Martin Dippenaar, chief executive of Global Kinetic, told TechCentral that many South African boards are moving toward an unsustainable reliance on public large language models (LLMs, AI systems that generate text from prompts). The warning matters most to chief information officers, chief financial officers and board members of large enterprises that are already budgeting for AI tools.
According to Dippenaar, the immediate financial impact can be dramatic. His company pays roughly US$600 per month for 30 licences. If the most active AI developer’s usage is multiplied across an organisation, the bill could climb to around US$10 000 per month. The cost escalation is not only about the headline price; it also hides hidden fees. When a user starts a new chat, the interface may automatically switch to a higher-end model that consumes tokens faster, and the session cannot be downgraded without restarting, leading to unexpected spend.
Beyond the wallet, the strategic risk is described as a new form of platform lock-in. Public AI providers such as Microsoft, Amazon Web Services (AWS) and Google Cloud are encouraging customers to feed proprietary data, rate cards, proposals, governance documents and historic project files, into retrieval-augmented generation (RAG) pipelines. Once that knowledge base is embedded, the AI system answers questions in the language of the business itself. Moving that knowledge to another provider would require rebuilding the entire substrate, a process more akin to re-platforming than a simple software swap.
The concern is not hypothetical. In June 2026, the US Bureau of Industry and Security issued a letter under the Export Control Reform Act that temporarily barred foreign nationals from accessing Anthropic’s Claude models. Anthropic responded by disabling the models for all customers worldwide, including those in South Africa, without prior notice. The restriction was lifted after three weeks, but the episode showed how a single regulatory decision can shut down a critical workflow overnight.
For South African companies, the geographic location of data centres does not solve the problem. Azure, AWS and Google Cloud now offer South African regions, but the controlling government can still order a model to be switched off, altered or withdrawn regardless of where the data physically resides. This creates a security and control risk that many boards have not yet quantified.
Industry analysts at the BCG Institute warned in a June 2026 report that the United States and China are diverging into incompatible AI stacks, narrowing the window for mixed-technology solutions. While the report focuses on global dynamics, the implication for local enterprises is clear: the ability to mix and match models from different superpowers may disappear quickly.
What can boards do? Dippenaar suggests a hybrid approach: keep sensitive workloads on an internal layer built from open-weight models that can be fine-tuned and run on owned infrastructure, while using public frontier models for exploratory tasks. This balances innovation with a safeguard against sudden loss of service.
Boards that ignore these signals risk turning AI into a “money furnace” and a single point of failure. The prudent step is to map current AI dependencies, model cost trajectories and develop a migration path that includes an alternative, either another public provider or an internal solution.
For further guidance on assessing AI governance risks, see our Tech & Telco resources and consider using the compliance-document-generator tool to draft AI policy frameworks.
Where South African data actually sits
Microsoft Azure, Amazon Web Services and Google Cloud have each opened data centre regions in South Africa over the past several years specifically to let local firms store data within the country’s borders for POPIA compliance purposes. What that regional presence does not change, as Dippenaar’s warning highlights, is which government has jurisdiction over the company operating the servers: a US export-control order applies to a US-headquartered AI provider’s models regardless of whether the underlying infrastructure sits in Cape Town or Virginia, which is the gap between data residency and genuine platform independence that South African boards are being urged to plan for.


