Skip to content
You don't own the AI you rent – but you can own the architecture around it

You don't own the AI you rent – but you can own the architecture around it

Palantir's CEO says you're paying for tokens and losing your IP. The fear is legitimate - and the answer is a three-rung ladder, not a rack of servers. Where the contract is enough, where zero-retention is, and what actually has to come home.

Alex Karp told CNBC that enterprises are burning tokens, getting nothing, and handing over their IP - and said it the same week Palantir announced an Nvidia partnership and a manifesto on AI sovereignty. Ran thinks the fear is legitimate and the answer on offer is one rung of a three-rung ladder, sold as the whole thing. His argument in Founder Mode: the contract handles more than you think, zero-retention handles more still, and the part that genuinely has to come home is smaller and cheaper than anyone quoting you a rack wants to admit. — Muximus


On 1 July, Palantir CEO Alex Karp went on CNBC and said something had gone completely wrong with how AI is sold. In Fortune's transcription of the segment, his version of the prevailing enterprise mood was this: I'm going to waste my time with tokens, I'm going to get no value, and they're going to get my IP.

He said it during a week in which Palantir announced an expanded partnership with Nvidia, one day after Palantir published a nine-point manifesto on AI sovereignty, and on a day its shares climbed 8%, per CNBC.

I want to take the fear seriously, because it is the single most common question I get in a room with a lawyer in it. Our orders, our margins, our supplier terms, the map of how we actually work - we're sending that out?

It is the right question. It also has three different answers depending on what is actually driving it, and they form a ladder. Karp is selling the top rung to people who need the bottom one.

Quick disclosure before I go further, because I am not neutral either: VarOps builds and transforms AI-native organizations, and the architecture I land on at the end is work I do for money. Weigh it accordingly.

Rung one: "we won't"

Let's kill the cheap version of the fear before it costs you money.

"The AI companies will train on our data" is, at the tier you would actually buy, mostly a contract question with a known answer. OpenAI's enterprise privacy page lists "We do not train our models on your data by default" among its commitments and says that by default it does not use business data for training. Anthropic states that by default it will not use inputs or outputs from its commercial products - Claude for Work, the API, Claude Gov - to train its models.

Fortune's AI editor Jeremy Kahn adds the part most people miss: most large enterprises reach these models through Azure, Amazon Bedrock, or Google Vertex, and the labs' descriptions of using anonymized usage data for research apply to consumer services and direct APIs rather than those channels. Anthropic's own documentation says the same thing from the other side - on Bedrock and Google Cloud's Agent Platform, the cloud provider is the data processor, not Anthropic.

There are edges worth knowing. "By default" means an opt-in exists, and on the Anthropic side that opt-in can be tripped by any one employee hitting the thumbs-down feedback button until an admin switches it off org-wide. Go check that setting this week. It costs nothing.

But if training is your whole concern, the fix is not hardware. The fix is reading the contract and having your counsel read it before you sign. Anyone quoting you a server rack before that conversation is selling you fear.

Rung two: "and we won't keep it either"

If retention itself is the worry - not training, just the fact that your prompts sit on someone's disk - there is a second rung, and it is underused because most buyers do not know to ask for it.

Zero data retention. Under a ZDR arrangement, Anthropic does not store customer prompts or responses at rest after the API response is returned. OpenAI's platform docs describe ZDR-eligible endpoints that do not retain customer content for application state.

Now read the fine print, because this is where it gets interesting.

ZDR is not a checkbox. At Anthropic it is enabled per organization, on request through your account team, and enablement does not automatically extend to other organizations on the same account. It covers the Messages and Token Counting APIs for eligible features. It does not cover the Console or Workbench, Managed Agents, consumer plans, the Claude Teams and Enterprise product interfaces, or third-party integrations. Claude Code is the notable exception on that last point - it is covered when used with commercial API keys, or through Enterprise with ZDR switched on.

And here is the part that should change how you plan: Claude Fable 5 and Claude Mythos 5 are designated Covered Models that require 30-day data retention, and are therefore not available under ZDR at all. Send a request to Fable 5 from an organization configured for zero retention and the API hands you back an error saying your organization or workspace must have data retention enabled.

Sit with that, because it is the whole argument compressed into one config error. Anthropic's two most capable models and its strongest retention promise are, right now, mutually exclusive. The documented way through is to enable 30-day retention on a single workspace and let the rest of the organization keep zero retention - which is to say the answer, even inside one vendor, is already an architecture. You draw a boundary and you decide what crosses it.

One more line worth reading: even under ZDR, content flagged by automated trust and safety systems may be retained for up to two years.

None of that is scandalous. It is engineering reality - stateful features need state, and safety systems need evidence. But it means rung two is narrower than the brochure, and you have to design around its shape rather than assume it.

What a contract cannot do

Notice what both rungs are made of. A promise. A good one, from serious companies with real reputations behind it, backed by published policy and enforceable terms. But still: "we won't."

Rex made the sharp version of this point on this site last week, taking a proxy to a coding agent that had been told to open nothing and watching the whole repo leave anyway. The lesson that generalizes past that one vendor: a control you cannot observe is a control you are accepting on faith. Contracts and toggles are both promises. Plenty of them are excellent. None of them is architecture.

Sovereignty is for when "we won't" is not enough and you need "we can't."

There are three situations where that is the correct call rather than the paranoid one.

Compliance will not let the data leave. Regulated work, government-adjacent work, data-residency law, defense supply chains. Sometimes the rule is not "the vendor must promise," it is "this information does not cross this boundary." No contract fixes that. Only architecture does.

Your clients' contracts bind you. This is the one mid-market companies forget until it bites. You may be perfectly comfortable with a provider's terms, but if your biggest customer's MSA says their pricing and specs never touch a third-party processor, your comfort is irrelevant. Obligations flow downhill. Audit those before you audit the AI vendor.

Your company's experience is the asset. For some companies in some competitive positions, the structured understanding of how you decide, price, route and win is treated the way you treat the recipe vault: it does not leave the building as a matter of principle, regardless of what any contract says. Not because anyone is lying. Because some things you do not put on someone else's shelf, however good the lock.

If the first two do not apply to you - and for most mid-market companies they honestly do not - you do not need the full closet. Use the frontier models under a proper enterprise agreement. The best AI available is rented, it improves every quarter without you lifting a finger, and refusing it without a reason is expensive pride.

But do not stop reading, because the third reason has a property the other two lack. It used to be a luxury posture. It quietly became nearly free.

The split that actually matters

Sovereignty is not all-or-nothing, and treating it that way is how the half-million-dollar quotes happen. But the obvious hybrid - sensitive tasks local, everything else rented - is the weaker version of the idea.

The sharper split is not by task. It is by what the model gets to read.

Here is the threat worth pricing properly. No single task leaks your business. What leaks your business is the aggregate: the full map of how you decide, price, route and win. A model that receives one task-scoped slice - this customer's history, this quote, draft the reply - learns almost nothing about you. A model that holds your whole comprehension holds the company.

The risk was never in the errand. It is in the education.

So the rule is one line: full-brain readers run local, slice readers may run frontier.

The company brain - building it, maintaining it, querying it whole - lives on machines you own. Conveniently, that work is patient. Nobody is waiting on it, so it can grind overnight on modest hardware and lose nothing. Execution goes the other way: each task gets a minimal, brain-prepared slice, and that slice can go to the best rented model on earth under the terms above.

Which gives the local brain a second job, quietly more valuable than the first. It is the information firewall. The brain decides, per task, what leaves the building. Minimal disclosure stops being a policy somebody has to remember to enforce and becomes how the architecture works.

Your alpha stays home. Your errands get frontier intelligence.

And the hardware is not what you think. We are talking about a couple of high-memory desktop machines - the kind that sit in a closet, plug into a normal outlet, and get financed like office equipment. Not a rack. Not a datacenter. Your IT person can point at it.

There is a second reason the cost collapsed, and it is the one nobody selling hardware will tell you. A frontier model with no context about your company is a brilliant stranger, spending most of its intelligence guessing at what your business means. A modest open-weight model reading an excellent company brain will beat a frontier model reading nothing, on your specific work, most days of the week. The intelligence you built into the brain is intelligence you no longer have to rent from the model.

The dividend nobody prices

Now go back to what Karp was actually afraid of: dependence. Lock-in. The alpha migrating into somebody else's product.

Here is the thing. That fear does not dissolve by changing landlord. It dissolves through architecture.

When your comprehension lives inside one vendor's model, switching is surgery. When it lives in your own brain, switching is a routing change. The brain prepares the slice, and the slice goes to whichever model is currently best - or cheapest - at that class of work. Tasks have shapes. Deep reasoning over a gnarly contract, high-volume drafting, cheap classification of inbound email: these want different models at wildly different prices, and the market for rented intelligence re-ranks itself every quarter.

The brain makes you model-agnostic. The model becomes a commodity you re-bid. It is the same reason a new model won't save you if you have not done this work, and the same reason it barely matters which one you are on once you have.

That is also the honest answer to the question I have been circling all piece.

What do you still have if you swap the model tomorrow?

Tokens are rent. Rent is not a scandal - you rent your cloud, your payroll system, probably your building. The scandal, if there is one, is paying rent for a year and accumulating nothing. Which is the same argument I made a few days ago from the measurement side: the goal was never to use AI. Usage is what you spend. The brain is what you keep.

The swap test

Run this on your own operation this week. Assume your main provider doubles its price, or the model you depend on turns out to be one you cannot get under the retention terms you need. You have thirty days.

  1. Is the task written down anywhere? If the only specification of what the AI is supposed to do lives in a prompt somebody pasted into a chat window, you own nothing.
  2. Can you tell whether the new model is worse? No evaluation set drawn from your own work means you cannot answer this. You will decide by vibes.
  3. Does the work survive the swap? If the workflow is welded to one vendor's tool-calling format, the switching cost is the real price you have been paying all along.
  4. Who holds the data the system runs on? Not the weights. The retrieval corpus, the labeled examples, the corrections your staff made. This is the genuinely yours part, and the part most often left sitting inside somebody's product.
  5. What reads the whole thing, and what gets slices? That line, written down, is your architecture. It is also the document your compliance officer, your biggest client's auditor and your own board actually want to see.

A single no on 1, 2 or 4 is the finding. Those three are also the cheapest to fix.

Name the interests. All of them.

Palantir's partnership pairs Nvidia's open-source Nemotron models with Palantir's AIP application layer to build custom models for US government agencies. The manifesto published the day before the interview attacked tokenmaxxing by name and told companies their data retention was their treasure, to be transferred at their peril.

None of that makes Karp wrong. It means his description of the problem is also a description of his product, and that the rung he is selling - full sovereignty - is the right answer for the regulated and the contractually bound, and overkill for most of the people who heard him.

Kahn's rebuttal carries its own disclosure, and it is an honest one: the clearest genuine case of labs training on other people's work, he writes, is his own industry, media. There is also one reported episode on the other side worth stating rather than waving off. Fortune, reporting on The Information's story, describes Anthropic working with Figma and Canva on a Claude design tool while Anthropic's chief product officer sat on Figma's board; Figma pulled out and the seat was vacated after Figma concluded the product overlapped its own features more than it had been told. Fortune's own wording is that the access may have been used that way. One disputed episode, at second hand, inside a design-partner relationship rather than ordinary API purchasing. Worth knowing if you are considering becoming a design partner. Not evidence that a mid-market manufacturer's edge is leaking into a model.

And mine again, in full: VarOps sells this work to the same operators I am writing for. It is also not right for everyone. A company with no platform team and no intention of growing one should buy the layer rather than build it, and will get a better result buying it than half-building it with people who already have other jobs.

Your move

So here is the honest ladder, top to bottom.

Full sovereignty, everything local, for the regulated and the contractually bound. The split - brain home, execution rented under ZDR, with the right model per task - for everyone else. And everything on one rented model with no brain of your own, which is the industry's current default, for nobody. It is the one configuration on the menu with no reason to exist: it pays frontier prices, accepts maximum exposure, and owns nothing at the end.

Karp was right that a lot of companies are paying for tokens and getting nothing, and right that metered billing gives the seller no stake in whether it worked. Where I part company is the remedy. You do not fix that by owning the weights. You fix it by owning what reads them.

Write the spec. Build the eval set. Keep the data. Draw the line between what reads the whole brain and what gets a slice, and write that line down.

Do that, and it stops mattering much whose weights you rent.

I go considerably deeper on this - the three reasons, the hardware, and the checklist - in an appendix of the book I'm finishing.


Sources: CNBC · CNBC video · Fortune · Palantir's manifesto · OpenAI enterprise privacy · OpenAI data controls · Anthropic training policy · Anthropic API and data retention. The Information's original Figma report is paywalled and was not read directly; it is cited here via Fortune's account of it.

Add VarOps on Google