What happened
VMware's virtualisation platform underpins infrastructure across banking, telecommunications, government and healthcare. Broadcom's acquisition gave it control of the product, licensing terms, support arrangements and renewal timelines.
Perpetual licences were discontinued in favour of subscription bundles. Customers that had relied on long-term support found themselves evaluating new commercial terms and difficult migration programmes.
AT&T became the most visible public example. In legal filings it said a proposed annual increase of 1,050% was extreme, while estimating that moving away from VMware could cost $40–50 million and take years because the software was embedded across thousands of servers.
Incident at a glance
- Acquisition value
- $61B
- AT&T proposed annual increase
- +1,050%
- AT&T virtual machines
- 75,000
- AT&T servers
- ~8,600
- Estimated AT&T migration cost
- $40–50M
- Migration complexity
- Years of engineering work
The root cause
Every enterprise facing a renewal shock had implicitly accepted an unverified dependency: the assumption that the vendor would continue operating on affordable terms. Acquisition can eliminate that assumption quickly.
Software escrow addresses custody. Custody alone does not answer the harder question: can the enterprise operate the software without the vendor if it has to? That answer requires verified recoverability before a negotiation, not during one.
What would Proof of Recovery have changed?
- An enterprise with current signed Proof of Recovery enters a renewal negotiation from a stronger position because it can demonstrate a tested independent operating path.
- Migration planning begins from a verified baseline rather than an unknown software state.
- The board and risk committee have evidence of recoverability on file before the acquisition event, not a scramble after it.
“When the acquirer controls the licence, the SLA and the support team, the negotiating position that matters is whether you can operate without them”
The regulatory consequence
Acquisition and concentration risk are addressed through exit-planning requirements under EU DORA, the UK FCA's operational-resilience framework and India's RBI IT Directions. Each expects institutions to demonstrate that they can exit critical outsourced dependencies in an orderly way.