Microsoft CEO Satya Nadella has issued a surprising and sharply worded warning to companies that rely on commercial AI models. In a blog post published on Sunday, Nadella argues that business buyers of AI are not just paying with money. They are also paying with the data and know-how that make their companies unique. That trade, he says, is neither fair nor safe.
The warning adds a powerful voice to a growing debate inside Silicon Valley. For months, tech investors and enterprise software leaders have worried that the largest AI labs are behaving like Trojan horses. Startups and established companies use models from labs such as OpenAI and Anthropic to run chatbots, analyze documents, automate workflows and build new products. Every time they do, the labs can collect information about those companies. The fear is that AI model makers could use that information to build competing products or share insights with other customers.
Nadella had not previously joined those warnings in such direct terms. Now he has, and his blog post is being read as a major statement about the future of enterprise AI.
Key facts from Nadella’s warning
- Nadella says AI customers pay twice: once for tokens and again with proprietary knowledge.
- He warns that models learn from prompts, tool use and corrections, creating institutional know-how that could benefit competitors.
- He argues that if AI makers can train on public internet data, users should have fair rights to distill or study the models.
- He calls on enterprises to retain ownership of their data and build orchestration layers that allow easy switching between AI providers.
- He says the kind of knowledge companies feed into models is “the kind of knowledge a competitor could never buy.”
What Nadella means by “paying twice”
Nadella writes that AI buyers pay for intelligence twice. The first payment is the token price, the fee charged every time an AI model processes a request. The second payment is far more subtle. To get useful results from a model, a company must reveal context about its business. It must share internal documents, customer data, product plans, technical documentation and operational details. The AI model uses that information to generate answers, but the model provider also gains visibility into the company’s inner workings.
“You essentially pay for intelligence twice, once with money, and again with something even more valuable: the proprietary knowledge you must reveal to make that intelligence useful,” Nadella wrote.
He goes further. The more a company wants the model to perform, the more knowledge it must feed into the system. A generic AI model might be useful for common tasks, but a model that understands a company’s specific products, customers and processes requires deep customization. That customization becomes a data transfer from the enterprise to the model provider.
The danger of “exhaust” data
Nadella argues that the most sensitive information is not necessarily in training documents. It is in the behavioral trail created by people using AI tools. He calls this “exhaust.” Every prompt, every correction, every approval or rejection teaches the model something about how the business works.
“Models learn from ‘exhaust,’ the prompts people write, the tools agents use, and especially the corrections people make when the model is wrong. Every correction is distilled into institutional know-how,” he wrote.
This is the kind of knowledge that cannot be bought in a market or replicated through public research. A competitor would need years of operational experience to understand how a company makes decisions. If an AI lab collects that knowledge, it could potentially package it in ways that undermine the original company’s advantage.
The distillation debate
Nadella’s proposed remedy is rooted in the concept of distillation. In the AI world, distillation means using the output of one model to train another model, usually a smaller and cheaper one. Model makers often restrict this practice in their terms of service. They argue that allowing competitors to distill their models would let them profit from the massive investment required to build frontier AI systems.
Nadella sees an inconsistency. AI companies are happy to use public data, including copyrighted and proprietary content scraped from the internet, to train their models. But they do not want users to study their models with the same freedom. He finds this hypocritical.
“While the great innovation that comes from model providers having fair use rights to train models on public data is needed, I find it ironic that the status quo is to then turn around and impose restrictive terms on distillation,” Nadella wrote.
The debate is not theoretical. In February, Anthropic accused Chinese open source model developers of sending millions of prompts to Claude in an effort to improve their own models. Anthropic urged the U.S. government to consider export controls. That dispute shows how commercially important distillation has become.
A solution that favors Microsoft’s cloud
Nadella’s advice to enterprises reflects his position as the head of Microsoft, one of the world’s largest cloud providers. He urges companies to retain ownership of all data created through AI use, including prompts, feedback and model outputs. He also wants them to build “proprietary learning environments” in the cloud, where their data is already likely stored. Microsoft’s Azure cloud is an obvious beneficiary of that advice.
In addition, Nadella encourages companies to build orchestration layers. These are software tools that let a company switch between AI models from different providers without being locked into one vendor. AI gateways and model routers have become increasingly popular as enterprises try to avoid vendor lock-in. They allow companies to choose the best model for each task, negotiate better pricing and preserve the ability to move workloads elsewhere.
Although Nadella does not use the phrase “open source” in a direct call to action, the subtext is clear. Companies that want to retain control of their data can avoid proprietary model makers altogether by using open source models. Open source models can be installed on a company’s own servers or in a private cloud, where the data and the model remain under the company’s control.
Enterprises are already moving
There is evidence that the shift is already underway. Idit Levine, founder and CEO of Solo.io, a company that makes networking and security software for managing AI systems, says her customers are increasingly choosing open source models for on-premises deployment. After experimenting with proprietary models, they begin to realize that open source alternatives can deliver roughly 90 percent of the capability at a much lower cost.
“Can I take an open source model and run it on-prem? It will do almost 90% of what the big one’s doing. It will cost way less,” she said.
Solo.io’s technology was selected last year to power the Linux Foundation’s Agentgateway project. The company counts T-Mobile, ADP and SAP among its customers. Levine says the movement toward on-premise open source models is becoming the next big wave in enterprise AI.
Other companies see the same trend. Vercel, a platform for building and hosting websites, has added AI model-switching tools. OpenRouter helps developers route requests across different AI models. Both have reported surges in traffic to open source models. Last month, open models accounted for 29 percent of all traffic routed through Vercel’s gateway.
What this means for the AI industry
Nadella’s warning is notable because Microsoft has invested billions of dollars in OpenAI and has a close relationship with Anthropic. His message could encourage more enterprises to question whether proprietary AI providers are the right long-term home for their most valuable data.
It also puts pressure on AI labs to reconsider their data policies. If enterprise customers begin to insist on data ownership, no-use clauses and distillation rights, model makers may need to change their terms. Some may try to offer private deployments or data isolation. Others may push back and defend the need to learn from user interactions in order to improve their models.
The larger question is who owns the intelligence created when a company applies its knowledge to an AI model. Nadella argues that the answer should be the company, not the model provider. “In consuming intelligence, you are creating intelligence. And what you create should belong to you,” he wrote.
Source: TechCrunch News