
In a surprising and strongly worded blog post published on Sunday, Microsoft CEO Satya Nadella has issued a stark warning to companies that rely on proprietary artificial intelligence models from major labs like OpenAI and Anthropic. His central argument is that these enterprises are unknowingly giving away their most sensitive business secrets while paying for AI services. Nadella, whose company Microsoft has invested billions in both OpenAI and Anthropic, now appears to be cautioning his own customers about the risks of locking themselves into such ecosystems.
The concern is not new. Venture capitalists like Jason Calacanis and Palantir CEO Alex Karp have previously voiced similar fears. But Nadella's entry into this debate carries immense weight given his position at the helm of the world's largest cloud provider and a major AI investor. He describes the situation as one where AI users, whom he calls 'buyers,' are effectively paying for intelligence twice. 'You essentially pay for intelligence twice, once with money, and again with something even more valuable: the proprietary knowledge you must reveal to make that intelligence useful. The better you want the model to perform, the more of that knowledge you have to feed it!' he writes.
Nadella elaborates that every interaction with a large language model contributes to its learning. This includes prompts written by users, the tools that agents use, and especially the corrections people make when the model produces wrong answers. 'Every correction is distilled into institutional know-how,' he warns. This knowledge, he argues, is 'the kind of knowledge a competitor could never buy,' yet enterprises are freely handing it over to model providers. The implication is that these labs could one day use that data to compete directly with their own customers, a scenario that would be catastrophic for many businesses.
To understand the full context of Nadella's warning, it helps to look at the broader AI landscape. The debate over model training data has been raging ever since the launch of ChatGPT in late 2022. AI labs have argued that they need fair use rights to scrape public internet data to train their models. Nadella supports this right, calling it 'great innovation.' However, he finds it 'ironic' that these same labs then turn around and impose restrictive terms on a practice called distillation. Distillation is the process of using a model's own outputs to learn how it works and to train a new, often cheaper, model. In February 2026, Anthropic accused Chinese open-source models of sending millions of prompts to Claude specifically for this purpose, and urged the U.S. government to crack down on export controls.
Nadella's point is one of fairness: model makers cannot have it both ways. They should not be allowed to freely train on the world's data while restricting others from doing the same to their models. He argues that companies should be allowed to distill these large models to create custom, proprietary versions that they control. The alternative, he warns, is a future where a handful of AI providers accumulate vast troves of corporate intelligence and use it to dominate industries.
So what does Nadella propose as a solution? Unsurprisingly, his answer aligns with Microsoft's cloud strategy. He urges companies to 'retain ownership' of their data, including prompts, feedback, and all interaction data. This means building what he calls 'proprietary learning environments' on the cloud—ideally on a platform where their data is already stored. That platform, of course, is Azure, Microsoft's cloud computing service. He also recommends building 'orchestration layers' that allow easy switching between different AI models from various providers, preventing vendor lock-in. Tools like AI gateways, which route requests across multiple models, have become increasingly popular for exactly this purpose.
While Nadella never explicitly uses the term 'open source,' it is an obvious subtext. Large enterprises, many of which still operate their own data centers in addition to using cloud services, are already moving toward open-source models that they can install on their own premises. Idit Levine, founder and CEO of Solo.io, a company that makes networking and security software for managing AI systems, says she sees this shift firsthand. 'Can I take an open-source model and run it on-prem? It will do almost 90% of what the big one's doing. It will cost way less,' she describes her customers' thinking. 'They understand that, and they can control it.' Solo.io's technology powers the Linux Foundation's Agentgateway project, and its customers include major enterprises like T-Mobile, ADP, and SAP.
The trend toward on-premises open-source models is not just anecdotal. Vercel, a platform for building and hosting websites that has added AI model-switching tools, and OpenRouter, a company that helps developers route requests across different AI models, both report a surge in traffic to open-source models. Last month, open models accounted for 29% of all traffic routed through Vercel's gateway. This suggests that enterprises are increasingly voting with their wallets, choosing cost-effective and controllable open-source alternatives over proprietary black boxes.
Nadella's warning comes at a time when Microsoft itself is deeply entangled with proprietary AI. The company has invested an estimated $13 billion in OpenAI and also has a stake in Anthropic. Its own offerings, such as Copilot for Office 365 and Azure AI services, rely heavily on these models. Critics might see his blog post as a nuanced attempt to guide customers toward Microsoft's cloud while also preparing for a future where open-source models dominate. After all, if enterprises build their AI environments on Azure using open-source models, Microsoft still wins through cloud revenue.
Yet the core of Nadella's message is hard to dismiss: 'In consuming intelligence, you are creating intelligence. And what you create should belong to you.' This principle strikes at the heart of the debate over data ownership in the age of AI. As more companies rush to adopt generative AI tools, the question of who truly owns the insights derived from these interactions becomes critical. Nadella's intervention may accelerate a shift that was already underway, forcing both AI labs and their customers to reconsider the terms of engagement.
For now, the smartest enterprises appear to be hedging their bets. They continue to experiment with proprietary models for specific tasks but are simultaneously building internal capabilities to run open-source models on their own infrastructure. This dual approach protects them from being held hostage by any single provider and ensures they maintain control over their most valuable asset: their proprietary knowledge.
Source:TechCrunch News
