Microsoft CEO Satya Nadella issued an unusual warning this month to companies adopting AI: every prompt, correction, and workflow you feed a proprietary model teaches the model provider how your business works. As he put it, "you essentially pay for intelligence twice — once with money, and again with something even more valuable."
For Saudi organisations, where data sovereignty is already a regulatory requirement rather than a preference, the warning deserves a closer look.
1. What Nadella actually said
Speaking on 13 July, Nadella argued that the commercial relationship between enterprises and AI model providers is lopsided. The better you want a model to perform, the more of your operational knowledge you have to feed it — prompts, corrections, documents, and tool usage patterns. That knowledge is competitive intelligence, and today it flows in one direction.
His sharpest line: "In consuming intelligence, you are creating intelligence. And what you create should belong to you." He described the current arrangement as a Trojan horse, where firms unknowingly educate potential rivals.
2. Why this lands differently in Saudi Arabia
Saudi enterprises already operate under rules that anticipate exactly this problem. The Personal Data Protection Law (PDPL), overseen by SDAIA, restricts how personal data can leave the Kingdom. The NCA's Essential Cybersecurity Controls require organisations to know where their data is processed and by whom. SAMA-regulated institutions face stricter requirements again.
Sending business data to an AI API hosted abroad is not just a competitive question here — it can be a compliance question. Many organisations we speak to have discovered that the AI pilot a department launched last quarter routes customer data through a service with no in-Kingdom presence and no clear data-handling terms.
3. The shift towards models you control
Nadella's proposed answer is for companies to own their prompts and feedback, build learning environments on infrastructure they control, and keep an orchestration layer that lets them switch providers without rebuilding everything.
The market is moving this way already. TechCrunch cites Vercel gateway data showing 29% of AI traffic last month went to open-source models rather than proprietary ones. Open-weight models deployed on-premises or in-Kingdom cloud regions have matured to the point where they handle most document processing, classification, and internal assistant workloads well.
4. What we recommend
Three practical steps, in order of urgency.
Audit what is leaving. Inventory every AI tool in use — sanctioned or not — and establish what data each one sends, where it is processed, and under what terms. This is also the starting point for PDPL compliance.
Negotiate data terms, not just price. Enterprise AI agreements can and should exclude your inputs from provider training. If a vendor will not commit to that in writing, treat everything you send them as disclosed.
Design for portability. Route AI calls through an internal gateway rather than embedding one provider's API throughout your systems. When a better or more compliant option appears — including an in-Kingdom hosted model — switching becomes a configuration change, not a rebuild.
5. Where Oasis Systems fits
We help Saudi organisations deploy AI on infrastructure that satisfies PDPL and NCA requirements — from private deployments of open-weight models to orchestration layers that keep provider choice open. If your organisation is using AI tools today and cannot say precisely what data leaves the Kingdom through them, that is the conversation to have first.
Learn more about our AI software development services, or get a free AI automation assessment tailored to your environment.

