The CEO of Microsoft just told his own customers to think twice about how much they hand over to AI.
In a recent blog post, Satya Nadella argued that companies using AI are essentially paying for it in two ways. Once with the subscription fee, and again with the proprietary knowledge they have to share to make it useful. Every prompt, every document uploaded for context, every correction someone makes when the model gets it wrong feeds back into how these systems learn.
"You essentially pay for intelligence twice, once with money, and again with something even more valuable: the proprietary knowledge you must reveal to make that intelligence useful," Nadella wrote, according to a TechCrunch summary of the post. "The better you get at using AI, the more of your institutional knowledge you transfer into models you do not own."
His mechanism for how this happens is what makes the argument land. Nadella describes models learning from what he calls "exhaust." That's the prompts people write, the tools their agents pick, and especially the corrections humans give when the model messes up. Each of those corrections gets distilled into something like institutional knowledge, except it isn't sitting inside your company anymore.
The odd part is who's making this case. Nadella runs the company that hosts ChatGPT on Azure and built Copilot to reach into your email, files, and Teams chats. He is warning about a problem he helped create, and Microsoft has quietly built the fix into its own product line. Purview DLP for Copilot can now scan prompts in real time and block employees from pasting credit card numbers, SSNs, or custom sensitive data into the assistant. If you were wondering whether the leakage problem is real, Microsoft built a whole product around solving it.
Palantir made the same argument this week, only louder. The company published a 9-point manifesto on X framing what it calls AI sovereignty as an existential question for enterprises. "Sovereignty is the precondition for choice," the company wrote. "Relinquishing sovereignty transfers the future choices of your institution to others, who are likely misaligned with your interests."
Akshay Krishnaswamy, Palantir's chief architect, put it in more practical terms. Since Palantir's first government deployment, he said, the software has had to work in environments where customers can't afford to leak anything to anyone. That framing is now bleeding into commercial customers who are realizing their AI vendor relationship looks a lot like a data-sharing relationship they never quite signed up for.
The concern isn't just American. Kai-Fu Lee, who runs Chinese AI lab 01.AI and used to head Google China, told Capgemini that sovereignty for most countries outside the US and China really comes down to two things. Control over the technology, and confidence that the data you feed it doesn't end up in someone else's model. His practical suggestion is that companies and governments take a leading open-source model and keep training it on their own language, values, and regulations, so the intelligence they build stays local.
That points to where a lot of enterprises are actually heading. Not away from AI, but toward AI they can host themselves, inspect, and keep off someone else's servers. The pitch from Nadella and Palantir is that the model you rent isn't really the moat anymore. The data you feed it is.

There's something almost funny about the same executives who spent two years telling boards to adopt AI or fall behind now telling those same boards to be careful what they feed it. But the shift is real, and it explains why the sovereignty conversation is getting louder just as open-weight models catch up on capability. If you can run something roughly as good on your own hardware, the question stops being who has the smartest model and starts being who ends up owning what you teach it. Nadella isn't wrong that you pay for AI twice. He also happens to sell you a way to pay less the second time.
