cd /news/ai-policy/bring-the-ai-to-your-data-not-your-d… · home topics ai-policy article
[ARTICLE · art-111755] src=fastcompany.com ↗ pub= topic=ai-policy verified=true sentiment=· neutral

Bring the AI to your data, not your data to the AI

Enterprises are increasingly rejecting the traditional approach of moving proprietary data to frontier AI models, opting instead for AI systems that operate within their own data environments, according to an AI company leader. Microsoft CEO Satya Nadella warned that companies 'pay for intelligence twice' by revealing proprietary knowledge, while IBM's 2025 Cost of a Data Breach Report found shadow AI involved in 20% of breaches, adding roughly $670,000 to the average incident, with global average breach costs at $5.05 million for multi-environment incidents and $4.01 million for on-premises incidents. KPMG's Q4 2025 AI Pulse reported 80% of leaders cite cybersecurity as the greatest barrier to AI strategy goals, up from 68% in Q1, and 77% cite data privacy concerns.

read4 min views1 publishedAug 26, 2026

For the past few years, enterprises that wanted to build their own agentic systems adopted AI the same way: Pick a frontier model, copy your knowledge into it, then route your tickets through it. Eventually you’re piping customer records, contacts, and workflows into someone else’s system, hoping the contract protects you. The premise was that the capability alone justified moving your data to the model. More and more, the prospects I talk to are caught in the same bind. They want the efficiency AI promises, but they don’t want to pipe their data into the frontier models and simply hope it doesn’t come back to bite them. I lead an AI company, and I’ve sat through this exact pros-and-cons debate in more boardrooms than I can count. Enterprises have spent decades and billions of dollars building the systems and gates meant to protect themselves and their customers. Now they’re being asked to gamble it all on someone else’s system.

That deal is being renegotiated. For many enterprises, no amount of capability is worth the risk they’d be taking.

Every one of your competitors can license the same frontier model you can. What they can’t license is your data. That’s your moat. Early AI adoption asked you to put that moat into a system you don’t own, don’t control, and can’t audit. The model you chose will be replaced within a year. The data you handed over to it stays handed over.

Satya Nadella, Microsoft’s CEO, put it bluntly a few weeks ago: “You essentially pay for intelligence twice, once with money, and again with something even more valuable: the proprietary knowledge you must reveal to make that intelligence useful.”

Palantir’s Alex Karp expounded on what technical customers actually want: “control over their compute, their models, their data stack.” The exposure is already showing up in the data. IBM’s 2025 Cost of a Data Breach Report found that shadow AI, the unsanctioned tools employees reach for, was involved in 20% of breaches and added roughly $670,000 to the average incident, on top of a global average breach cost of $5.05 million for incidents involving multiple environments and $4.01 million when on premises.

Enterprises are responding by deciding they want AI that comes to their data, and operates inside their existing governance. The data stays in place by deployment choice, whether that’s a private cloud, hybrid, or fully on-prem. Frontier capability still matters, but where your data sits matters more than the latest model. Models change constantly, but governance obligations rarely do.

KPMG’s Q4 2025 AI Quarterly Pulse put percentages on how much this now weighs on the people making the call: 80% of leaders called cybersecurity “the single greatest barrier to achieving AI strategy goals,” up from 68% in Q1. Data privacy concerns were close behind at 77%. Data privacy concerns get called caution, though the leaders running global enterprises have simply worked out what an ungoverned deployment costs them when it goes wrong.

The EU AI Act’s most significant compliance deadline was supposed to land on August 2nd of this year. In June, the EU formally pushed the high-risk obligations out to December 2027, and to August 2028 for AI embedded in regulated products. The transparency obligations still take effect on schedule. The direction hasn’t changed, only the dates. Any architecture built around a compliance date has to be rebuilt when the date moves. Data-residency and sovereignty rules are multiplying across jurisdictions. ISO 42001, the first international management-system standard for AI governance, is emerging as the credential procurement teams and regulators will start expecting.

Most enterprises aren’t ready for this level of compliance and governance scrutiny. Grant Thornton’s 2026 AI Impact Survey of 950 senior executives found that 78% of organizations do not have confidence that they could pass an AI governance audit within three months. Every ungoverned deployment makes the next one that much harder to trust and defend.

AI adoption isn’t slowing down. Enterprises are simply getting smarter about protecting their moat given their own specific circumstances. Ask these three questions of every vendor on your list.

**1. **Can we keep our data inside our own governance and residency perimeter by deployment choice?

**2. **Can we produce an audit trail today, not after a six-month remediation?

3. Can we swap the underlying model without re-exposing our data?

If the answer to any of those is no, you’re renting the capability rather than buying it, and paying with the one asset you can’t get back. A vendor who can’t answer all three today is asking you to take the risk on their behalf. Architecture outlives every new model release, which is why it’s the decision worth slowing down for. You will change models, probably more than once, and probably this year. Where your data sits when you do is the part to settle now. Get that right and the next model release is an upgrade instead of a migration.

Jonathan Corbin is CEO of Maven AGI.

── more in #ai-policy 4 stories · sorted by recency
── more on @microsoft 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/bring-the-ai-to-your…] indexed:0 read:4min 2026-08-26 ·