Every prompt your organisation sends to a rented model pays a second invoice — not in cash, but in the proprietary knowledge you must reveal to make it useful. Naming that wound is not the same as treating it.
In July 2026, Satya Nadella wrote something most technology chief executives would prefer their customers never dwell on. Use an AI model you did not build, he argued, and you pay for it twice — once with money, and once with the proprietary knowledge you have to hand over to make it useful. He called it the Reverse Information Paradox, and the essay drew something on the order of ten million views.
It is a genuine insight, and it is worth stating precisely, because it inverts a piece of economics that has stood for sixty years. The Nobel laureate Kenneth Arrow described the seller of information as trapped in a dilemma: to prove the value of what they are selling, they must reveal it — and once revealed, the buyer has it for nothing. Nadella’s point is that AI flips that burden onto the buyer. To make a general-purpose model perform on your work, you must feed it your specifics: your data, your corrections, the way your experts actually reach a decision. The better you want it to perform, the more of your edge you have to give away.
But here is where I part company with the diagnosis, because a named wound is not a treated one. Nadella described the problem precisely and then prescribed a cure that, on inspection, routes back to his own cloud. That is not a knock on the man; it is the structural position of any vendor who sells you the model and the remedy in the same breath. The observation is real. The answer a vendor can offer is not the answer you need — because the answer you need is a control, and what they are selling is a better place to keep paying the invoice.
What actually leaves the building
Start with what is being spent. Every prompt an employee writes, every correction they make to a weak answer, every evaluation of which output was better — each is a small deposit of institutional know-how into someone else’s system. Call it intelligence exhaust: the residue of how your organisation actually works, accumulating on infrastructure you do not own. The asymmetry compounds quietly. The vendor learns more about how you operate with every session; you learn almost nothing about the model in return.
This is not hypothetical, and it is not rare. According to the data-security firm Cyberhaven, which analysed usage across 1.6 million workers, roughly one in nine things employees paste into ChatGPT is sensitive or confidential — strategy documents, client records, source code, regulated data. The most-cited illustration is the cleanest: in April 2023, engineers in Samsung’s semiconductor division pasted confidential chip source code and internal meeting notes into ChatGPT to debug and summarise them. As Bloomberg reported, Samsung responded within weeks by banning generative AI on company devices altogether — a blunt instrument reached for precisely because the firm had no finer one.
11%
of everything employees paste into ChatGPT is sensitive or confidential — strategy documents, client data, source code, regulated information.
Cyberhaven, analysis of 1.6 million workers, 2023
The policy that only watches
Confronted with this, most organisations reach for a document. A data-handling policy. A clause in the vendor contract. A reassuring line in the sales deck — “we don’t train on your data.” A memo instructing staff not to paste anything confidential. Each of these feels like a control. None of them is one.
A data-handling policy records the breach in the quarterly review, long after the knowledge has left. That is not a control; it is a witness. The contractual clause is a promise that can only be enforced after the fact, in a dispute, once the exhaust is already in the vendor’s loop and cannot be recalled. And “we don’t train on your data” is the referee paid by the team: the assurance you are asked to rely on comes from the party with the strongest commercial interest in your continued use, verifiable by you approximately never. The memo, meanwhile, is simply blind. According to LayerX’s enterprise research, the large majority of sensitive data pasted into AI tools flows through personal, unmanaged accounts — the exact traffic a corporate security stack cannot see. You cannot govern what you cannot observe, and you are not observing most of it.
A data policy that discovers the leak in the quarterly review is not a control. It is a witness — and a witness governs nothing.
82%
of sensitive data pasted into generative-AI tools flows through unmanaged personal accounts — the exact traffic a corporate security stack cannot see.
LayerX, Enterprise AI Security Report, 2025
The boundary is the control
A real control does not record the leak. It refuses it, at the instant of action, before the context leaves your perimeter. This is the same distinction that separates a memo warning about a defect from the cord on a factory line that actually stops it: one observes, the other binds. For enterprise AI, the binding control is a boundary that lives in the runtime rather than the policy binder — a gate every prompt must pass through that inspects what is about to leave and refuses those carrying what must not.
The components are not new — that’s the point: nobody has to invent anything. Open-weight models can be hosted inside your own environment, so the capable model runs on your own ground rather than someone else’s. Confidential computing, so the data is protected even in use. The keys you hold to yourself, so access is yours to grant and revoke. And an egress gate that evaluates each outbound prompt against a known boundary and blocks the send before it happens, rather than logging it after. Assembled at the perimeter as an enforced check, these stop being a set of good intentions and become a control: the transaction is refused, not reviewed. That distinction is the whole of it, because of a fact about this technology that no contract can undo — you cannot unsay a secret to a model that has already learned it.
You cannot unsay a secret to a model that has already learned it. The only place to stop the leak is the instant before the prompt leaves.
Own the loop, and the exhaust becomes an asset
There is an upside hidden within the paradox, and it is why this is a strategy question rather than merely a security one. The corrections, the evaluations, the accumulated record of how your people get good answers out of a model — that intelligence exhaust is precisely the thing that makes a model valuable for your specific work. Vented to an external provider, it is a gift to a competitor’s supplier. Captured inside a boundary you control, it is a compounding advantage: the model improves on your ground, and the improvement stays yours. The same exhaust that is a liability when it leaves is an asset when it is kept. Owning the learning loop is how the second invoice stops being a cost and starts being an investment in something you actually retain.
27.4%
of corporate data entering AI tools was sensitive by March 2024, up from 10.7% a year earlier. The exposure is not stable — it is compounding.
Cyberhaven, AI adoption and risk report, 2024
The only question that matters
There is a simple test for whether an organisation has built a control or merely bought a reassurance. Ask what happens in that specific place the instant a prompt carrying your crown jewels is sent to an external model. If the honest answer is a policy, a training module, a clause you could invoke in a future dispute, an audit that will surely catch it next quarter — that is a witness, and you are already paying the second invoice without a way to stop it. If the answer is that it simply cannot happen — the gate inspects the prompt and refuses it, the sensitive context never crosses the boundary, the send does not complete — that is a control.
The term is not mine to mint, and the tools are not new: confidential computing, open-weight models, key management, and egress control have existed for years. What governing the autonomous enterprise insists on is where they sit — at the boundary, as an enforced gate, not in a binder, as a promise. Nadella is right that you pay for intelligence twice. But the second invoice is not settled at signing. It is paid one prompt at a time, and the only place to refuse it is the instant before the prompt leaves. The boundary is the control.
References
This piece draws on Satya Nadella’s primary essay, the classical information economics of Kenneth Arrow, enterprise data-security research, and public reporting, including material from Cyberhaven, LayerX, and Bloomberg. Vendor-produced measurements (Cyberhaven, LayerX) are corroborated by independent media and are cited for direction; exact figures may vary by sample and period.
Nadella, Satya. “The Reverse Information Paradox.” Essay posted on X, July 2026. (Reported by The New Stack, MIT Sloan Management Review Middle East, and Business Standard.)
Arrow, Kenneth J. “Economic Welfare and the Allocation of Resources for Invention.” In The Rate and Direction of Inventive Activity. Princeton University Press, 1962.
Cyberhaven. “4.2% of Workers Have Pasted Company Data into ChatGPT.” 2023; and AI adoption and risk reporting, 2024.
LayerX. Enterprise AI Security Report, 2025.
Bloomberg. “Samsung Bans ChatGPT, Google Bard, Other Generative AI Use by Staff After Leak.” May 2, 2023.


