Microsoft's CEO warns companies are paying for AI twice, once in cash and once in secrets

Satya Nadella says every prompt, correction and workflow businesses feed into AI models is quietly training the companies they pay. He wants enterprises to take back control.

AI2Day Newsdesk· 3 min read
Full-frame photoreal editorial shot of a modern server room aisle at night, rows of dark racks with soft blue and amber status lights receding into the distance
Share

Key points

  • Microsoft CEO Satya Nadella published a blog post on Monday warning that enterprises unknowingly hand over proprietary business knowledge every time they use a third-party AI model.
  • Nadella argues that the prompts, corrections and workflows companies feed into AI systems become training data that makes the model smarter, potentially at the customer's expense.
  • Open models running on a company's own servers accounted for 29% of all traffic through Vercel's AI routing service last month, suggesting a real shift is already underway.
  • In February 2025, Anthropic accused Chinese open-source AI developers of sending millions of test prompts to its Claude model to copy its behaviour into cheaper alternatives.

Satya Nadella runs Microsoft, the company that has poured billions of dollars into OpenAI and also owns a stake in Anthropic. So when he tells enterprises to be careful trusting the very AI labs he has backed, people pay attention.

In a blog post published Monday, Nadella laid out a worry that has been circulating quietly in boardrooms for a while. Companies pay for AI tools in money, he says. They also pay in something they rarely notice: the specific, hard-won knowledge of how their business actually works.

Every time a staff member types a prompt into an AI tool, every time they correct an answer that comes back wrong, the model learns something. It learns your terminology, your edge cases, your standards. Nadella calls this knowledge the "exhaust" of AI use. It is also, he argues, some of the most valuable information a company owns.

"Every correction is distilled into institutional know-how," he writes. "The kind of knowledge a competitor could never buy."

His concern is that the terms AI providers attach to their services often let them learn from that exhaust. A company feeding its internal processes into an AI model could, in effect, be training a future competitor.

Should businesses be worried about this?

Yes, but the risk is practical, not theoretical. AI providers do differ in what their terms allow. Some contractually promise not to train on your data; others reserve the right to do so unless you opt out. Most businesses have never read those clauses.

Nadella also raises a separate point about fairness. AI labs argue they have a legal right to train their models on publicly available internet data. He finds it inconsistent that the same labs then write terms forbidding their customers from doing something similar, a practice called "distillation", which means using a model's own outputs to train a smaller, cheaper model. Anthropic made headlines in February by accusing Chinese AI developers of doing exactly that to its Claude model, and calling for tighter government controls.

His proposed fix is predictable for the CEO of a cloud computing company. He wants enterprises to keep ownership of their prompts and feedback, build their systems so they can swap between AI providers easily, and run sensitive workloads on private infrastructure. Conveniently, private infrastructure often means Microsoft Azure, Microsoft's cloud platform.

But the broader market is already moving this way regardless. Idit Levine, CEO of enterprise software company Solo.io, told TechCrunch she sees customers switching from big proprietary models to open-source models, AI systems whose underlying code is publicly available, installed on servers the company physically controls. Open models now handle 29% of traffic through Vercel's AI routing tools.

What should ordinary employees take from this? Ask your IT team whether your company has reviewed the data terms of every AI tool staff use. The answer will probably surprise someone.

Watch for: AI service agreements that include phrases like "we may use your data to improve our services" without a clear opt-out. That clause, buried in the small print, is the mechanism Nadella is warning about.

© 2026 AI2Day