The Next Trillion Dollars in AI Will Be Built Inside the Trust Boundary
The Next Trillion Dollars in AI Will Be Built Inside the Trust Boundary
Why private, sovereign AI is where enterprise value compounds — and why the current architecture of the AI industry guarantees it.
Satya Nadella recently put a name to something every enterprise architect has felt in their gut for two years. He calls it the Reverse Information Paradox, an inversion of Kenneth Arrow’s famous observation about the market for information. Arrow’s paradox was a seller’s problem: you can’t prove the value of knowledge without revealing it. Nadella’s paradox is a buyer’s problem: in the AI era, you can’t use the intelligence you purchased without feeding it the proprietary knowledge that makes your company valuable in the first place.
You pay twice. Once in dollars. Again in the prompts, corrections, workflows, and institutional judgment you pour into the model to make it useful. And the better you want the model to perform, the more of yourself you have to hand over.
Nadella is right about the diagnosis. But I want to push on what it implies, because the implication is bigger than a policy debate about data terms of service. It’s a statement about where economic value will accumulate in the AI era — and the answer is not where most of the market is currently looking.
The exhaust is the asset
The cloud era taught enterprises to think of data as the asset. That framing is now obsolete. In the AI era, the asset is learning — the continuous loop of tasks, traces, evaluations, and corrections through which an organization’s specific intelligence gets encoded.
Every time one of your engineers corrects an agent’s output, that correction is a distillation of institutional know-how. Every eval you write is a definition of what “good” means inside your company — knowledge no competitor can buy and no generalist model was born with. This is Hayek’s particular knowledge of time, place, and circumstance, and it now leaks trace by trace, correction by correction, into infrastructure someone else owns.
Follow the flow of learning and you can predict the flow of value. If learning flows in one direction — from every enterprise into a handful of frontier model providers — then economic value converges toward the owners of the learning infrastructure. The knowledge creators become sharecroppers on someone else’s cognitive land.
That is the default trajectory. It is not the inevitable one.
Sovereignty is not a feature
The market’s first response to this anxiety has been checkbox sovereignty: data residency, encryption at rest, “we don’t train on your data” pledges buried in enterprise agreements. These are necessary and wildly insufficient, because they protect information while the thing that actually needs protecting is the mechanism of learning.
A real trust boundary — the kind Nadella argues enterprises will demand — has to enclose the entire loop:
- Your data, in place. Not copied into someone else’s context pipeline, not shuttled through ingestion layers you don’t control. The intelligence comes to the data; the data does not migrate to the intelligence.
- Your evals. Private, proprietary definitions of quality, because whoever writes the evals defines what the model is optimizing for. If your evals live inside a vendor’s platform, so does your definition of excellence.
- Your traces and memory. The accumulated record of decisions, corrections, and context is the raw material of your firm-specific model advantage. It should compound inside your boundary, not evaporate into someone else’s training corpus.
- Your right to distill. Enterprises will — and should — demand the right to use model outputs from their own tasks to tune and train their own models. Call it what Nadella calls it: the right to align models to your enterprise accountability obligations. I’d go further and call it the right to own your own learning curve.
Model independence
The orchestration layer must be decoupled from any single model. The test is brutal and simple: if your primary model vendor disappeared tomorrow, would your “company veteran” capability survive? If the answer is no, you don’t have an AI strategy. You have a dependency.
Where the value actually gets built
Here’s the investment thesis hiding inside all of this. The generalist frontier models are becoming extraordinary — and increasingly interchangeable. Capability at the frontier is converging; prices are falling; open-weight models are eighteen months behind and closing. The generalist layer is on its way to becoming the most sophisticated commodity in history.
What does not commoditize is the sovereign layer: the firm-specific compound of data, evals, traces, adapted weights, and memory that lives inside the trust boundary and improves with every task. Two companies can rent identical intelligence from the same API and end up with wildly different returns, and the entire difference is explained by which one owns its learning loop.
This is precisely the pattern we saw in cloud, replayed at higher stakes. The hyperscalers commoditized compute, and the enduring enterprise value was built by companies that used commodity compute to compound proprietary advantage. In AI, the frontier labs are commoditizing raw cognition — and the enduring value will be built by firms that use commodity cognition to compound proprietary learning.
Alex Karp captured the customer demand bluntly: technical buyers want control over their compute, their models, their data stack, and their alpha. They want to own the means of production. The current regime — fair-use training on the world’s public data going in, restrictive distillation terms and usage-data harvesting coming out — does exactly the transfer those customers fear.
The missing infrastructure layer
Which brings us to the practical question: what does the infrastructure for sovereign AI actually look like?
It looks like a substrate where AI comes to your data in place rather than your data being exported to the AI. Where agents operate on files, records, and workflows inside your tenant boundary, with the traces, evals, and memory accruing to you. Where the orchestration layer is open and model-agnostic by design, so that swapping the generalist model underneath is a configuration change, not an existential event. Where the learning loop — task, trace, eval, correction, adaptation — runs entirely within a boundary you control, and nothing crosses it without consent. Not even the exhaust.
This layer barely exists today, which is exactly why it matters. The frontier labs won’t build it; their business model depends on the learning flowing inward. The hyperscalers are conflicted; they are the frontier labs, or their landlords. The opening belongs to a new class of infrastructure company — open-core, agent-native, built from first principles around the trust boundary rather than bolted onto it. Companies like Olympus.io are being built precisely on this thesis: that the agentic filesystem, the sovereign learning loop, and the model-agnostic orchestration layer are the picks and shovels of the next decade.
Nadella closes his argument by saying a company should be able to use a model without giving up the knowledge that makes it unique. I agree — and I’d sharpen it into a prediction:
In the cloud era, enterprises accumulated data. In the AI era, they will accumulate learning. And the firms — and infrastructure companies — that keep that learning sovereign will capture the compounding.
The Reverse Information Paradox isn’t just a problem to confront. It’s the market map for where the next great enterprise software franchises get built.