Businesses are increasingly questioning their reliance on frontier artificial intelligence companies, as data privacy concerns push them to explore open source alternatives and build greater control over their own AI infrastructure. The shift follows a series of controversies over how leading AI vendors handle corporate data, with executives worried that their proprietary information could be used to train models that eventually compete with them.
The tension came to a head in June when Anthropic began mandating a 30-day retention policy for all chats with its most powerful AI models, Fable and Mythos. The move provoked what one adviser described as an almost allergic reaction from companies that had grown accustomed to stricter data controls. The industry at large rejected the policy, according to a source who advises clients on becoming AI-native and spoke on condition of anonymity because his company works closely with Anthropic.
Both OpenAI and Anthropic have stated they do not train their models on enterprise data. Yet many data security experts argue that AI companies may have subtler ways to glean insights about how their customers operate, improving future models without directly training on the data being processed. Rob Gregory, Vice President and Chief Information Security Officer at the cybersecurity advisory firm Optiv, said the risk of any business data being trained on an AI model is unacceptable. He described the current moment as a very interesting crossroad.
The concerns have been sharpened by a string of rogue AI incidents, in which models have scraped data or published it without permission. In July, Microsoft CEO Satya Nadella and Palantir CEO Alex Karp both warned companies against relying on models from frontier AI firms. Nadella said businesses essentially pay for intelligence twice, once with money and again with proprietary knowledge they must reveal to make that intelligence useful.
In response, companies are looking to diversify their AI usage and reduce dependency on the leading providers. The term du jour is sovereign AI, referring to a company's ability to control its own AI stack, from owning the chips on which workloads run to setting up proprietary cloud infrastructure and using open source models that can be downloaded and run in-house. Historically associated with governments, the concept has bled into the corporate world this year.
Brooke Hopkins, founder of the voice AI company Coval, said data sovereignty is something her firm is talking about a lot. Dutta, another executive, said sovereign AI has been a large topic of conversation over the past few months. The trade-off is that running open source models requires more technical expertise and may mean companies miss out on cutting-edge capabilities in areas such as coding or financial analysis that products from OpenAI, Anthropic and Google offer. Gregory summarised the dilemma as trading control for responsibility, noting the significant burden that comes with bringing AI operations internally.
OpenAI and Anthropic are still competing directly to win over business customers and keep them from switching to open source alternatives. OpenAI saw an opening after Anthropic's data retention announcement and in an August 19 blog post reiterated that it offers full zero data retention for enterprise customers, while previewing a feature called Private Safety Processing that lets customers store data in their own cloud rather than on OpenAI's servers. Anthropic responded on September 1 with a similar version of zero data retention that also allows businesses to store data in their own cloud accounts.
But the damage may already be done. After Anthropic announced its 30-day retention policy, businesses including Booz Allen restricted their teams' use of its Fable model. Another route for companies is Amazon Bedrock, which provides access to multiple AI models without the providers seeing their data. It is one of the fastest growing AWS products of all time, with customer spend growing 170 per cent in the first quarter and nearly 80 per cent adoption by the Fortune 100. Randall Hunt, chief technology officer at the AWS advisory firm Caylent, said Amazon's pitch is that companies do not have to trust the frontier labs, and that it is a more established company people have been using for decades.
Many companies are adopting a hybrid model, using a combination of closed and open source models. Gregory said sovereign AI enables businesses to continue partnering with OpenAI and Anthropic for some tasks while using open source models on premises for others. That approach, however, requires companies to secure their own infrastructure and accept greater responsibility for the technology they deploy.