Cloud Vendor Lock-In: What UK Boards Must Govern in 2026
Cloud vendor lock-in leaves enterprises trapped in costly, single-provider dependencies — and UK boards, the CMA, and regulators now treat it as a strategic governance priority that demands direct board attention.
What Is Cloud Vendor Lock-In and Why Does It Matter at Board Level?
Cloud vendor lock-in occurs when an organisation’s infrastructure, data, and applications become so deeply embedded in a single cloud ecosystem — AWS, Microsoft Azure, or Google Cloud — that switching becomes technically complex and commercially prohibitive. The barriers include proprietary APIs, data formats, egress costs, long-term discount contracts with exit penalties, and the significant retraining burden associated with migrating teams and workloads to a new platform.
AWS, Microsoft Azure, and Google Cloud together control approximately two-thirds of the global cloud infrastructure services market. According to research published by Civo in 2026, 73% of UK IT leaders now cite cloud sovereignty and geopolitical risk as a primary concern — a proportion that has increased markedly in recent years. For boards, the question is not whether to use hyperscale cloud providers — they offer unrivalled capability and scale — but whether strategic decisions are being made with full awareness of the dependencies being created and the cost of reversing them.
The Competition and Markets Authority (CMA) Cloud Services Market Study has already elevated this concern to the highest regulatory level. The CMA found that technical barriers to switching significantly reduce market participants’ willingness to change providers or adopt multi-cloud strategies — a finding with direct implications for enterprise boards responsible for competitive resilience and third-party risk.
Executive Action
- Commission a cloud concentration audit mapping infrastructure, data storage, and application dependencies across all providers.
- Request a board-level briefing on contractual lock-in — including discount structures, exit clauses, and data egress cost exposure.
- Include cloud concentration risk in your annual technology risk register with explicit risk appetite statements.
How Are UK Regulators Responding to Cloud Concentration Risk?
Regulatory scrutiny of cloud concentration is intensifying across multiple UK bodies. The CMA’s Cloud Services Market Study identified that the dominance of three providers creates systemic risks for enterprise customers and national resilience. The CMA has engaged major cloud providers on commitments to improve switching and interoperability, but the pace of change has been incremental — leaving enterprise boards to manage the risk in the interim.
For regulated industries, the implications are more immediate. The Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA) have incorporated cloud concentration risk into their operational resilience frameworks. Under FCA operational resilience rules, financial services firms must demonstrate that third-party dependencies — including concentration in a single cloud provider — are identified, their impact on important business services understood, and credible exit strategies documented and tested.
Beyond financial services, the Product Security and Telecommunications Infrastructure Act 2022 and the Network and Information Systems Regulations 2018 (NIS Regulations 2018) already extend similar obligations to critical national infrastructure sectors including energy, telecommunications, and health. The NIS Regulations are currently being updated to NIS2, which will further strengthen these requirements. Boards in these sectors should treat cloud dependency governance as a pre-requisite for resilience compliance, not an optional enhancement.
Executive Action
- Confirm that cloud exit strategies are documented, tested, and proportionate to your organisation’s recovery time and recovery point objectives.
- Brief your board on the CMA’s cloud market findings and assess whether your concentration risk would withstand FCA or PRA scrutiny.
- Engage your General Counsel on whether current cloud contracts include interoperability and data portability rights aligned with regulatory expectations.
What Is the Commercial and Strategic Cost of Staying Locked In?
Over-reliance on a single cloud provider carries significant commercial consequences beyond regulatory risk. Enterprises deeply embedded in one ecosystem lose negotiating leverage on pricing, face punitive data egress costs when replicating or migrating workloads, and find themselves constrained in adopting best-of-breed solutions from competing platforms. Innovation velocity can also slow, as product and technology decisions become shaped by what a single provider offers rather than what is strategically optimal for the business.
Geopolitical instability adds a further dimension. According to Civo’s 2026 research, 77% of UK IT leaders are concerned about their data infrastructure’s exposure to geopolitical risk. US-China tensions, European data sovereignty requirements, and post-Brexit trade dynamics all create scenarios in which the terms and continuity of access to hyperscale cloud infrastructure can shift — potentially with limited notice. Boards should treat geopolitical cloud risk as a live operational concern, not a theoretical scenario.
Executive Action
- Mandate that all new major cloud procurement decisions include a multi-cloud or cloud-neutral architecture assessment before commitment.
- Ensure business continuity plans address credible scenarios where the primary cloud provider experiences prolonged service disruption.
- Review whether AI and data workloads being migrated to cloud are creating new concentration risks not captured in existing assessments.
How Should UK Boards Govern Cloud Strategy Without Overreaching into Operations?
Effective cloud governance at board level is not about approving architecture decisions — that is rightly the domain of the CTO and CIO. It is about ensuring the right questions are asked, the right reporting is in place, and that technology strategy aligns with the board’s risk appetite and long-term objectives.
Boards that govern cloud risk effectively share three characteristics. First, they receive structured reporting on cloud spend and provider concentration — including the proportion of workloads and data held with each provider and the trend over time. Second, they actively require technology leadership to articulate a cloud strategy that includes explicit consideration of multi-cloud and cloud-neutral architectures. Third, they ensure that procurement governance frameworks require lock-in risk to be assessed and documented before major cloud commitments are approved at board or executive level.
According to the Flexera State of the Cloud Report, 89% of large enterprises now operate a multi-cloud strategy — and nearly all expect to expand it. The rationale is compelling: distributing workloads across providers reduces dependency risk, supports data sovereignty requirements, improves pricing leverage with providers, and builds resilience against single-provider outages or geopolitical disruption. For UK boards yet to adopt this posture formally, 2026 is the year to act.
The INFORMD technology risk assessments and executive briefing library offer practical frameworks for evaluating your board’s technology governance posture, including cloud dependency and third-party concentration risk.
Executive Action
- Add cloud strategy governance to the annual board technology review agenda, with specific metrics on provider concentration and switching readiness.
- Require technology leadership to present a multi-cloud roadmap alongside the current cloud strategy at the next board technology session.
- Consider whether your board has sufficient technology expertise to evaluate cloud risk independently — and whether a technology committee or digital NED would strengthen oversight.
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library or access our free assessment tools.
Frequently Asked Questions
What is cloud vendor lock-in?
Cloud vendor lock-in occurs when an organisation becomes so dependent on a single provider’s proprietary services, APIs, and tools that switching becomes prohibitively costly or complex. It restricts strategic flexibility, reduces negotiating leverage, and creates resilience risks that UK boards are increasingly required to address under FCA, PRA, and emerging Cyber Resilience Bill obligations.
Why is the CMA concerned about cloud concentration in the UK?
The CMA’s Cloud Services Market Study found that AWS, Microsoft, and Google control approximately two-thirds of the global cloud market and that technical switching barriers are deterring competition. The CMA views this concentration as a risk to enterprise competitiveness and national resilience, and has engaged providers on interoperability and data portability commitments.
What is a multi-cloud strategy and should every UK enterprise adopt one?
A multi-cloud strategy distributes workloads, data,
