The Times They Are A-Changin' - Just Not on SAP's Terms

Headshot for blog author Adam Mayer. Hew short hair, a light-colored shirt with dark sweater over it. He smiles at the camera, standing in an office with striped glass partitions.

Adam Mayer

4 minutes

Bob Dylan wrote those words in 1964 about a world in flux - where the old rules were being quietly rewritten, and the people who hadn't noticed yet were about to find out the hard way. He wasn't thinking about enterprise data architecture. But if you've been following SAP's moves on data access, extraction, and platform strategy over the past two years, those words might be landing a little closer to home than usual.

In June 2026, SAP enforced a security patch that blocked third-party ODP-RFC access - a method that had been officially prohibited since February 2024, but never technically enforced until now. For many organizations using ODP-RFC in their data integration pipelines it has become a hard-stop.

Take the practical steps you need to take - there's a separate post for that on Qlik Community. But once you've done that, sit with the bigger question this moment is really asking: what does SAP's tightening grip on data extraction tell us about where enterprise AI is actually heading, and whether SAP's platform story is the right vehicle to get there?

The Pattern Behind the Patch

The ODP-RFC enforcement didn't happen in isolation. It arrived at the same time SAP was launching SAP Business Data Cloud, positioning Datasphere as the governed intermediary layer for SAP data, and announcing zero-copy partnerships with Snowflake, Databricks, Google BigQuery, and Microsoft Fabric.

Read together, the message is coherent: SAP wants to be the control plane for how its data moves, who can access it, and under what terms. BDC Connect is the sanctioned path within the new SAP eco-system. ODP-RFC, in SAP's framing, was always an unsanctioned shortcut - and now that shortcut is closed.

That's a reasonable position for a platform vendor to take. The question worth asking isn't whether SAP has the right to enforce it. It's whether SAP's preferred path is where enterprise AI is actually being built.

The Bigger Picture: SAP Data in a Multi-Platform World

It would be easy to read SAP's ODP changes purely as a compliance headache. But there's a broader shift worth understanding alongside it - one that affects how organizations think about SAP data strategy more generally.

SAP is actively steering customers toward its own data platform: SAP Business Data Cloud (BDC) and SAP Datasphere. On paper, the pitch may be compelling - a governed, semantically rich layer purpose-built for SAP data, with zero-copy connectivity to platforms like Snowflake and Databricks. For organizations deeply invested in the SAP ecosystem, there is genuine value in that model.

However, here’s an interesting stat that really stood out for me. According to the DSAG Investment Report 2026 - a survey of SAP's own German-speaking user community, not a Qlik-commissioned study - 77% of productive AI scenarios are currently being run on non-SAP platforms. Nearly four in five SAP customers have already decided, in practice, that their AI future doesn't live inside the SAP stack.

That's not a criticism of SAP. It's a description of where AI is actually happening in the enterprise - on Snowflake, Databricks, Google BigQuery, Microsoft Fabric, and combinations thereof. Organizations have made significant investments in those platforms, and they're not unwinding them because BDC arrived. In fact, as The Register reported in December 2025, 83% of DSAG members were only slightly familiar or not familiar at all with BDC at the time of launch - and nearly half expressed concern about commercial lock-in if BDC became their only path to data innovation.

As my colleague Ben Wild pointed out, The Kingfisher story is worth noting here too. B&Q's parent company publicly stepped off SAP's recommended upgrade path, choosing instead to innovate around its legacy ECC core using Google Cloud and Databricks. The point isn't that every organization should follow Kingfisher's lead - it's that the notion of a single SAP-native path to AI is not the only path.

That's exactly where Qlik Open Lakehouse fits - the layer that makes your whole data estate coherent. Whether you're building on Snowflake, Databricks, BigQuery, or Fabric - the platforms where 77% of enterprise AI is already being built - Qlik gives you the freedom to build an open, governed foundation that spans your entire data estate. Not just the SAP part. And critically, it does so without forcing you to choose between your SAP investments and everything else.

Think of it this way: BDC Connect is excellent at making SAP data products available to your analytics platform of choice. Qlik makes sure everything else that needs to join that conversation - from a legacy ERP to a real-time IoT feed - arrives at the same party with the same level of trust and quality. For the 77% of AI scenarios already running outside the SAP stack, that foundation isn't a nice-to-have. It's the whole point.

For organizations actively evaluating BDC, Datasphere, or both, Qlik can serve as a complement: handling data quality, non-SAP integration, and the kind of flexible multi-cloud integration that SAP's native tooling wasn't designed for. For those asking harder questions - whether Datasphere is the right intermediary layer given existing investments in Snowflake or Databricks - Qlik can serve as a capable ingest and optimize solution for all your data, SAP and non-SAP, into these investments.

The ODP enforcement is a reminder that data access is never truly free. What matters is whether the architecture you're building gives you genuine choice - or simply trades one dependency for another.

As Matt Hayes, our GM for the Data Business Unit recently argued at SAP Sapphire: "Open" on whose terms? It's still the right question.

The Bottom Line

SAP's ODP move is a compliance event. But it's also a signal - about where SAP wants to sit in your architecture, and what it will cost you to operate outside that model. The enterprises that navigate this well won't be the ones that simply find the nearest SAP-approved workaround. They'll be the ones that use this moment to ask a harder question about whether their data foundation is genuinely open, or just open on someone else's terms.

The times are changing. The question is whether your architecture is changing with them.

If you're looking for the practical guide to ODP-RFC migration steps and Qlik product options, start here. This post is about the bigger picture.

Ready to get started?