Nadella named the trap. To make a model useful you feed it the knowledge that makes you unique, and it leaks back one correction at a time. His fix is a trust boundary you own. Here is where that boundary lives in your stack, and what governs the meaning inside it.
"You essentially pay for intelligence twice, once with money, and again with something even more valuable: the proprietary knowledge you must reveal to make that intelligence useful."Satya Nadella, CEO of Microsoft. July 2026
The classic problem exposed the seller. AI moves the exposure to the buyer, and it compounds every time you use what you bought.
In 1962 Kenneth Arrow described a problem at the heart of any market for information. Its value to the buyer is not known until the seller reveals it, but once revealed the buyer has it for free. The seller is the one at risk. Patents and NDAs exist to let an inventor show an idea without giving it away.
Nadella’s argument is that AI flips the vulnerability. Now the buyer is exposed. To make a model useful on your work you have to feed it the proprietary knowledge that makes your work valuable, and the better you want it to perform, the more of that knowledge you hand over. You pay once in cash and again in the context you reveal. Over time the asymmetry widens: the provider learns more about you with every session, while you learn almost nothing about what it takes in return.
The leak is not a single document walking out the door. It is diffuse. Models learn from what Nadella calls exhaust: the prompts your people write, the tools your agents call, and especially the corrections your experts make when the answer is wrong. Each correction is a small piece of institutional judgment, the kind a competitor could never buy, distilled into a rented system trace by trace and eval by eval.
"In consuming intelligence, you are creating intelligence. And what you create should belong to you."
Satya Nadella, CEO of MicrosoftHis prescription is not more data protection. It is a trust boundary: a hard line inside the enterprise across which nothing crosses without consent, not prompts, not traces, not evals, not adapted weights, not memory. Inside that boundary an organization’s data and learning are supposed to accumulate and compound as an owned asset. That is the right idea.
The practical question he leaves open is where the boundary sits in a real stack, and what governs the meaning of the data inside it so an agent gives the same answer your business would. That is an architectural requirement, not a policy. The sections below take his five tests, Control, Capability, Choice, Cost, and Compound, and show what each demands in practice.
Every prompt, tool call and correction carries your judgment. In consuming intelligence you create it, and unless you decide otherwise it stays on someone else’s infrastructure.
Think about what a good AI answer requires from you. A question, and also the context that makes the question answerable: how your business defines its terms, which system is authoritative for which number, the historical exceptions that only live in your team’s heads. Nadella’s point is that this context is the asset, and the model needs it to be useful. You cannot get the value without revealing the thing that creates the value.
The corrections are the sharpest example. When a senior analyst tells the model "no, revenue here means net of returns for the fiscal quarter ending March 31," that is not a prompt. It is a piece of your operating knowledge, the product of years of judgment, handed to a system in a form it can absorb. Multiply that across six thousand employees and a year of usage, and you have transferred a meaningful part of how your company thinks, without a line item ever appearing on an invoice.
This is why the problem is easy to miss. A single confidential file leaving the building triggers alarms. Ten thousand small corrections, each individually trivial, do not. They leave as ordinary usage, and the aggregate is a map of your judgment. If your knowledge is only ever expressed as corrections to a model you do not control, then your most valuable context has no home you own. It exists as weights and history on someone else’s infrastructure, and the moment terms change, it does not come with you.
Fair use lets providers train on public data. The status quo then restricts what you can do with your own usage. That imbalance decides who compounds.
Nadella points to an irony. The industry won broad rights to train on public data as fair use, which enabled the current generation of models. The same regime then imposes restrictive terms on distillation while reserving the right to learn from customer usage and interaction data. Learning is permitted in one direction and constrained in the other, and direction is what determines where value accrues.
This is not abstract. In 2026 OpenAI began closing self-serve fine-tuning: no new organizations, and an end to new fine-tuning job creation for existing customers by January 2027. Whatever the business reasons, the practical effect for a buyer is that the ability to shape a model on your own data can be narrowed on a timeline you do not set. If your institutional knowledge only exists as adaptations inside that provider, your leverage erodes exactly as your dependence grows.
Every re-query ships raw organizational context outside your boundary, where you cannot take it with you. LazyFox abstracts your data at indexing, so your actual business data never reaches a model, at setup or after.
Nadella’s defense is to keep the definitions of "good" on your side: private evals that run against your real internal outcomes, plus ownership of your memory, traces, and the right to use model outputs from your own tasks.
"What the technical customers want is control over their compute, their models, their data stack, and their alpha. They want to know they own the means of production, and it’s not being transferred to someone else."
Alex Karp, Palantir, quoted in Nadella’s essayLazyFox puts that boundary around meaning. Definitions, business rules and the corrections your experts make are versioned in a layer the company owns, and the model receives governed queries built from abstracted data, never the data itself.
Nadella’s second test asks whether you can tell if a model is getting better at your work, not at someone else’s benchmark.
Public benchmarks cannot answer that question, because they don’t know what revenue means in your company. A private eval needs a fixed answer to check against, and that answer has to come from definitions you own and version. When the definition of an active customer is code, "did the new model get this right" becomes a query rather than a debate.
The same definitions catch a quieter failure. When a term drifts, because a schema change in SAP alters the data behind a metric or two systems start defining it differently, LazyFox flags which term is diverging and in which system, and re-enriches only the affected slice. Your evals keep measuring against the business as it is now.
Nadella’s Choice test: if any one model were taken away, could you still operate and optimize for your evals using another? That requires decoupling meaning from the model.
The way to keep the model interchangeable is to move the layer that holds your meaning out of the model entirely. Definitions, evals and context become governed artifacts you own, and models become engines that run against them. Because that layer is independent of the model, you can run different agents on different models, each chosen for its task, all reading the same governed definitions.
A replaceable model is only half of Choice. The answer also has to stay the same when the model changes. If "revenue" is resolved inside each model’s context, two models give two answers. If it is resolved once, by context, in the governed layer, every model runs the same query and returns the same number. Our piece on Nadella’s learning loop walks through that reconciliation across four systems.
Nadella’s fourth test is about who captures the savings as models get cheaper.
Every call that ships your definitions to a model pays for the same context again. Resolve the meaning once, in a layer you own, and the model receives a governed query instead of a briefing. The cost of the millionth question stops scaling with how much context the model has to read, and a cheaper model can take over a task the moment it is good enough, because nothing about your business has to be taught to it first.
Nadella’s fifth test is the point of the other four: bring them together and the learning loop hill-climbs inside a boundary the firm owns.
Nadella describes the goal as a "hill climbing machine": every workflow that runs deepens the organization’s knowledge and makes the next one better and cheaper. The loop exists in any real AI deployment. The question is who it compounds for.
If each correction only lives as history inside a rented model, it compounds for the provider. If it refines a definition in a layer you own, it compounds for you, and it survives the next model change. We walked through what that looks like over the first two years in The Learning Loop Is the IP.
Separate what you already own from what you are quietly renting. Five questions do most of the work.
Score these separately from model quality. A better model does not answer any of them. The layer that does is the one that decides whether you are using a model, or paying it in the knowledge that makes you unique.
In the cloud era enterprises accumulated data. In the AI era they accumulate learning. The boundary has to evolve from protecting information to protecting the mechanism that learns.
Nadella is right that in the AI era enterprises accumulate learning as well as data, and that the trust boundary has to protect the mechanism through which a company learns, adapts, and compounds intelligence. If learning flows in only one direction, value converges toward the owners of the learning infrastructure rather than the creators of the knowledge. That is the trajectory the current regime is on, and it is already visible.
The part left to you is implementation. A trust boundary is only real when it is a layer you own: one that governs meaning, indexes context once, and keeps your definitions and evals as company assets while the models underneath stay interchangeable. A clause in a contract does not do this. A layer does.
"In the cloud era, enterprises accumulated data. In the AI era, they accumulate learning. The trust boundary must evolve accordingly."
Satya Nadella, CEO of MicrosoftLazyFox is built to be that layer: a semantic governance layer that sits above a company’s existing data stack, encodes institutional knowledge in a form the organization owns and controls, and makes it compound with each use without ever requiring it to leave their infrastructure. Your data is indexed once and abstracted with probabilistic methods, so your actual business data never reaches a model. Every request runs from governed code. Cross-system conflicts are resolved inside the boundary before any query goes out. Semantic drift is detected before it propagates into outputs. The model executes. Your data and the meaning stay inside.
That is the difference between using a model and giving up the knowledge that makes you unique. It is also the reverse information paradox, answered: you can consume intelligence without handing over the intelligence you create.
"A company should be able to use a model without giving up the knowledge that makes it unique. That is the reverse information paradox we need to confront."
Satya Nadella, CEO of Microsoft, July 2026This post responds to Satya Nadella's July 2026 essay on the reverse information paradox: Arrow's information paradox exposed the seller, while AI exposes the buyer, who pays once in cash and again in the proprietary knowledge revealed to make a model useful. It walks through Nadella's five tests (Control, Capability, Choice, Cost and Compound) and what each demands of an enterprise stack.
A governed semantic layer is the trust boundary in practice: definitions, evals and corrections stay versioned in a layer the company owns, the model receives governed queries built from abstracted data rather than the data itself, and any model can be swapped without losing the institutional knowledge.
LazyFox holds your definitions, evals, and context inside a boundary you control, indexed once from your existing stack, while the model underneath stays interchangeable. It connects read-only. Nothing migrates.