Home > Journals > AIS Journals > MISQE > Vol. 25 (2026) > Iss. 3
Abstract
CIOs consistently report that software vendors are dramatically increasing license costs while reducing negotiation flexibility. Increased prices result from the erosion of digital sovereignty, limiting an organization’s ability to control its digital infrastructures. Our research reveals how vendors leverage the “triple bind” (lock-in, bundling and scaling) to create insurmountable dependencies, which will likely intensify further in the AI era. This leaves enterprises with little room to negotiate or exit. Though there is no silver bullet, we recommend four strategies that CIOs can adopt to regain control.
Executive Briefing
THE KEY PROBLEM
- Dominant software vendors are raising license costs by 5% to 20% a year while giving enterprises less and less room to negotiate. CIOs report the increases as unavoidable, and few have a credible way to push back.
- Rising prices are a symptom. The underlying condition is an erosion of digital sovereignty: the enterprise’s ability to act independently and control the data, hardware and software it depends on.
- Confidentiality agreements and antitrust concerns keep CIOs isolated, so the pattern stays invisible and each negotiation starts from scratch.
KEY INSIGHTS
Based on a survey of 37 CIOs in Switzerland and Germany, 12 in-depth interviews and a series of practitioner workshops:
- Enterprises are caught in a triple bind of three interlocking mechanisms. Lock-in makes exit prohibitively expensive. Bundling forces payment for functionality nobody asked for. Scaling lets vendors extract more value at close to zero marginal cost.
- The mechanisms reinforce one another, which is why addressing any single one fails.
- The bind is measurable: 53% of CIOs spend more than 20% of their IT budget on licenses and maintenance, 70% see software costs outgrow revenue, and 24.3% call their vendor relationship unfair
- AI accelerates all three mechanisms at once. Embedded AI deepens data dependency, arrives as a mandatory bundle and is priced per use.
- No single countermeasure exists. Sovereignty is regained incrementally, through capabilities enterprises can build themselves.
WHAT EXECUTIVES SHOULD DO
- Categorize vendors into indispensable, replaceable and commodity, and report the indispensable ones to the board as an enterprise risk with a defined risk appetite.
- Turn software purchasing into strategic sourcing: build sourcing expertise, involve it before architecture decisions are made, and right-size contracted volume to actual usage.
- Establish discontinuity management: modular or dual-vendor architectures, executable exit plans piloted on non-critical systems, and exit options used openly in negotiations.
- Build coalitions through business user interest groups, and escalate deliberately from private dialogue to coordinated public pressure.
Key Questions Addressed by the Article
What is digital sovereignty for an enterprise, and how does it differ from digital sovereignty for a nation-state?
Digital sovereignty at the enterprise level is an organization's ability to act independently and control its digital destiny, including the data, hardware and software it relies on and creates. It differs from the geopolitical debate, which concerns nation-states, government bodies and defense agencies and centers on jurisdiction, data residency and strategic autonomy. For a CIO, digital sovereignty is operational rather than political. It shows up in three concrete capacities: whether the enterprise can still negotiate terms, decline functionality it did not ask for, and switch vendors within a realistic timeframe. An enterprise that has lost these capacities becomes a price-taker. Rising software costs are the visible symptom; the loss of control is the underlying condition.
Why are enterprise software license costs rising so sharply, and why can’t CIOs negotiate them down?
License costs rise because three vendor mechanisms operate together in what our research calls the triple bind. First, lock-in: technical, organizational and human dependencies make exit prohibitively expensive. Second, bundling: new functionality is packaged into core products, so enterprises pay for features they never requested. Third, scaling: subscription and usage-based pricing let vendors extract more value while their marginal costs approach zero. Because the three reinforce one another, addressing any single mechanism fails. In a survey of 37 CIOs in Switzerland and Germany, 62.1% reported volume-adjusted annual license increases of 5% to 20% between 2022 and 2024, and 70% said software spending outgrew company revenue. Embedded AI intensifies all three mechanisms simultaneously.
What can CIOs do to regain control over dominant software vendors, thereby reclaiming their digital sovereignty?
No single countermeasure exists, but four strategies address the triple bind directly. First, vendor categorization: sort vendors into indispensable, replaceable and commodity using business-process integration, market alternatives, market structure, switching barriers and switching timeline, then report the indispensable ones to the board as a defined enterprise risk. Second, strategic software sourcing: build sourcing expertise that matches the vendor's sales organization, involve it before architecture decisions are locked in, and right-size contracted volume to actual usage. Third, discontinuity management: modular or dual-vendor architectures, executable exit plans piloted on non-critical systems, and exit options used openly in negotiations. Fourth, coalition building through business user interest groups, escalating deliberately from private dialogue to coordinated public pressure. The organizing principle is that dependency risk should be assessed by depth of integration into core business processes.
Recommended Citation
van Giffen, Benjamin; Brenner, Barbara; and Brenner, Walter
(2026)
"How to Achieve Digital Sovereignty,"
MIS Quarterly Executive: Vol. 25:
Iss.
3, Article 4.
Available at:
https://aisel.aisnet.org/misqe/vol25/iss3/4