Reverse Information Paradox: Why You Pay Twice for AI

The landlord warns against renting

Satya Nadella of all people. The boss of Microsoft, the corporation that rents out more AI infrastructure than almost anyone else, writes a post about the fact that precisely this rental relationship has a problem for customers.

His thesis is called the Reverse Information Paradox.

In 1962, the economist Kenneth Arrow described a well-known dilemma in the trade of information: the buyer only knows the value of information once they have it. But by then they already have it without having paid for it. The seller therefore risks giving away their knowledge just to be able to sell it. Patents were invented for this purpose among others: they allow an idea to be disclosed without giving it away.

AI reverses this dilemma. Today, it is not the seller who risks their knowledge, but the buyer. To make an AI model useful, you must feed it with your context: your processes, your customer cases, your pricing logic, your quality standards. The better the model is supposed to work for you, the more of this you feed into it.

Knowledge flows as a glowing liquid from a corporate vessel into a cloud, with coins falling along the same path
Figure: Arrow's Paradox of 1962 and Nadella's Reversal. In the AI era, money and knowledge flow in the same direction, to the provider.

So you pay twice. Once with money for the tokens. And once with the knowledge that makes using it valuable in the first place.

What exactly flows out (and why it is more than just data)

Translated for business people: imagine you hire a brilliant external specialist. Affordable and available around the clock. There is only one condition: they take notes on every task. About the task itself, but also about your way of working: which answers you accept and where you make improvements. And these notes do not belong to you, but to their actual employer, who uses them to train their next specialist. For your competitors too.

This sounds exaggerated, but it captures the mechanism. Nadella calls it "exhaust", or the exhaust fumes of usage: prompts, the tools your AI agents use, and above all, the corrections made when the model goes wrong. Every correction is distilled experiential knowledge. The kind of knowledge that a competitor can hardly buy because it only exists within your company: knowledge about your customers and your processes.

Individually, each of these traces is harmless. In sum, they create a picture of your way of working, and this picture is created at the provider’s end, not yours. The information asymmetry grows with every use: the provider constantly learns more about you, while you learn practically nothing about what they are learning.

This is not a security incident, but the normal, usually contractually permissible operating state of many AI services. That is what makes it so easy to overlook.

Alex Karp says the same thing, from the opposing camp

In his post, Nadella quotes a second voice: Alex Karp, CEO of Palantir. In a CNBC interview, Karp phrases it more sharply. Technically advanced customers, he says, want "control over their compute, their models, their data stack, and their alpha". They want to know that they own the means of production and that they are not creeping over to someone else.

Karp goes even further. His accusation against model providers: customers pay for tokens while the actual value, the "alpha" of their business, migrates in the opposite direction. And he asks the questions that, in his view, every buyer should ask: Who owns the data? Where is it cached? Are the prompts protected? Is something being transferred to the provider here?

Both are speaking in their own interest. With Palantir, Karp sells exactly the model-independent orchestration layer that he recommends. Nadella positions Microsoft's Tenant model as the answer to a problem that his own industry created. The fact that these two of all people, the hyperscaler and his challenger, with opposing business interests, share the same diagnosis, speaks in favor of the diagnosis rather than against it.

My opinion: contracts are a layer, not a boundary

In my mandates, I repeatedly see how companies reassure themselves with contractual clauses: no training on customer data, zero retention, data processing agreement. These clauses are necessary, and you should demand them. But they have a structural weakness: you cannot verify what actually happens to your data in a provider's infrastructure. A contract gives you a claim in the event of a dispute. It does not give you control during operations.

In security architecture, a principle has applied for decades: what is technically possible will happen at some point, whether by intention or by error. A provider can change its terms of use or be acquired. Your contract of yesterday only offers limited protection for your knowledge of tomorrow.

This is why I believe the sequence that is common today is wrong: contract first, architecture later or never. The reverse is correct: architecture first, to technically limit the outflow. The contract is the second line of defense, not the foundation.

However, the reverse is also true: pure technical isolation is equally illusory. Anyone who avoids every frontier model and hosts everything themselves sacrifices significant capabilities, and that is disproportionate to the risk of many workloads. As soon as you use an external model, your prompt crosses the boundary. The realistic question is therefore: What knowledge flows out, in what quantity, and what do you keep for yourself?

Diagram of a trust boundary around one's own tenant
Figure: Nadella's Trust Boundary. The components of one's own learning loop remain within one's own tenant; nothing crosses the boundary without explicit consent.

What is possible instead

Nadella summarizes his response in five points: Control, Capability, Choice, Cost, Compound. For a corporation with its own ML team, this is a useful blueprint. For a Swiss SME, it has to be translated, otherwise it remains poetry.

Translated, he describes a company that fully uses frontier models and still retains its alpha. You can recognize such a company by five characteristics.

It knows what flows out. A clean data classification answers the fundamental question of what information an external model is allowed to see and what it is never allowed to see. Without this visibility, every protective measure is coincidental, because you cannot limit what you cannot see. And the Karp questions (where is the data stored, where is it cached, what happens to the prompts?) are answered there before a contract is signed.

It does not treat every prompt the same. Uncritical tasks run on the best available model, while sensitive cases run on Swiss or European-hosted endpoints or an open-weight model on one's own infrastructure. This works because the risk depends on the content and not on the tool: anyone who treats everything the same either loses capabilities (everything forbidden) or knowledge (everything permitted). The prerequisite is an orchestration that is not tied to any single provider. That is Nadella's "Choice", and incidentially the best negotiating position on price.

Its learning loop is kept in-house. The most overlooked point. Prompts that work, the team's corrections of the output, and the metrics against which quality is measured (the evals): this is distilled know-how, and it sits in your own systems instead of just in the provider's chat history. This effect becomes apparent when switching providers: what has been learned moves with you instead of staying behind. That is the difference between a company that uses AI and one that becomes better because of AI.

Contracts form the second layer. No training on your own data, zero retention, audit rights, clear deletion periods, data processing agreement under nDSG. They give you a claim in the event of a dispute, active while the architecture limits the outflow during operations. Both layers support each other; either one alone is full of holes.

And lean governance holds it all together. An AI governance that defines who can use which models for what. Without it, usage will find its own way, and the outflow will bypass all other precautions through shadow IT.

Nadella's five points: Control, Capability, Choice, Cost, Compound
Figure: Nadella's five points. The first four are prerequisites, the fifth is the effect: a learning loop that yields interest in-house instead of with the provider.

The honest question

If your most important AI provider were to cut off access tomorrow: what would remain of what your organization has learned with AI over the last twelve months?

If the answer is "little to nothing", you have so far not invested in your own capability, but in that of the provider. That is what Nadella means by the Reverse Information Paradox. The good news: unlike Arrow's Paradox, you do not have to wait for a new patent law. You can draw the line that protects your knowledge yourself, and the best time to do so is before the learning loop starts running somewhere else.

How companies can use AI productively without getting lost in tool chaos is described in the article AI in SMEs: between ChatGPT chaos and real business value.