Last updated: 2026-10-05

U
Undergraduate level

Renting or Owning: Cloud Dependence, Retention, and Capability

What a change to a free service can reveal about where an organisation's data and abilities actually sit

A subscription to a cloud service feels like a service. Files are stored, mail is delivered, and someone else keeps the lights on. The arrangement becomes less comfortable when the terms change. In May 2025, Microsoft announced that it was retiring its grant offers for Microsoft 365 Business Premium and Office 365 E1, which had given about 400,000 nonprofits free access to these products. Existing recipients could continue until their next renewal on or after 1 July 2025, and after that renewal they had to pay or move to another offer[1].the license, not the data is what you rent

A change of that kind is a test of ownership. It asks whether an organisation can still do its work, keep its records, and move if it has to, once a provider stops providing something for free. The question applies to any capability an organisation has handed to someone else, and it applies with more force to AI systems that now perform parts of professional work.

1. Shared Responsibility FoundationalKnowledge that endures for decades — core principles

Large cloud providers usually describe their arrangements with customers as shared responsibility. The provider is responsible for the availability and physical security of its platform. The customer is responsible for what it stores, who can access it, and whether it has copies it controls. The division is reasonable, but many organisations read it in a way that moves more responsibility to the provider than the contract does.

Built-in features such as recycle bins, version histories, and grace periods after a subscription ends are policies of the platform. They are useful, but they are not independent copies. If the platform itself removes data, every copy held inside that platform can be affected at once. An independent copy is one whose deletion does not depend on the same administrative decisions as the original.if the account is suspended, you lose it all

2. Retention Windows and Backups Applied / MethodologicalKnowledge with a 5–10 year half-life — stable practice

The distinction between a retention window and a backup is easy to blur. A retention window says how long data is kept after an account changes state. It is a promise about timing, and it can be shortened, amended, or applied differently from what the customer expected. A backup is a copy whose survival does not depend on the subscription remaining in good standing.

Plan changes, tenant reorganisations, licence renewals, and offboarding are the events where data is most exposed to automated clean-up. They are also the events that administrators treat as routine paperwork. A useful rule is to treat each of them as a change to production, with a check that the data is still reachable afterwards and still copied somewhere the provider does not control.

The commonly cited 3-2-1 rule describes the arrangement: three copies of important data, on two different kinds of media, with one copy off-site and independent of the main provider. The rule is a starting point rather than a guarantee. A copy that has never been restored may not work when it is needed, so the rule should be paired with regular restore tests.off-site means off-provider, not just off-premise

3. What Was Reported Applied / MethodologicalKnowledge with a 5–10 year half-life — stable practice

The grant change is documented, and so is the notice that existing recipients received. Reports in 2026 went further. They described nonprofits that had lost data after their grant licences ended, and a headline from a technology news site stated that Microsoft had deleted some nonprofit customers' data early and said it could not recover it[2]. The details reported here, including how many organisations were affected and what support was offered, have not been checked against Microsoft's own statements, and this page does not rely on them.

The lesson does not depend on the details. Whatever the cause, the organisation that held only one copy, inside the platform whose licence had lapsed, had no route to recovery. The organisation that could still reach its own copies did not have that problem.the 3-2-1 rule: 3 copies, 2 media, 1 offsite

4. Ownership of Capability Applied / MethodologicalKnowledge with a 5–10 year half-life — stable practice

Data ownership is one part of resilience. Organisations also depend on capabilities: the ability to perform a task, to understand how it is done, to check whether it was done correctly, and to recover if the usual route fails. A task can be outsourced successfully for years and still leave the organisation unable to do it itself.capability is the know-how, not just the output

Examples include hosting, identity management, security monitoring, software development, legal analysis, assessment design, and AI-assisted decision making. For each, the question is the same. Which capabilities must stay inside the organisation even when an outside system does part of the work? Which of them can be lost without anyone noticing until something goes wrong?

Cloud questionParallel question for AI-assisted work
Who owns the data?Who owns the reasoning behind the work?
Can we recover if the provider fails?Can we still do the task if the AI is unavailable?
Do we hold an independent copy?Do we hold independent expertise?
Can we verify what was lost?Can we verify what the AI produced?
Are we dependent on one vendor?Are we dependent on one tool or model?

5. Risk Dimensions Applied / MethodologicalKnowledge with a 5–10 year half-life — stable practice

A provider's failure is usually discussed as an operational problem. Reliance on any outside system carries several kinds of risk, and an organisation that considers only the operational one will miss the others.

Risk typeQuestion to ask
OperationalWhat happens when the service fails or is withdrawn?
EpistemicCan we verify the output we depend on?
EducationalWhich capabilities are people no longer developing?
ProfessionalWho remains accountable for the decisions?
PoliticalWho controls access to an essential capability?
StrategicCan we leave without major disruption?

The grant change is mainly an operational and strategic risk. The same questions arise with AI systems, where the epistemic, educational, and professional dimensions are often more pressing.epistemic risk: you stop knowing what you know

6. The Responsibility That Stays Human Applied / MethodologicalKnowledge with a 5–10 year half-life — stable practice

A common assumption in AI deployment is that the system produced the answer, so the system is responsible for it. In practice, the responsibility stays with the people who chose to use the output, who acted on it, and who answer for the consequences. A cloud provider does not take on responsibility for the integrity of a customer's data, and an AI system does not take on responsibility for decisions made using its output. The tool can be part of the reasoning. It cannot be the one held to account.

7. Understanding as a Backup Applied / MethodologicalKnowledge with a 5–10 year half-life — stable practice

Independent copies protect data. Independent competence protects capability. A student who has built a mental model of a subject can check an AI's explanation, notice when it is wrong, and continue working when the tool is unavailable. A student who has only received explanations loses those abilities as soon as the explanations stop. In this sense understanding works as a backup, and it is one that the individual, rather than a provider, has to keep.

8. Resilience Through Collaboration Applied / MethodologicalKnowledge with a 5–10 year half-life — stable practice

The lesson is not that organisations should refuse cloud services, and it is not that professionals should refuse AI tools. Resilience comes from keeping capabilities distributed, from having several perspectives able to spot errors, from keeping independent verification possible, and from keeping a way out.

ModeDependency and resilience
ReplacementHigh dependency; no retained capability
DelegationModerate dependency; some verification possible
CollaborationGreater resilience; several perspectives in the work
Independent capability with collaborationHighest resilience

Conclusion FoundationalKnowledge that endures for decades — core principles

Every technology that reduces effort also changes how knowledge, responsibility, and power are distributed. The ethical question is therefore not only whether a technology works, but what individuals and organisations give up when they rely on it. Responsible adoption needs more than efficiency. It needs ways to verify outputs, recover from failure, keep oversight, and leave when necessary. The aim is not self-sufficiency. It is a partnership in which enough independent capability remains to understand, challenge, and recover from the systems people now depend on.

References

  1. NonprofitQuarterly, "Microsoft Axes Free 365 Software for Nonprofits" (May 2025). https://nonprofitquarterly.org/microsoft-axes-free-365-software-for-nonprofits/
  2. TechRadar, "Microsoft deletes nonprofit customers' M365 data — and says it can't get it back." Reported; the article text was not available for checking. https://techradar.com/pro/microsoft-deletes-nonprofit-customers-m365-data-and-says-it-cant-get-it-back