Satya Nadella warns enterprises not to leak “token capital” to frontier AI labs
Microsoft’s CEO lays out a “reverse information paradox” and argues for hard boundaries around AI learning and exhaust.

Satya Nadella, Microsoft CEO and chairman, used a long-form X post to warn AI using enterprises about a “reverse information paradox” and the risk of leaking proprietary business knowledge. The implication for decision-makers: enterprise AI governance is not enough, because models can absorb “exhaust” over time and reveal hard to replace organizational intelligence.
Satya Nadella, Microsoft CEO and chairman, is telling enterprises to guard their proprietary knowledge from frontier AI labs. In a long-form post on X, he warned of what he called the “reverse information paradox,” where buyers of AI pay twice: once with cash and again “with something even more valuable,” the business knowledge needed to make an AI model worth using. He then adds the uncomfortable part, the seller learns more about the buyer as the buyer uses the purchased system, while the buyer learns very little about what the seller is learning in return.
Nadella’s point is not just that data governance matters, but that the AI value chain itself turns normal enterprise activity into a leaking mechanism. He argues that models learn from “exhaust,” including the prompts people write, the tools agents use, and especially the corrections people make. That “trace by trace, correction by correction, eval by eval” accumulation is, in his framing, organizational intelligence competitors could not easily buy outright and can absorb in ways that feel “almost imperceptibly.” So if you are treating “AI safety” as a checkbox for safe inputs, his post is essentially saying: you are missing how learning happens in practice.
This warning lands in a politically charged moment for Microsoft and its partners. The Register notes the irony is “thick,” because Microsoft has been pushing AI that “slurps up business data,” and Redmond helped kick off much of this generative AI cycle by investing billions into early leader OpenAI. Azure was the former exclusive cloud home for ChatGPT, and Microsoft leadership arguably helped get Sam Altman’s job back when OpenAI ousted him in 2023. The relationship later strained, and Microsoft and OpenAI loosened several exclusivity provisions in early 2026.
Why this matters to executives now is that the problem Nadella points at is already familiar in enterprise AI rollouts: internal data exposure through broad access rights and weak governance. The Register ties this directly to earlier enterprise Copilot concerns, including that in 2024 a number of large organizations paused or restricted Microsoft Copilot deployments over data governance and internal access rights. Enterprise data security outfit Securiti told The Register in 2024 that about half of the more than 20 chief data officers it polled had grounded Copilot deployments, either switching the assistant off or severely restricting what it could access. The concern was especially acute in organizations with years of accumulated SharePoint and Microsoft 365 permissions, where overly broad access rights could expose sensitive information through Copilot.
But Nadella is effectively moving the argument one level deeper. His claim is that protecting data “isn’t even enough for a business to stay safe in the AI age,” because the knowledge generated through AI interactions should belong to the company that creates it, not to the vendor or the hosting provider that trained or improves its systems. He writes that enterprises need a “real trust boundary” for both human capital and “token capital” to compound, and describes an ideal solution: “a hard boundary across which nothing crosses, not even the intelligence exhaust, without consent.” The direction of travel here is clear: welcome to a “post-cloud era” in which AI infrastructure comes back inside your own network.
To solve the “reverse information paradox,” Nadella’s post also calls for operational changes that go beyond tightening who can read what. He even suggests enterprises should build their own proprietary AI learning environments “within the tenant boundary.” According to The Register, his additional recommendations include creating private evaluation systems and retaining ownership of organizational AI memory. He also suggests decoupling the orchestration layer from any particular AI model, describing “your own continuous learning loop.” The message to leadership is that if you want to use a model without surrendering the knowledge that makes your business unique, you may need to treat model consumption and model learning as separate, contractually and technically constrained activities.
Microsoft’s spokesperson tells The Register that this goes beyond good data governance and frames it as a structural issue with the current generally accepted model of AI business, where companies rely on hosted services. They add that “anyone and everyone using AI for business is at risk.” The spokesperson also points to Microsoft’s solutions to address the problems Nadella outlined: Copilot and Azure AI Foundry. The spokesperson characterizes these offerings as separating context, memory, and agent harnesses from AI models themselves, giving businesses an “additional layer of assurance” that their data is safe, and they also argue agent harnesses and memory should be independent of models. The spokesperson further argues for enterprise rights to their own usage data and model outputs.
Strategically, the biggest takeaway is uncomfortable for every buyer of frontier AI capabilities, regardless of who sells them. The Register lands on a blunt truth that Nadella’s argument depends on: frontier labs are processing valuable proprietary data, and that could come back to bite the businesses that supply it. In other words, “reverse information” is not just a theoretical concern. If AI learning draws from prompts, tool use, and corrections, then every enterprise that trains users into better asking, agentifying workflows, and iterating on outputs is also quietly feeding a learning system. The question for boards and CFOs is whether their current contractual and technical posture treats that learning as theirs to control, audit, and contain, or as a side effect that their business will have to endure later.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology

Nvidia and Wistron will build Blackwell AI servers in Texas, Nikkei Asia reports
A Texas manufacturing plan for Blackwell AI servers ties Nvidia's next platform rollout to Wistron's local capacity and supply chain risk.

Meta tests StoryKit bedtime stories in select regions to measure parent response
The experiment is regional, and the real question is how quickly parents adopt AI storytelling for kids.

Range Rover GT is not a Velar EV replacement, spy tests at Arctic Circle confirm
The EV plan is real, but the direction was misread for months. Here is the actual story.
