be/brief
Request access
← The Debrief
Trust & portability

A download is not ownership.

Ask a vendor whether you own your data and you will get a yes so quick it should worry you. Of course you do. There is an export button in settings, and the law now says there has to be. Click it and a file lands in your downloads folder. That file is where the honesty usually ends.

“You own your data” has quietly become the emptiest sentence in AI, because almost everyone saying it means the same small thing: you can download a copy. That used to sound generous. It is now the legal floor. The GDPR’s right to data portability already obliges anyone holding your data to hand it back in a “structured, commonly used and machine-readable format.” The EU Data Act, applicable since 12 September 2025, goes further for cloud services: it forces providers to support your migration to a competitor within set timelines and phases out the switching fees they used to charge for the privilege. So the download button is no longer a favour a company does you. It is table stakes. And a compliant file can still leave you completely stuck.

Where the lock-in actually lives

Here is the claim I will not soften: a data export you can’t run anywhere else is worthless, and most of the vendors loudest about ownership are betting you will never check. The download proves the bytes left the building. It says nothing about whether they can enter another building. A JSON dump of two years of chat logs is machine-readable, entirely portable in the strict legal sense, and completely inert the moment you try to do anything with it somewhere new. You have the transcript. You do not have the working knowledge.

That gap is deliberate more often than it is accidental. The format is where the lock-in quietly moved once the download button became mandatory. A company can satisfy every letter of the regulation and still ship you a shape no other tool understands, missing the one thing that made the product worth using. You get a deed to a house with no doors.

Four checks a non-coder can run

You do not need to read the schema to know whether your export is real. You need four questions, and you can answer all of them in an afternoon without writing a line of code.

First, can you read it without their app open? Export the file, close the product, and open what you got. A calendar that comes back as .ics or contacts as .vcf you can read on any machine forever. If the file only makes sense once it is loaded back into the software you were trying to leave, you exported a hostage rather than a copy.

Second, does another tool actually ingest it? This is the question the word “machine-readable” hides. Valid JSON that no other product knows how to load is machine-readable and useless in the same breath. Take your export to a competitor or a plain spreadsheet and try to bring it in. If nothing on the other side can absorb it without a developer in the middle, the format was a wall wearing the costume of a door.

Third, does it carry the judgment or just the raw material? The value your assistant built up was never the transcript. It was everything it learned around the transcript: your preferences, the decisions you made and reversed, the way you like a thing handled, who matters and who can wait. A pile of past messages is evidence that work happened. It is not the accumulated context that made the tool feel like it knew you. Most exports give you the former and call it the latter.

Fourth, does anything still function once you have left? A photo archive is still a set of photos on a hard drive. An automation you spent months teaching, exported as a document describing what it used to do, is a memoir. Ask whether the exported thing does its job on the other side, or merely describes a job it used to do.

Two of those four will usually pass. It is the third and fourth that separate a genuine deed from a printed receipt, and they are exactly the two no marketing page mentions.

This is the test be/brief is built to survive, because it is the one we would apply to anyone else. What your associates learn about your work is held in an open format you can read with the app shut, structured so another tool can pick it up and keep going. Not because a regulator started counting, but because a promise you cannot check is not a promise. Before you trust any vendor with the context that makes your work yours, run the four checks on their export. The good ones will already have an answer. The rest will point you back to the download button and hope you stop there.

Brief is opening to a small group at a time. Direct a team instead of operating one more tool.

Request access