When your vendor buys its AI features instead of building them
How to judge an AI feature that arrived through an acquisition, so you can tell what changed on your invoice, in your data path and in the product itself.
on this page · 0 / 0 checked
A button appeared in a tool you pay for. It says something like “ask”, or “agent”, or “summarise this for me”, and it was not there in the spring. The tool is one you already trust, so the button inherits that trust automatically. That is the part worth slowing down on, because there is a good chance the button is not your vendor’s work. It is a company your vendor bought, wired into the product over a few months, and shipped under the logo you already trusted.
This is now the default way AI capability arrives in business software. It matters to you for three ordinary reasons: the price of the feature will change, your data may take a different route than the rest of the product, and the thing is much newer than the brand above it. This guide is about how to check those three things quickly and what to do while you wait for an answer. It is written for a one-person business or a team under about twenty, buying its own software with its own money. If you have a procurement function, a security questionnaire and a legal team reading the master services agreement, you have a different process already and this is too small for you.
The AI feature in your toolbar was probably somebody else’s company
The pattern is easiest to see in security software, where the deals are public and close together. Palo Alto Networks announced on 1 September 2026 that it had acquired Console, an AI-native platform that lets a team express an operational goal and have software carry out the execution, and said it would fold those capabilities into Cortex, its security operations platform. Its chief executive said the deal would “deepen our agentic capabilities”. Financial terms were not disclosed [1]. A month earlier, on 30 July 2026, Okta announced an agreement to acquire Permiso Security, a cloud-native identity security platform covering human, non-human and AI agent identities, to extend Okta’s identity security fabric and its threat detection and response product. That deal closed on 26 August 2026, and its terms were not disclosed either [2]. Two days before the Okta announcement, on 28 July 2026, Cyera’s own newsroom carried reporting that it had agreed to buy Oasis Security in a deal valued at 1 billion dollars; on 3 August 2026 Cyera announced a product called Agent Guardian [3].
Three vendors with substantial engineering teams, three purchases of the same shape inside five weeks. You can read that as a market signal about how hard agent behaviour is to build well, and it probably is one. But the useful reading for a buyer is duller. In a fast category, buying beats building, so the feature you are being offered inside a mature product is frequently a young product wearing an older company’s name. The brand is ten years old. The feature is ten weeks old.
Nothing about that is dishonest, and the acquired team is often better at the specific job than the parent would have been. It just means the trust you extend to the product as a whole does not transfer cleanly to the newest part of it. The same thing happens further down the market, in the tools a solo operator actually runs, with no press release at all.
Three things change for you, and the feature is not one of them
The first is the bill. AI features usually arrive free, because adoption is what the vendor is buying, and then they get a meter. Notion is a clear, current example of the shape. The plans are 0 dollars for Free, 10 dollars per member per month for Plus and 20 dollars for Business, with up to 20 per cent off on annual billing. Its Custom Agents are free to try, then 10 dollars per 1,000 monthly Notion credits, and Workers are free to try now and start using credits on 15 October [8]. Read that as a template rather than a complaint. A per-seat price is predictable and a credit price is not, and a feature that is free during its first season is being priced for its second.
The second is the data path. An acquired product does not automatically share the parent’s storage, region, retention or permission model on day one, and the marketing page will not tell you which parts are shared yet. This is the question that decides whether you can put client material through the new feature.
The third is who answers when it breaks. A freshly acquired team has its own backlog, its own on-call rota and, for a while, its own support queue. That shows up as a slower answer on the exact day the new feature does something surprising with your data.
Your contract already says you can be handed to someone else
Read the assignment clause in whatever you accepted. Zapier’s terms, last updated 8 April 2026, are typical and unusually readable: neither party may assign the terms without the other’s consent, “except that either party may assign these Terms, with notice to the other party, in connection with the assigning party’s merger, reorganization, acquisition or other transfer of all or substantially all of its assets or voting securities, provided that the assignee agrees to be bound by these Terms” [4]. In plain terms, you get told, not asked. The one protection in that sentence is real and worth knowing: the buyer inherits the terms you signed.
The same logic runs through the privacy policies of the model vendors underneath your stack. Anthropic’s policy, effective 8 July 2026, says that if Anthropic “is involved in a merger, corporate transaction, bankruptcy, or other situation involving the transfer of business assets, Anthropic will receive or disclose your personal data as part of these corporate transactions” [5]. OpenAI’s rest-of-world policy, effective 6 February 2026, says that in a strategic transaction, reorganisation, bankruptcy, receivership or transition of service, your personal data may be disclosed during diligence and “transferred to a successor or affiliate as part of that Transaction along with other assets” [6]. Both statements sit alongside commitments not to sell your data, and both are compatible with those commitments. Data moving with the business is not a sale. It is the ordinary mechanics of company ownership, and it applies to every vendor you use, including the ones you like.
The practical consequence is small and specific. Do not choose a vendor on the assumption that its current owner will be its owner in two years. Choose on the assumption that the terms you signed are the floor of what you get.
The subprocessor list is where an acquisition shows up first
If you have a data processing agreement with a vendor, you are the controller and they are the processor, and the rule about who else touches your data is written down. Article 28(2) of the GDPR, in the text retained in UK law, says a processor “shall not engage another processor without prior specific or general written authorisation of the controller”, and that under a general authorisation the processor “shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes” [7]. Article 28(3)(g) requires the processor, at your choice, to delete or return all the personal data at the end of the service and delete existing copies unless the law requires storage [7].
Two things follow. First, the subprocessor page is the earliest honest signal you get. New infrastructure and newly acquired entities appear on that list before they appear in a product announcement, so find the vendor’s page, subscribe to its change notifications if it offers them, and read the emails you already ignore. Second, your objection right is only as strong as your willingness to leave, which is why the deletion-and-return clause matters more than it looks. It is the mechanism you use to get your material out in a usable state.
If you are a sole trader in a country with no equivalent rule, or you are on a self-serve consumer plan with no data processing agreement at all, you have none of this by right. You still have the vendor’s published list, and you should read it anyway.
Ask how deep the integration goes, in writing
Two systems under one product name behave differently from one system, and the difference is invisible from the outside. Ask the vendor, by email, so the answer exists in text: whether the feature uses the same login and the same permission model as the rest of the product, or its own; where the data it processes is stored and in which region; whether deleting a record in the main product removes it from the new feature as well; which subprocessors and which model providers the feature adds; and whether support for it goes to the same queue with the same response time.
Judge the reply by whether it is specific, not by whether it is reassuring. A one-line answer naming the storage region and the permission model is worth more than three paragraphs about a commitment to security. A vendor that cannot answer in a week is telling you the integration is still in progress, which is a real answer too and one you can act on. In the meantime, use the feature for work that would not hurt if it leaked, and keep the client material out of it.
Then set the feature’s authority deliberately. The rule that holds up across tools is that an agent may read anything you would show a temporary contractor, and may not do anything irreversible without you. Sending an email, deleting records, moving money, changing permissions and publishing are the irreversible ones. Give it a first quarter of read-only work and see whether the output is right before you let it act.
What leaving would cost, before you need to know
The reason to price your exit while you are happy is that you cannot price it calmly while you are angry. It is two numbers. The first is the work of getting out: export your data now, once, and time it, then look at what came back and estimate how long rebuilding it elsewhere would take. Exports that arrive as one flat file of text are a different proposition from exports that reload into another tool. The second is the price difference of the replacement over a year.
Note also what your provider destroys on the way out. Zapier’s terms state that once you delete your account, neither the account nor your customer content “can be restored or recovered in any way” [4]. Export before you cancel, not after.
hours to export and rebuild × your hourly rate, plus twelve months of the price difference. Computed in the page; nothing is sent anywhere.
If that number is small, you are free and you can adopt the new feature early and cheaply. If it is large, you are not really evaluating a feature, you are managing a dependency, and the sensible response is to keep one workflow you could move: the automation that matters most held in a tool you could rehost, such as n8n, or a copy of the source material kept outside the vendor. The point is not to leave. It is to be able to.
What still goes wrong
Most of this fails quietly at the vendor’s end. Small customers often get no answer to the integration questions, or get a marketing answer, and there is no lever that produces a better one when you are paying 20 dollars a month. The subprocessor mechanism assumes a data processing agreement you may not have, and the notice period assumes you are reading the notices. Both assumptions fail in ordinary weeks.
The diligence also cannot save you from the structure of the market. If every vendor in a category is buying its AI capability rather than building it, checking that yours did the same only tells you it is normal. You are choosing between differently assembled products, not between an assembled one and a hand-built one, and a switch made in protest usually lands you somewhere with the same pattern and a worse export.
And the acquired feature is often good. The team that sold itself into a bigger company usually did so because it had solved a genuinely hard problem, and refusing the feature on principle costs you the benefit while the risk stays roughly where it was. The honest position is narrower than a rule about acquisitions: treat any AI feature younger than about two quarters as unproven whatever its provenance, keep it away from actions you cannot undo, price your exit once a year, and spend the attention you save on the work.
- 01Palo Alto Networks — Palo Alto Networks Acquires Console to Agentify Securitypaloaltonetworks.com
- 02Okta — Okta signs definitive agreement to acquire Permiso Securityokta.com
- 03Cyera — Newsroomcyera.com
- 04Zapier — Terms of Servicezapier.com
- 05Anthropic — Privacy Policyanthropic.com
- 06OpenAI — Privacy policy (rest of world)openai.com
- 07legislation.gov.uk — GDPR Article 28, Processorlegislation.gov.uk
- 08Notion — Pricingnotion.com