In May, I wrote about Andrew Olsson, a YouTuber who woke up locked out of Claude with no warning and no explanation. Everything he'd built inside it was gone. I asked: if your AI account closed tonight, with no warning and no appeal, what would you lose?
The situation has developed since then. In September alone, we saw three examples of how innocent businesses can become collateral damage and lose data.
- You get locked out by the AI vendor
- The AI vendor shuts down
- The AI vendor gets acquired
I'll then share how I've been able to mitigate some of them with a few changes to how I work and use these AI tools.
1. Your login gets stolen, and you're the one who gets locked out
We're used to a familiar pattern of account theft. Someone steals your login, locks you out, and ransoms the account back. What happened to Grant De Swardt is different.
De Swardt runs a one-person business in East Sussex, helping companies set up AI agents. On 4 August, he noticed his Claude token usage climbing on a day he hadn't touched it. He disabled everything connected to his account. Usage kept climbing anyway.
He asked Anthropic for an itemized list of what was consuming his tokens. They couldn't provide one, so there was no easy way to stop the unauthorized usage. In a last ditch move, Anthropic suspended his entire account for two weeks.
Anthropic later told him a compromised session key had been used to create unauthorized tokens on his account. As he relayed to TechCrunch, the evidence was "consistent either with credentials/session data being taken without my knowledge, or with the account having been connected to an outside service." De Swardt says he found no sign his own computer was compromised, and still doesn't know how it happened.
He got his account back after 2 weeks, and has since moved to a different tool. Anthropic still has no way for a customer to see what's consuming their usage. "I don't think there's any way that these people can protect themselves," he told TechCrunch.
The attacker didn't lock De Swardt out. The vendor did, correctly, to stop further unauthorized use. For 2 weeks, he was locked out of his account.
What would be the impact if this happened to you? Do you have a copy of your critical data if you're locked out of your account?
2. The key staff leave for a big company, and the product dies
Cyber risks are just one way to lose access to an AI account, as our next story shows. The career choices of individuals can also be a risk to you.
Relay was an AI workflow tool for moving data between apps a small business already runs. Tools like this are incredibly useful – just getting different apps to "talk to each other" has huge business benefits.
Like any tool or software service, it takes an investment of time and money to adopt, learn and use the service: connecting systems, testing that they work, changing business processes.
Relay had paying customers and $8.1 million in funding. On 14 September, it stopped operating completely.
Why, you may ask? Relay's founder, Jacob Bank, left to rejoin Google as VP of Product for Chrome, and members of his team went with him (TechCrunch).
Relay simply shut the product down. Free users lost access on 15 August. Paying customers had until 14 September, about a month, to export their data and find an alternative service.
This is the classic "vendor shuts down" risk.
In this case, the founder decided to make a career change. Customers weren't the target of Bank's career move; they were collateral damage.
3. Your AI vendor gets acquired; will the purchaser treat you with respect?
It's common for software and AI vendors to get acquired. But this kind of event can put your account, and the work inside it, at risk.
Almost nobody reads the terms of service at signup. You click through because you want the tool. Did you read all the T&Cs for Microsoft 365 or AWS or Google Docs?
Years later, when a bigger company buys the vendor, it's the written contract that governs the relationship. The purchaser looks at the legal terms, not at the goodwill you had with the old team, and not at any moral obligation you assumed was there.
NetNow is a fresh example. It runs credit checks and fraud screening for businesses, and says it's used by 85,000 customers. On 21 September, BlackLine bought it. That is the moment a lot of customers start reading paperwork they skipped on day one.
When people checked the fine print, two things became clear:
- On the service: "Either party, be it you or us, can conclude this Terms of Service either with or without reason or prior notification." §14 Ending or Discontinuation
- On customer data: "It's your responsibility to keep copies of Your Content. NetNow isn't responsible for any content losses or damages." §3(b) Your Content
Here's the problem. You might have signed up for NetNow, or any AI vendor, when they were a small company – friendly people, a mission you believed in, great tech support.
But when a company gets acquired, the prior "good vibes" can change instantly. Small vendors get bought by mid-size ones, which get bought by large ones. Before long, your vendor can be completely different to deal with. Yet, the original contract you agreed to is still in place.
And NetNow's contract is not good for its customers. It took Rajesh Beri, an enterprise AI practitioner, to highlight the worst-case risk. This is how an operational matter becomes a business risk:
- You risk losing access to those credit files.
- In a lawsuit you can’t prove why you approved or denied credit to an applicant.
- That makes it extremely challenging to defend claims or prove compliance with Regulation B (under the Equal Credit Opportunity Act).
Collateral damage, then the fix
I find it interesting that the 3 risks existed long before AI, but with the hype and drive towards AI adoption, many people aren't thinking about the risks.
That's the problem. If the only copy of your work is in your vendor's tool or account, you take on every risk the vendor has, and more.
| Story | What actually happened | Was the work ever separate from the tool? |
|---|---|---|
| Claude | A stolen login led the vendor to suspend the account | Chat sessions, project files live in Anthropic's servers. Export is a separate, manual task you have to do yourself. |
| Relay | The product shut down after its founder and staff joined Google | Export was available, and customers got a month's notice to export and save their data. |
| NetNow | Acquired, drawing attention to the T&Cs. | Some way to pull files appears to exist, but under the T&Cs keeping copies is the customer’s job, and the vendor can cut access with no advance notice and no duty to hand over an export. |
What I've been doing and how I'm thinking about this
In May, I still didn't have a good answer. I exported Claude project files by hand whenever I remembered, because they only ever existed inside the account. I still do periodic exports, but I've changed tack over the past few months.
I've been experimenting and trying to find an approach that works for me personally, before rolling it out through the company. It's been pretty successful so far – my new approach is to decouple the tool from the data.
Since then, I've moved most of my own AI work onto files on my hard drive, and changed the bulk of my work from Claude (on the web) to Claude Code. This has only been possible recently, because a year ago, Claude Code refused to do any task that wasn't coding-related.
Here are my new work practices:
- I keep every version of my AI related files with git (free software that tracks every past change to a file)
- I push a copy to a remote server (which you can do too – GitHub and Bitbucket are two examples)
- I back up my local machines to separate media
This gives me the classic 3-2-1 backup configuration.
Although I went down that path for data protection and cyber-security reasons, there's a huge secondary benefit that I only just realized recently: switching costs drop dramatically.
Because the work already lives in files I control, I've been able to use Grok on the same material and move across smoothly when I wanted to. If one provider became untenable for any reason (price, policy, lockout, shutdown), I'm not starting from zero inside a brand new account.
This works when the tool can work on files you hold. I'll be monitoring the landscape to look out for opportunities where BackupAssist 365 can also help.
Your turn
The test for any tool your business depends on: if the company behind it disappeared tonight, would your data go with it?
Pick the AI tool your business would miss most tomorrow morning. This week, find out whether the work is separate from the tool. Could you walk away from the vendor tomorrow and still retain a copy of your data and work?
If you already knew the answer, you're ahead of most people I've talked to. If you didn't, that's useful too. What did you find?





