern states and organisations, that would be economically destructive and strategically unrealistic.
The objective is to preserve choice.
Choice exists only when an alternative can be reached.
Conclusion
The threatened interruption did not occur. Support continued while the parties negotiated, and the dispute later ended in a confidential settlement. The network continued to operate. The immediate crisis passed without the failures described in the complaint.
The episode was therefore easy to overlook.
It appeared to be a narrow disagreement over contractual language, renewal rights and software support. Yet its significance lay in the contradiction at its centre. AT&T was preparing to leave VMware while asking a court to preserve the relationship long enough for departure to remain safe.
The company possessed the servers, employed the engineers and controlled the network. It also had the financial and technical capacity to build another environment.
What it did not possess was the ability to compress the transition into nine days.
That limitation had not been created in August 2024. It had accumulated across years of integrations, procedures and decisions made while the system was working as intended.
This is the deeper structure of departure.
Entering a system is an event. Leaving one is a campaign. It requires time, capital, expertise and institutional will. It must be conducted while the organisation continues to serve customers, satisfy regulators and protect the operations it is trying to move.
The most powerful systems do not always need to prevent departure. Their position is secured by the distance between the decision to leave and the capacity to complete it.
On the evening AT&T filed its complaint, the network had not changed. Calls continued to connect. Engineers remained at their posts. Nothing visible indicated that the company's control had weakened.
Only the deadline did.
It revealed that the relationship AT&T intended to end was still necessary to make the ending possible.
That is the cost of exit.
It begins long before anyone decides to leave.
— Curated Sovereignty
Selected Sources
AT&T and Broadcom
AT&T Services, Inc. v. Broadcom Inc. and VMware, Inc. Complaint, Supreme Court of the State of New York, New York County, filed 29 August 2024.
Reuters
"AT&T Sues Broadcom Over VMware Support Dispute." 2024.
The Register
"AT&T Sues Broadcom Over VMware Support Contract." 2024.
International Financial Networks
Society for Worldwide Interbank Financial Telecommunication. SWIFT and Sanctions.
Commercial Aviation
International Civil Aviation Organization. Annex 6 — Operation of Aircraft. · Airbus. A320 Family: Aircraft Characteristics — Airport and Maintenance Planning. 2023. · Boeing. 737 Airplane Characteristics for Airport Planning. 2023.
Author's Note
Questions for Future Research
1. Can Exit Architecture be measured? — Which indicators would capture the time, cost and operational risk of withdrawing from a system?
2. How does Exit Architecture interact with market power? — When does integration become a structural barrier to competition?
3. At what point should regulators treat exit conditions as seriously as entry conditions?
4. Can a state's exposure to Exit Architecture be assessed across defence, energy, finance, technology and critical infrastructure?
5. Under what conditions do open standards, interoperability and data portability materially reduce the cost of departure?
6. Can systems be deliberately designed with low Exit Architecture while preserving the efficiencies created by integration?
Concept Introduced
Exit Architecture — The legal, technical, contractual and operational conditions that determine the cost, time and feasibility of withdrawing from a system. Exit Architecture does not necessarily prohibit departure. It shapes the conditions under which departure can occur, often making continued participation easier than the construction of a viable alternative.
Curated Sovereignty examines strategic questions whose answers are still emerging.