The great AI lockdown has begun
AI broke the open-API bargain. Access is repricing.
Contents
In June, an email from Strava landed in my inbox. A new Developer Program: from 30 June, standard API access would require an active Strava subscription, new tiers, and a new agreement with restrictions written specifically for the AI era.
In the first week of July, Pelaris’s Strava import went from dozens of synced sessions a week to zero. Our integration code had not changed since mid-June. Nothing on our side broke. The door we had built on closed, at least for now, on someone else’s calendar.
Six weeks earlier I had published a piece on AI exploding content that used Strava’s developer ecosystem, 175,000 developers and climbing, as evidence that AI was widening platforms rather than shrinking them. The email announcing the paywall was already sitting in my inbox when I hit publish. That is how fast this is moving.
The lockdown is not one company’s pricing decision, and it is not a fitness-app story. The same move is running across consumer platforms, infrastructure, and enterprise software at the same time, for the same reason, in two very different styles. If your organisation builds on other people’s APIs, or you are wiring AI agents into an enterprise stack, the ground rules changed underneath you this year.
The doors are closing across consumer platforms
Strava, credit to them, put the real reasons in writing: AI companies scraping for training data, API intermediaries breaching terms at scale, zero-code AI tools hammering the API, and developer applications up 448% year to date. That surge is not 448% more fitness startups. It is vibe coding arriving at one platform’s front door. The response followed the money: standard access now requires a paid subscription while big device partners sit in an exempt tier, the API agreement restricts AI training on the data, and on the same day it announced the change Strava launched its official MCP connector, read-only, subscribers-only. The free door closed and a supervised window opened.
Garmin is running the quieter version. It has paused all new Connect API access requests while the program is “evolving and modernizing”, with the application form removed and no reopening date, while its own paid Connect+ analytics tier expands into territory third-party developers used to own.
A pause with no end date is a lockdown with better manners.
Reddit wrote the playbook. In 2023 it repriced its API hard enough to kill a generation of third-party apps. Then it signed data licensing deals reported at around $60 million a year with Google, and a similar arrangement with OpenAI. Then it sued Anthropic for allegedly scraping rather than paying for a licence.
Close the free door, open a paid one, litigate the side doors.
Once you know the sequence, you find it everywhere. X put its API behind steep paywalls in 2023, the first big door to slam. Spotify cut recommendation and audio-analysis endpoints for new third-party apps in late 2024, citing scraping, then tightened again this February. Stack Overflow turned its archive into a licensing product and sells paid access to OpenAI. And the open web flipped its default: Cloudflare now blocks AI crawlers by default for new domains and runs a pay-per-crawl marketplace on top, extended this month to paying publishers when their content appears in AI answers. Fitness, music, code, social, publishing, the web itself. Different industries, identical move.

Why now: AI broke the API bargain
The open-API era ran on a bargain nobody wrote down. Platforms gave developers free or cheap access because every use of the API pulled humans toward the platform: more engagement, more accounts, more lock-in, more eyeballs for whatever the platform monetised.
The API was a marketing channel that happened to ship JSON.
AI broke both halves of that bargain at once. This is my synthesis of what changed, not any platform’s official line, but the pieces are all in plain view.
First, the consumer of the API stopped being a proxy for a human. An agent pulling your data into a chat interface generates no ad impressions, no subscriptions, no network effects. The explosion in cheap software multiplied API traffic exactly when the value of that traffic to the platform collapsed. Strava’s 448% application surge is what that looks like from the platform’s side of the counter.
Second, the data itself acquired a price. When Reddit’s conversation archive is worth tens of millions a year to a model lab, a free API is not a growth channel anymore. It is a leak in the vault. Platforms that watched those deals get signed now look at their own APIs the same way.

Add the pressure of an IPO or a quarterly earnings call, and the lockdown is not paranoia. It is the rational repricing of an asset that used to be given away because nobody knew what it was worth.
The enterprise version is politer
Consumer platforms slam doors. Enterprise vendors install revolving ones, with a meter on the axle.
The move is the same, the manners are different, and the numbers are much larger.
SAP is building the walls in the open. Its new API policy for 2026 restricts consumption to published, documented APIs only, explicitly shuts down the internal and undocumented interfaces that decades of integrations quietly depend on, and tightens how data can be accessed at scale by AI-driven tools. The sanctioned path runs through the Business Technology Platform, where the Integration Suite is priced per message, with capability packs licensed on top. CEO Christian Klein’s framing is that customers’ data stays free to access; what SAP is protecting is the semantic model, the process logic, the IP around the data. That distinction is doing a lot of work. If your agent needs SAP’s business context to act on SAP data, and it does, the context is the product, and the road to it runs through a gate SAP owns.
None of this should surprise anyone who remembers that SAP litigated the question of whether a third-party system touching SAP indirectly needs a licence, and won, against Diageo, in 2017. The claim exceeded £54 million. The settlement architecture that followed became Digital Access licensing, pay-per-document for anything a non-human creates in the system. Agents are about to make that meter spin at a rate 2018 could not have imagined. The AI-era API policy is the same doctrine, upgraded for a world where the “third-party system” is an autonomous agent.
Salesforce is going headless. The head it kept is the till. In May 2025 it changed Slack’s API terms to prohibit bulk data export and ban using Slack data to train LLMs. Third-party enterprise search tools that had indexed customers’ own Slack history lost that access, replaced by a Real-Time Search API that answers query by query, inside the fence. Then came the second half of the move: Slack repositioned as the front door to the agentic enterprise, where agents built on any platform can surface, chat, and act, provided the conversation flows through Salesforce’s interface, Salesforce’s connectors, and Salesforce’s metering. The screens are dissolving into chat, the releases arrive on Salesforce’s calendar rather than yours, and the data never leaves home. Your data, their front door, a toll either way. It is a genuinely elegant construction.
Microsoft closed a data door and reopened it inside the agent stack. In August 2025 it retired the Bing Search APIs outright, on three months’ notice. The replacement, Grounding with Bing Search, exists only inside Azure AI Agents: you no longer get the data, you get an agent that has read the data, at 40 to 483% more depending on tier. The raw endpoint died and its successor is shaped like a platform commitment.
Workday built the gate first and called it governance. Its Agent System of Record registers, configures, activates and deactivates AI agents, including third-party agents arriving through its Agent Gateway, pitched as a unified control point to manage and meter all agent interactions, with more than 65 partners already signed on. The governance need is real. Meter is still the load-bearing word.
ServiceNow is flirting with both. It may be the smartest posture of the set. At Knowledge 2026 it opened its “full system of action” to any AI agent, Claude, Copilot, custom builds, no requirement to use ServiceNow’s own agents. That is real openness, and it is more than the others offered. The other hand holds the AI Control Tower positioning: every one of those external agents executes through ServiceNow’s governed workflow layer, which is the layer that gets measured, and measured layers get monetised. Having spent years running exactly this class of platform at enterprise scale, I think the governance is genuinely needed. I also think open protocol, governed gate, metered throughput is the whole strategy in six words.
Step back and these are one story. Nobody in enterprise software is ending the API era. They are converting it from a commons into a toll road, and the conversion is happening at the precise moment MCP and A2A make cross-platform agents almost trivial to build. Those two facts are not in tension. The second caused the first. Open protocols made agent traffic inevitable, so the platforms moved the control point from the connection, which they can no longer defend, to the gate, which they can charge for.

The new asymmetry
Two weeks ago I argued that the cost of intelligence is collapsing, roughly tenfold a year for a fixed capability, and that falling cost is the base case to design for. That argument stands. The lockdown adds its counterweight: the one input repricing upward is access to the data and systems worth pointing intelligence at.
That asymmetry is the strategic fact of the next few years. Models are commoditising. Data rights, integration rights, and action rights are concentrating. The platforms have worked this out faster than their customers.
The moat has moved from having the intelligence to owning the thing the intelligence needs to touch.

In June I wrote about the three clocks that broke enterprise application support. This lands squarely on the second one, architecture. The vendor calendar you do not control now covers more than releases: licensing terms, API tiers, integration points and workflow access can all be repriced or revoked between one sprint and the next. And it has to be designed for on both sides of the counter, the platforms your applications consume and the doors your own applications provide, because the same repricing logic is coming for both.
What this means for the enterprise
None of this is a reason to slow an agent roadmap. It is a reason to walk into it with eyes open, because the exposure compounds on the cost line and the risk line at the same time. Where I would start:
- Inventory the estate. List every workflow that depends on a third-party API, a connector, or an undocumented interface, and mark whose calendar each one dies on. SAP has already declared undocumented interfaces out of bounds; assume every vendor will. Your agent roadmap multiplies this list.
- Model the meters at agent volume. Per-message, per-document, per-conversation and per-action pricing all compound as agent traffic grows. Price the target architecture at ten times today’s call volume before signing anything.
- Negotiate data and agent rights at renewal, not at incident. The AI and agent clauses in your contracts are being rewritten right now, mostly unread. Diageo teaches that the wording decides, and that the invoice can arrive years later.
- Test bulk egress annually. The practical definition of owning your data is being able to get all of it out, at will, at reasonable cost. Slack’s shift to query-by-query access shows how quickly “your data” becomes “your data, viewed through our window”.
- Treat revocation as a failure mode. Design integrations to distinguish “no new data” from “the door just closed”, and alert on the difference. The default failure is silent, and a silently dead integration can run for weeks before anyone notices the numbers drifting.
- Audit the long tail. The citizen developers you have empowered built their tools on these same APIs. When a platform repockets access, the sanctioned integrations fail loudly in IT; the unsanctioned ones just quietly stop working somewhere on a frontline.
There is a second half to this that most enterprises have not started. You are not only a consumer of other people’s doors. You hold data and systems that other people’s agents increasingly want to reach: suppliers, partners, customers, and soon their AI acting on their behalf. Every vendor in this piece has decided its posture, open protocol, governed gate, metered throughput. Most enterprises have not decided theirs. Which doors exist, who gets keys, what gets metered, and what stays shut is about to become a standing architecture question, and it is better answered before the traffic arrives than after.
The repricing, not the end
I do not think the lockdown is a tragedy, and I am not going to pretend I would behave differently with a balance sheet full of valuable data. The platforms making this move are reading the same numbers and acting rationally. The open-API commons was always an artefact of data being cheap, and data stopped being cheap the moment machines learned to read all of it.
But a repricing this fast rewards the organisations that notice it early. Intelligence is getting cheaper. Access is getting dearer. The enterprises that come through this cleanly will treat access as a priced, revocable input, negotiate it like one, and design for the day a door closes.
Start with the inventory. One list, every external dependency, whose calendar it dies on, and what happens to the business the week it does. The email that opened this piece was addressed to a weekend-scale developer program. The ones being drafted now are addressed to enterprise integration estates. The list is cheaper to write before yours arrives.
Written by Bradley Hunt. For more on AI-first building and enterprise architecture, see the writing index.
Read next
Bradley Hunt
AI, engineering & leadership