The Letter That Doesn’t Know You Already Left
Somewhere out there, a compliance system is very upset about software nobody is using.
Broadcom has been sending a wave of VMware cease and desist letters over expired licenses, and the pattern goes back further than people realize. It escalated in 2024 when AT&T sued Broadcom over a VMware support dispute involving roughly 75,000 virtual machines, a fight that eventually ended in a settlement. Since then, reports have piled up of smaller organizations getting the same kind of letter, some of them well after they had already decommissioned VMware entirely.
Which means somewhere, a system is comparing an expiration date to a “still active” flag, and nobody checked whether the flag was actually true.
Automated Compliance Doesn’t Do Context
Here’s the thing about enforcement at scale. It’s not a person reading your account history and deciding you look suspicious. It’s a script matching one date against another and generating a letter with the word “willfully” in it. The letter sounds personal. It is not personal. It is a spreadsheet with a mail merge.
That’s a little unsettling if you sit with it for more than a minute, because it means the letter you get has nothing to do with what you actually did. It has to do with whether your account still shows an open license row in a database somewhere. You could have unplugged every server in Q1 and still get a letter in August, because nobody told the database.
The Reseller Blind Spot
A lot of enterprise software doesn’t get bought directly. It gets bought through a reseller, who becomes the actual point of contact for renewals, support, and account changes. Which makes sense, until the vendor’s compliance team decides to reach out directly and the reseller relationship isn’t the channel they’re checking.
So you tell your reseller, “We’re done with this.” Your reseller, presumably, updates something on their end. Meanwhile, the vendor’s own records may never get the memo, because the reseller relationship and the vendor’s internal compliance tracking are two different systems that were never really designed to sync. You did the responsible thing. The responsible thing just didn’t reach the place that mattered.
What to Actually Document
If there’s a practical takeaway here, it’s this: decommissioning something quietly is not the same as decommissioning it on the record. A few habits that would save someone a very awkward Tuesday:
- Get written confirmation from your reseller when you tell them you’re done with a product, and keep it somewhere you can find it in six months, not buried in an email thread.
- Ask who at the vendor actually owns your account, directly, not just through the reseller, and get their name in writing at least once.
- When you turn something off, note the date. Not in your head. Somewhere searchable. “We decommissioned this in Q1” is a much stronger sentence when you can point to the ticket that proves it.
- Set a calendar reminder to confirm the decommissioning was actually received and logged on the other end, not just sent into the void.
None of this prevents a badly targeted letter from showing up. Automated systems are going to keep generating them regardless of what you actually did. But it turns a stressful ten day scramble into a five minute reply with a paper trail attached.
A Paper Trail Beats a Good Memory
The uncomfortable lesson in all of this isn’t really about VMware, or Broadcom, or any one vendor. It’s that the systems tracking our compliance are only as accurate as the last update somebody remembered to make. We build automation to remove the need for human judgment and then act surprised when it does exactly that: removes the judgment and keeps the automation.
So maybe the real fix isn’t a better vendor relationship. It’s better records. Because apparently, in enough of these systems, if it isn’t written down, it didn’t happen. Even when it very much did.



