
Microsoft chief executive Satya Nadella has issued a stark warning to organizations that rely on commercial AI models: they are paying for the same intelligence twice. The first payment is the fee they hand over for tokens and API usage. The second, more costly payment comes in the form of proprietary knowledge that companies reveal each time they feed a model internal data. Nadella made the case in a Sunday blog post that has rattled the enterprise AI world.
Key facts
- Microsoft CEO Satya Nadella says AI buyers pay for intelligence with money and with proprietary knowledge.
- He warns that model makers can learn from customer prompts, agent tools, and corrections, turning that data into institutional know-how.
- Nadella argues it is hypocritical for AI labs to train on public data while restricting others from distilling their models.
- He advises companies to retain ownership of data, build proprietary learning environments, and use orchestration layers to switch between models.
- Enterprises are increasingly moving to open source models installed on their own servers, according to industry executives.
Nadella's warning
Nadella joins a growing list of prominent technology figures who have warned about the risks of relying on proprietary AI models. Venture capitalists such as Jason Calacanis and Palantir CEO Alex Karp have already expressed similar concerns. Their central fear is that AI labs act like Trojan horses: startups and enterprises use models from companies like OpenAI and Anthropic, and in the process those labs gain access to sensitive business information. That information could eventually be used by model makers to build competing products or services.
Nadella's blog post sharpens that warning with a simple economic framing. He writes that buyers pay for intelligence twice: once with money and once with something more valuable — the proprietary knowledge they must reveal to make the intelligence useful. He also notes that the better a company wants a model to perform, the more knowledge it must feed the model.
This is not a hypothetical concern. Modern AI systems are trained and customized through interactions. Every prompt, every tool call, and every correction made by human users helps refine the model. Nadella says models learn from what he calls "exhaust" — the prompts people write, the tools agents use, and especially the corrections people make when the model is wrong. Each correction is distilled into institutional know-how. That knowledge, he argues, is the kind a competitor could never buy, and yet enterprises are handing it over without fully understanding the cost.
The distillation debate
Nadella also waded into one of the most contentious debates in artificial intelligence: model distillation. Distillation is the practice of using one model's outputs to train another model, often a smaller and cheaper one. It has become a key technique for improving open source models and reducing the cost of AI inference.
The practice has already caused friction. In February, Anthropic accused Chinese open source models of sending millions of prompts to Claude in order to improve their own systems. Anthropic urged the U.S. government to crack down on the practice through export controls. That moment illustrated how sensitive AI labs are about protecting their models from being copied or imitated.
Nadella argues that model makers cannot have it both ways. They freely train on the world's public data, often without explicit permission, and yet they impose restrictive terms on distillation. He writes that while fair use rights for training on public data are needed, it is ironic that the status quo then turns around and imposes restrictive terms on distillation. His point is straightforward: if it is fair for AI companies to learn from the collective work of the internet, it should be fair for enterprises to learn from AI models they use and pay for.
Data ownership and "orchestration layers"
Nadella's proposed solution is exactly what a chief executive of a giant cloud provider would suggest. He urges companies to retain ownership of their data, including prompts, feedback, and interaction logs. He wants them to build what he calls "proprietary learning environments" on the cloud — a place where their data already lives and where they can control how AI models learn from it. That environment, naturally, could be Microsoft's Azure cloud.
He also recommends building "orchestration layers" into enterprise AI systems. An orchestration layer allows companies to switch between different AI models from different providers without being locked into one ecosystem. This kind of AI gateway approach has become increasingly popular. Companies like Vercel and OpenRouter already help developers route requests across multiple models, and many enterprises are adding similar layers to reduce their dependence on any single AI vendor.
Nadella never explicitly says "open source" in his blog post, but the implication is clear. For companies to truly own their data and control their AI destinies, they need alternatives to proprietary models. Open source models offer a way to keep data on-premises, customize behavior, and avoid the risk of feeding competitive secrets to an AI lab.
The shift to on-prem open source models
There is growing evidence that enterprises are already moving in this direction. Idit Levine, founder and CEO of Solo.io, a company that makes networking and security software for enterprise AI systems, says she is seeing exactly this shift play out with her own customers. After experimenting with proprietary model makers, they start asking themselves whether an open source model running on their own premises can do almost 90 percent of what the big models do at a fraction of the cost. Levine says customers understand that they can control the model and keep their data inside their own infrastructure.
Solo.io's technology was selected last year to power the Linux Foundation's Agentgateway project. The company counts T-Mobile, ADP, and SAP among its customers. Levine predicts that on-premise open source models will become the next big wave in enterprise AI use, especially as organizations become more sensitive about where their data flows.
Other companies are seeing the same trend. Vercel, the web development platform that recently added AI model-switching tools, reports that open models accounted for 29 percent of all traffic routed through its gateway last month. OpenRouter, which helps developers send requests across different AI models, has also seen a surge in traffic to open source models. These numbers suggest that the open source movement is no longer a niche preference among hobbyists. It is becoming a mainstream enterprise strategy.
Why this matters
Nadella's intervention is especially significant because Microsoft has invested heavily in both OpenAI and Anthropic. He is not an outside critic attacking the AI industry; he is a central player with financial ties to some of the largest proprietary model makers. His willingness to publicly encourage enterprises to question those models signals a shift in the competitive landscape.
One of the underlying issues is trust. Enterprises are being asked to put their most sensitive business logic into systems that are operated by third parties. This is similar to an earlier era of cloud computing, when companies worried about whether their data was safe in someone else's data center. Over time, many companies embraced the cloud for convenience and scale. But AI is different because the value of the data goes beyond storage. The data is used to train models, refine outputs, and build knowledge that can outlive the customer relationship.
Nadella's argument suggests a new model of AI consumption. Instead of renting intelligence from a black box, companies should build their own AI capabilities using open source components and their own data. They should keep the learning process inside their own controlled environment. They should treat AI models as infrastructure rather than as strategic partners with conflicting interests.
This is not just a philosophical position; it has practical implications for procurement, security, and competitive advantage. Companies that cede control over their data may find themselves training a competitor that can eventually offer a better product to their own customers. The model maker could learn the same patterns, insights, and corrections and then transfer that knowledge across its entire customer base.
In his blog post, Nadella sums up the challenge with a memorable line: "In consuming intelligence, you are creating intelligence. And what you create should belong to you." That sentence captures the essence of the debate. Every company that uses AI is not just consuming a product; it is co-creating something of value with the model provider. The question is who gets to keep that value. Nadella has made his answer clear, and a growing number of enterprise technology leaders appear to agree.
Source:TechCrunch News
