Microsoft chief executive Satya Nadella has issued a stark warning to companies that rely on proprietary artificial intelligence models. In a blog post published on Sunday, he argued that AI customers are paying twice for the same service: once through token fees, and again through the valuable business knowledge they reveal to model makers. The post adds a powerful voice to a growing debate about data ownership, competitive risk, and the economics of AI adoption.
Key facts at a glance
- Nadella warns AI customers pay for intelligence twice: in fees and in proprietary knowledge.
- AI models learn from user prompts, agent tool use, and corrections, which Nadella calls 'exhaust.'
- He argues it is hypocritical for model makers to train on public data while restricting distillation of their models.
- He recommends companies retain ownership of data and use orchestration layers to switch between models.
- Enterprises are increasingly turning to open source models on-premise for cost, control, and security.
- Open models accounted for 29% of traffic routed through Vercel's AI gateway last month.
The growing fear of AI's Trojan horse
For months, investors, executives, and technologists have warned that the big AI labs selling proprietary models could act like Trojan horses. The idea is simple: startups and enterprises feed their most sensitive information into these systems in order to get useful results. In the process, the model maker gains an unprecedented view of the customer's business strategy, customer relationships, pricing, product plans, and operational weaknesses. The fear is that this knowledge can be used later, either to compete directly with the customer or to benefit a rival.
That warning has come from prominent figures across the industry. Venture capitalist Jason Calacanis has spoken publicly about the risk of handing proprietary data to AI providers. Palantir CEO Alex Karp has also sounded alarms about the concentration of power in a handful of AI labs. Until now, however, the chief executive of a major AI investor had not joined that chorus in such direct terms.
Paying twice
Nadella's central argument is that companies are not just paying for compute and tokens. They are also paying with something far more valuable: the private knowledge they must share to make the model useful. The better the model performs, the more the company has to teach it. That means writing detailed prompts, providing proprietary documents, and showing the model where it went wrong.
He calls this 'exhaust' — the byproduct of every interaction with an AI system. Prompts, tool choices, feedback, corrections, and re-runs all create a trail of institutional knowledge. Over time, the model absorbs how the company thinks, how it solves problems, and how it makes decisions. That is precisely the kind of intelligence that gives a business its edge.
'Models learn from exhaust,' Nadella writes. 'Every correction is distilled into institutional know-how.' He argues that a competitor could never buy that knowledge openly, and yet companies are giving it away in daily transactions with model providers.
The distillation debate
Nadella also takes aim at the asymmetry in how AI models are trained. Model makers have used massive amounts of public data from the open internet, often under the banner of fair use. But when others want to study those models in return — a process known as distillation — the model makers often impose restrictive terms. Distillation uses a model's own outputs to train a new, cheaper model or to better understand the original model's behavior.
In February, Anthropic accused Chinese open source models of sending millions of prompts to Claude as a way to improve their own models. Anthropic urged the U.S. government to tighten export controls. Nadella sees this as hypocrisy. If AI labs can freely train on the world's collective knowledge, he argues, then enterprises should have similar latitude to learn from the models they use.
'While the great innovation that comes from model providers having fair use rights to train models on public data is needed, I find it ironic that the status quo is to then turn around and impose restrictive terms on distillation,' he writes.
Nadella's prescription
Nadella's solution is not to reject AI. He says companies should retain ownership of their data, including prompts, feedback, and interaction logs. This requires building what he calls 'proprietary learning environments' in the cloud, where the data is already likely stored. He also urges companies to add an 'orchestration layer' so they can switch between models from different providers instead of being locked into one vendor. AI gateways, which provide this switching capability, have grown in popularity as organizations look for flexibility and leverage in their AI spending.
Although Nadella does not explicitly say 'open source,' the implication is clear. Open source models give companies a path to ownership and control. They can be installed on private infrastructure, adapted to specific needs, and inspected for security and bias. They also cannot be used by a third-party vendor as a source of competitive intelligence.
Enterprises are already moving
The shift Nadella describes is already underway. Large companies, especially those with their own data centers, are increasingly moving to open source models installed on their own servers. The motivation is cost as much as control. Open models can often perform close to the level of the largest proprietary systems, while lowering per-token expenses and avoiding vendor lock-in.
Idit Levine, founder and CEO of Solo.io, a company that makes networking and security software for enterprise AI systems, says she sees this change with her own customers. After experimenting with proprietary models, they begin to ask whether an open source model can do the same work in-house. 'Can I take an open source model and run it on-prem? It will do almost 90% of what the big one's doing. It will cost way less,' she says. 'They understand that, and they can control it.'
Solo.io's technology was selected last year to power the Linux Foundation's Agent Gateway project. The company's customers include T-Mobile, ADP, and SAP. Levine is not alone in predicting that on-premise open source models will become the next major wave in enterprise AI use.
Infrastructure providers are seeing the same trend. Vercel, which is best known as a platform for building and hosting websites and has recently added AI model-switching tools, says open models accounted for 29% of all traffic routed through its gateway last month. OpenRouter, a company that helps developers route requests across different AI models, is also reporting a surge in open source model usage. These numbers suggest that the appetite for alternatives to proprietary AI is more than hypothetical.
The stakes for business leaders
For company lawyers, chief information officers, and product leaders, the warning is a reminder that AI adoption requires more than just technical integration. Legal teams still face unclear rules about what data a vendor can use to improve its models. Procurement departments may not realize that standard terms can give a model maker broad rights to customer inputs. Even when a contract protects a company's data today, the model provider could change its terms after the customer has become dependent on the service.
Security is another concern. If every prompt is stored, reviewed, or used for training, then an enterprise is indirectly extending its attack surface. A breach at the AI provider could expose the customer's confidential strategy. A legal subpoena to the provider could also implicate customer data. These risks are forcing boards to ask harder questions about which AI tools should have access to which data.
There is also the issue of competitive dynamics. The more an AI model knows about a company, the more valuable it becomes to the model maker. It could be used to build industry benchmarks, coaching products, or even a direct competitor. Nadella's argument is not just about privacy; it is about the long-term distribution of economic power.
What this means for the AI industry
Nadella's warning carries unusual weight because Microsoft has invested heavily in the very companies that sell proprietary models. The company is a major backer of OpenAI and has also worked with Anthropic. His decision to urge enterprises to be cautious about proprietary models signals a possible turning point in the industry. It may reflect Microsoft's desire to build trust with enterprise customers as it expands its cloud business, but it also aligns with a broader movement toward data sovereignty.
For startups and enterprises, the practical advice is to treat AI as a resource that must be managed like any other critical business system. That means knowing where data flows, what the model provider can access, and what would happen if the relationship ended. It also means demanding clear terms around data use, training, and retention.
The debate over fair use and distillation is unlikely to be resolved quickly. AI labs argue that they need protections to invest in expensive models. Customers argue that they should not have to surrender their most valuable knowledge to use a tool. Governments are beginning to enter the conversation, with regulators in Europe and the United States grappling with how to balance innovation, competition, and privacy.
Nadella's message is likely to accelerate the search for alternatives. If the chief executive of one of the largest technology companies in the world tells customers to be wary, the market will listen. The growing popularity of open source models and on-premise deployments is evidence that the enterprise landscape is already changing. 'In consuming intelligence, you are creating intelligence. And what you create should belong to you,' Nadella writes.
Source: TechCrunch News