saturday, september 5, 2026 · the day's ai, attributed published by trilot llc · wyoming
guide · running the business

How to depend on an AI vendor that might get acquired

Your best-fitting AI tools are built by small companies that get bought, so learn to read the exit before you make any of them load-bearing.

Published 2026-09-05 · Updated 2026-09-05 · Read 9 min · Reviewed by Rami Steitieh

Verified 2026-09-05 · Rami
on this page · 0 / 0 checked

The tools that fit a small business best are usually built by small companies. A team of 12 that has only ever built one thing will beat a suite at that one thing, and it will answer your support email the same afternoon. That is a good trade and most of the time you should take it. The part nobody prices in at signup is that a company like that is also the most attractive object on the market to a larger platform, and on the day it sells, the workflow you built around it becomes a line item in somebody else’s integration plan.

This guide is about the ordinary work that makes the weeks after that announcement boring instead of expensive. Almost none of it happens after the news breaks. It happens on a normal Tuesday months earlier, when you spend 40 minutes finding out what your own data looks like outside the tool that holds it. If you have a procurement function, a vendor risk questionnaire and someone who reads assignment clauses for a living, this is beneath you. It is written for the person who is the entire IT department, buying with their own money, running three or four tools that would each take a fortnight to replace.

The announcement tells you about the team, not about your account

Read a few of these announcements next to each other and the shape becomes obvious. Harvey, which sells AI tooling to professional service firms and asset managers, acquired Benchmark on 16 July 2026, and its own post says this was its third acquisition of 2026 [1]. The post names Benchmark’s co-founders, Alec Dunn and Connor Janson, and says they and their team will join Harvey’s product and engineering organisation [1]. The Hexus announcement of 21 January 2026 said the Hexus team, composed of former Google and X/Twitter engineers, would join Harvey’s San Francisco office but build for customers globally, and that the deal was an opportunity to accelerate Harvey’s work supporting in-house legal teams [2].

Now look for yourself in those posts. The Benchmark announcement is the more generous of the two: it says the companies are “working together on a thoughtful plan to support existing Benchmark customers with continuity of service as a top priority” [1]. That is a commitment to intent, not to a date, a price or a feature. The Hexus post identifies Hexus as an AI product demo company and says where its engineers will sit and what their arrival accelerates, and says nothing about what becomes of that product [2]. Neither omission is dishonest. An acquisition announcement is written for candidates, investors and journalists, and the answer for customers usually arrives later, by email, from a support address, once someone has worked it out internally.

So the first correction to make is to your own reading. When you see that your vendor has been bought, you have learned that the founders are staying and roughly what the buyer wants from the deal. You have not learned whether your plan survives renewal, whether the standalone product keeps a login page, or whether the integration you rely on is on anyone’s list. Those are separate questions with separate answers, and they arrive on a slower clock than the press coverage.

It is also worth knowing what makes your vendor a target rather than an acquirer, because that is mostly a funding question and it is visible from outside. Harvey said it added more than $100 million in net-new annual recurring revenue in the second quarter of 2026, and that it works with more than 125 asset-management firms [1]. Companies at that end of the market buy. Companies with 12 people, one excellent product and a Series A get bought. If your tool is in the second category, the question is not whether an acquisition is possible but what it would cost you if it happened next quarter.

The clauses that already decided this

You almost certainly agreed to this in advance. The standard drafting says two things. First, that the agreement itself can move to the buyer without asking you. Anthropic’s commercial terms put it plainly: “Neither party may assign its rights or delegate its obligations under these Terms without the other party’s prior written consent, except that Anthropic may assign its rights and delegate its obligations to an affiliate or as part of a sale of all or substantially all its business” [3]. Read the exception, not the rule. Your consent is required for your assignment and not for theirs.

Second, that your data is one of the assets in the deal. OpenAI’s privacy policy says that if it is involved in “strategic transactions, reorganization, bankruptcy, receivership, or transition of service to another provider”, personal data “may be disclosed in the diligence process with counterparties and others assisting with the Transaction and transferred to a successor or affiliate as part of that Transaction along with other assets” [4]. That sentence covers the diligence stage too, which is the period before any announcement, while the deal is still confidential.

The third clause is the one that does the actual damage, and it is not about acquisitions at all. It is the amendment clause. Anthropic’s terms say it “may update these Terms at any time, to be effective 30 days after the updates are posted by Anthropic or Customer otherwise receives Notice”, with changes required by law taking effect immediately [3]. Chain the two together and you have the mechanism: the agreement moves to the buyer, and then the buyer changes it on 30 days’ notice like anybody else would. Nothing improper has happened at any step.

Open your own vendor’s terms and search for the words assign, merger and modify. It takes four minutes and it tells you the worst legal case before you build anything on top. If a vendor’s terms are not public, treat that as the answer to a different question.

The exit drill you run on a normal Tuesday

An export you have never performed is a claim on a features page. Run it once, while nothing is wrong, and you convert it into a fact.

Do the export, then open the result somewhere else and look for what is missing. Notion will export a page as PDF, HTML, or Markdown and CSV, where “Full page databases will be exports as a CSV file, with Markdown files for each subpage” [6]. It also documents the friction: exporting an entire workspace to PDF requires a Business or Enterprise plan, including subpages in a PDF export requires the same, and exports “can take up to 30 hours to process, depending on the size of the workspace” [6]. None of that is unreasonable. It is just the difference between an export you can do this afternoon and one you start on Thursday for Friday.

Automation is the case where the export matters most, because the logic is the thing you would otherwise rebuild from memory. In n8n you download the current workflow as a JSON file from the three-dot menu, and workflows are stored in JSON [7]. Note the caveat in the same documentation: exported workflow JSON files include credential names and IDs, and n8n tells you to remove or anonymise that information before sharing the file [7]. So your exit kit needs somewhere to live that is not a shared drive or a support ticket.

If you handle personal data in the EU or the UK, there is a legal floor under all of this. Article 20 of the GDPR gives the data subject the right to receive personal data they provided to a controller in a structured, commonly used and machine-readable format and to transmit it to another controller, where the processing is based on consent or a contract and is carried out by automated means, and to have it sent directly between controllers where that is technically feasible [8]. It is a real backstop and a narrow one. It covers personal data you provided, not the workflow you designed, not your prompt library, and not the configuration that makes the tool useful.

What changes first, and what a good wind-down looks like

The order of change after an acquisition is fairly predictable. Pricing and packaging move first, because that is the easiest lever and usually the reason for the deal. Support changes next, and it changes in a way that is hard to complain about, because the founder who used to answer you is now managing a team inside a larger organisation. Integrations and the smaller edges of the product go later, when the roadmaps are merged. The standalone product surviving as a separate login is the last question to be answered, and often the one nobody says out loud until the decision is made.

For what a well-run end-of-life actually looks like, borrow the standard from a different part of the industry. Anthropic’s deprecation policy defines four states for a model, Active, Legacy, Deprecated and Retired, publishes a table of retirement dates, and commits to notifying customers with active deployments “providing at least 60 days’ notice before model retirement for publicly released models” [5]. It is blunt about the endpoint: requests to retired models fail [5]. Claude 3.7 Sonnet, for example, was retired on 19 February 2026 [5].

That is the shape to ask an acquirer for, in the same words. Named states, a published date, a minimum notice period and an explicit statement of what stops working. A vendor that can answer in that form has made the decision and is telling you. A vendor that answers with reassurance about commitment to customers has not made it yet, which is useful information as long as you read it correctly rather than as a promise.

What to ask, and when

Send one email in the first week, before the integration work starts and while somebody is still assigned to answering customers. Keep it to five questions and make each of them answerable with a date or a name.

Ask whether your contract is being assigned and to which legal entity, since that is the party your terms will be with. Ask whether your current price holds to the end of the term and what happens at renewal, and get the renewal date in the reply so it is in writing. Ask for the earliest date on which the standalone product could stop being available, and the minimum notice you would receive, which is the deprecation question in plain clothes. Ask who the new subprocessors are and where data is stored now, because that list is what your own clients will eventually ask you about. Ask whether export remains available in the current formats after any platform migration, which is the only one of the five you can verify yourself later.

If you get four straight answers and one hedge, that is a normal, healthy reply. If the entire reply is enthusiasm, put a reminder in your calendar for 60 days out and ask again, because the answers exist by then whether or not they have been published.

How much to keep in one small vendor

The sizing rule is simple and unpopular. The amount of your business you keep inside a tool should be proportional to how quickly you could leave it, not to how good it is. A well-loved tool with a clean export and no lock-in earns more of your workload than an equally good one that holds the only copy of your operating knowledge in a proprietary format.

Cost the switch before you deepen the dependency, because the subscription is never the expensive part. The expensive part is your own hours rebuilding logic, plus whatever the replacement costs above what you pay now, for as long as you would run it. Put your real numbers in and the answer usually falls between one and three months of the tool’s own annual price, which is either reassuring or the reason to keep the second option warm.

calculator
Cost of a forced switch
$

rebuild hours × your rate, plus the monthly price difference over the months you would run the replacement. Computed in the page; nothing is sent anywhere.

checklist
Before a small vendor becomes load-bearing
0 of 8 · saved in this browser only

What still goes wrong

Most acquisitions are fine for customers, and a fair number are an improvement. A team that was three people short suddenly has a security programme, an on-call rota and a legal department, and the product it was struggling to maintain gets funded. The caution in this guide costs you something real, which is depth. If you keep every tool at arm’s length so you can leave it in a weekend, you never get very good at any of them, and the operator who committed hard to one platform will beat you on speed for as long as the bet holds.

Nothing here predicts anything either. There is no reliable outside signal that says a specific company is 90 days from being bought, and the confident-sounding ones are mostly hindsight. Treat the drill as insurance with a known premium of about an hour a quarter, not as forecasting. It is the same hour whether or not the deal ever happens.

The uncomfortable limit is that an export is not a working system. You can hold a complete JSON copy of every automation and still lose a fortnight rebuilding them somewhere with different triggers and different rate limits. Portability of files is not portability of behaviour, and no clause or export button fixes that. The only thing that genuinely reduces it is keeping the description of what your business does in a form you own, in plain text, so that the next tool is being configured rather than reverse-engineered. The quieter risk is not acquisition at all. Small companies also just stop, without a buyer, with a shorter notice period and nobody to email, and every measure in this guide is the same measure for that case.

sources
  1. 01Harvey — Y Combinator-Backed Benchmark Joins Harveyharvey.ai
  2. 02Harvey — Hexus Joins Harvey Engineering Teamharvey.ai
  3. 03Anthropic — Commercial Terms of Serviceanthropic.com
  4. 04OpenAI — Privacy policyopenai.com
  5. 05Anthropic — Model deprecationsplatform.claude.com
  6. 06Notion — Export your contentnotion.com
  7. 07n8n — Export and import workflowsdocs.n8n.io
  8. 08GDPR Article 20 — Right to data portabilitygdpr-info.eu
next guide
How to buy AI security as a small business
9 min · verified 2026-09-04
related guides