AI & Models
Satya Nadella warns companies against using proprietary AI models
Microsoft CEO Satya Nadella warned that companies using proprietary AI models essentially pay twice by exposing valuable proprietary data to potential future competitors.
Microsoft CEO Satya Nadella has warned that enterprises using proprietary AI models are effectively paying twice: once in money for token usage, and again by handing over proprietary business data that model makers could use to become competitors to their own customers. In a blog post published Monday, Nadella wrote: “You essentially pay for intelligence twice, once with money, and again with something even more valuable: the proprietary knowledge you must reveal to make that intelligence useful. The better you want the model to perform, the more of that knowledge you have to feed it!”
Nadella argues the risk compounds with use. Models learn from what he calls “exhaust” — the prompts people write, the tools agents use, and especially the corrections people make when a model gets something wrong — and every correction gets folded into institutional know-how that a competitor could never simply buy. He contends model makers can’t have it both ways: they claim fair-use rights to train on the public internet, yet impose restrictive terms on “distillation” — the practice of using a model’s own outputs to train a new, typically smaller and cheaper model — when enterprises might want to do the same with the model’s own behavior. He’s especially wary of model makers that reserve the right to learn from customer usage and interaction data.
The concern isn’t hypothetical. In February, Anthropic accused Chinese open source models of sending millions of prompts to Claude as a way to improve their own models. Nadella’s proposed fix leans toward giving companies “proprietary learning environments” built on the cloud — a suggestion worth noting given Microsoft sells cloud infrastructure through Azure and has itself invested in both OpenAI and Anthropic.
That tension is already reshaping enterprise buying. Idit Levine, founder and CEO of Solo.io, which makes networking and security software for managing AI systems, says she’s watching customers increasingly install open source models on-premises — running the software on their own local servers rather than through a model maker’s cloud. Enterprises are asking whether they can run an open source model on-prem instead, she says, since it will do almost 90% of what the big proprietary models do at a much lower cost, and they retain control of the data. Her company’s technology powers the Linux Foundation’s Agentgateway project and counts T-Mobile, ADP, and SAP among its customers.
Other platforms are seeing the same pull. Vercel and OpenRouter, both of which help developers route requests across different AI models, report a surge in traffic to open source options — open models accounted for 29% of all traffic routed through Vercel’s gateway last month.
Why it matters
Nadella’s warning exposes a structural tension at the heart of enterprise AI: the more useful a proprietary model becomes, the more of a company’s own knowledge it absorbs. That tension is already pushing enterprises toward open source models they can run and control on their own premises rather than proprietary systems whose makers could someday compete with them.