Everyone’s worried about model lock-in, but the real trap is context lock-in
claude code was the warm-up. claude tag is the real product, and it’s the most powerful thing anthropic has ever shipped. also the most dangerous.
anthropic shipped claude tag last week.
my feed called it a slack feature. tag @claude, it follows the thread, remembers the context, gets the work done. convenient. clean little demo.
i read the same announcement and lost a night of sleep over it.
because i build this stuff for a living. agents, harnesses, the context layer underneath them, in production, for real customers. so i know exactly which part of claude tag is the actual product. it isn’t the model. it’s the part that quietly learns your company.
what they actually shipped
one claude per channel, not one per person. it reads the threads you let it into. ambient mode means it doesn’t wait to be tagged, it watches and follows up on its own. it runs on opus 4.8. it replaces the old claude-in-slack app, which gets switched off august 3. and anthropic says 65% of their own product team’s code now comes from their internal version of it.
andrej karpathy, who just joined them, called it the third redesign of how we use llms. first the model was a website you visited. then an app you downloaded. now it’s a persistent thing that lives inside your org and works while you sleep.
he’s right. that’s the part that should make you stop scrolling.
the moat was never the model
everyone’s arguing about model lock-in. wrong layer.
a model you can swap. route to a different provider, re-run your evals, move on. annoying, not fatal.
context is different. claude tag spends months absorbing how your company actually runs. who owns what. how decisions really get made. the threads, the docs, the half-finished projects, the tribal knowledge that lives in nobody’s wiki. it builds a graph of your company.
that graph is the switching cost. and it doesn’t sit on your side of the fence. it sits on theirs.
so the day you want to leave, the model is the easy part. the company-shaped memory you spent a year feeding it is the part you can’t carry out the door.
that’s not model lock-in. that’s context lock-in. and you’re paying every month to rent your own company back.
where this goes
matthew berman walked through the endgame and i think he’s mostly right.
once your AI vendor becomes the place where work gets interpreted, routed and done, your software stops mattering. customers stop logging into your UI. they just tell the agent. then the agent learns your workflows. then it writes code to replace those workflows. and at the end of that line you’re a database the agent reads from.
no software is really safe from that argument. it’s the biggest version of platform risk we’ve seen. you’ve lived through the small versions (building on the app store, building on someone’s API until they changed it). this is the same move pointed at all knowledge work at once.
and the pricing makes it sharper. a human teammate has a salary. there’s a ceiling. claude tag bills tokenized activity with no ceiling at all. there’s always more work to chase, more context to ingest, another loop to run overnight. the company that can spend the most on tokens wins the most. sit with that one for a second.
why this is personal for me
i spend my days building the exact thing anthropic just turned into a product. the harness. the memory. the context engineering. the guardrails that stop an agent from doing something dumb at 3am while nobody’s watching.
the lesson from building it is boring and it’s clear. the model is a commodity. the moat was always the context layer. anthropic understands this better than anyone alive, and claude tag is them taking the moat. not by force. just by being the most convenient place to put your company’s brain.
what i’m betting on instead
so here’s where i’ve landed, and i’ll say it plainly.
if the context layer is the moat, you cannot rent it. you have to own it.
that means a different stack than the one everyone’s sprinting toward.
a model you can run on your own infra. open weights have quietly gotten good enough for most real work.
context engineering that lives inside your perimeter, not anthropic’s.
your own harness and orchestration, so the company graph belongs to you.
your data staying in your jurisdiction, under your audit log, on your terms.
sovereign isn’t a compliance checkbox. it’s the only version of this future where the memory of your company is actually yours.
and this isn’t paranoia. one export order took a model offline worldwide this month (the fable ban, june 12). the EU AI act’s real rules land august 2. a 2026 survey found 94% of IT leaders already worried about vendor lock-in. renting your intelligence from one US lab is shakier than the demos make it look.
the honest part
i want to be fair to anthropic. claude tag is genuinely good. the productivity is real, not hype, and i use their models almost every day.
but good and safe are two different questions.
the convenient version of this future is one company holding the live memory of every other company. i don’t want to build my business on top of that. i’d take a little less polish and a lot more of my own house.
rent the model if you have to. never rent the context.
