“We have really good lawyers.” That was the response from a tech leader at a $7.5 billion financial services company when asked how they handle their data with OpenAI.
The contracts they have in place are probably very clear about what OpenAI can and can’t do with their data, how long OpenAI can keep it, and what the bank’s rights are to retrieve it.
But I’d guess that OpenAI and Anthropic are still able to learn valuable information from their bank customers even if they don’t use raw data from those customers to train their models. They can learn from metadata about where prompts are coming from, token usage, model usage, and the timing of requests. Across many bank customers, those signals add up to a picture of which workflows banks are automating, how much they’re spending on each one, and which ones stick. They can build a competitive product roadmap without breaching “airtight” contracts.
Furthermore, I’d be surprised if this bank, or any enterprise customer, were allowed to access OpenAI or Anthropic systems to audit exactly what is happening to their data once it lands at the frontier labs. What enterprises typically get is a SOC 2 report and contractual commitments. Those describe the labs’ controls, but they don’t let you see what actually happens to your own traffic.
Fundamentally, the lawyers have created an after-the-fact defense system that could allow for punitive litigation if they’re able to discover that their data is misused. And a contract is only as useful as your ability to detect a breach of it.
Now combine that after-the-fact data protection with a default AI governance posture of “No. If we haven’t explicitly approved the specific way you’re planning to use AI, then it’s not allowed.” The two cover for each other badly. The lawyers make leadership feel that the data risk is handled, so nobody pushes for a different architecture. The “no” posture slows adoption, so the business falls behind competitors who move faster. You end up slow and still exposed, and your enterprise is fundamentally at risk from competition by both the frontier labs and startups.
The frontier labs are not shy about expanding their businesses into their customers’ domains. Earlier this year, when Anthropic released a version of Claude aimed at financial services analysis, FactSet’s stock fell about 9% in a day. Anthropic’s legal research tool and the labs’ enterprise agent platforms got similar reactions from the market.
These products weren’t made possible by the detailed data of one customer with bad (or good) lawyers. The labs don’t need that data to compete with you; they need to know where the value is, and their customers’ usage in aggregate shows them.
This puts enterprise CEOs in a pickle. They need the power of AI to stay competitive, but they’re giving up extremely valuable operational information to do it.
The obvious answer is to use open weight models and sovereign AI as much as possible.
As I speak to these financial services companies, I’m realizing that they’re not fully aware of how this works, what it enables, or how to use it. They’re only just now starting to understand how their companies can benefit from AI at all, so to add the layer of “you need to be using sovereign AI” is a lot. One potential customer told me, “Well, we like some of the benefits you’re talking about like cheaper inference and assured data protection, but they’re just not a priority for us right now.”
They’re prioritizing the short term.
If you start sovereign from the beginning, it’s not harder than building your agents on the frontier labs’ APIs. Open weight models are served through the same kind of API, and the agent frameworks are the same. The extra work is hosting and operations, and that’s something you can hand to a partner. Starting sovereign also saves you from having to redo your work when it does become a priority.
It will definitely become a priority.
The frontier labs know that ultimately the model layer will not be a defensible moat to protect their enterprise value. Open weight models are already close behind and good enough for most of the document-heavy work banks care about. Many of the leading ones come from Chinese labs, which gives some people pause, but with the right hardening the weights run on your own infrastructure with no connection back to whoever trained them.
So, the only way the labs can protect their enterprise value is to own the application layer. The application layer is where users live and value is created.
Your company is currently serving those same customers that the frontier labs want to own. You can hold onto them if you own the application layer. But you can only own that layer if you keep the most valuable parts of it on infrastructure you control.
This means you need to undertake a period of significant building. You need to build agentic systems on your own infrastructure that automate and perform the most valuable work your business does. Get going on this now, and in two years, you’ll be well on your way to being an AI native company.
Let’s get going.
—Jon Christensen


