Essays on how companies hold together as they fill with abundant intelligence. Written for CEOs, enterprise leaders and executives navigating the organizational impact of AI and agentic AI.

AI and agentic systems are changing organizational design, operating models and the way companies work. The problem isn’t simply redesigning the organization for AI. It’s keeping the redesigned organization coherent as AI accelerates complexity.

Looking for something else? My academic publications and my Concentric AI writing live elsewhere.

Your AI Usage Exhaust Is Someone Else’s Moat

Two arguments about AI landed within days of each other this month. They look unrelated. They describe the same event from opposite ends, and read together they close a loop that neither closes alone.

Satya Nadella published a short piece over the weekend that names something most enterprises have not yet noticed they are doing. A few days earlier, Arvind Narayanan and Akash Kapur published a longer essay on why the AI labs cannot make money selling raw intelligence, and what they will do about it instead. One argument tells you what you are losing. The other tells you why the loss is not an accident.

Let’s start with Nadella.

He begins with Kenneth Arrow. Arrow described a paradox in the market for information: a buyer cannot know what information is worth until they have it, at which point they have it for free. So the seller risks giving away the knowledge in the act of trying to sell it.

You pay for intelligence twice. Once in money. Again in the proprietary knowledge you have to reveal to make that intelligence useful.

Nadella inverts it. In the AI age, the risk runs the other way. The buyer gives away knowledge in order to use what they bought. You pay for intelligence twice. Once in money. Again in the proprietary knowledge you have to reveal to make that intelligence useful. And the better you want the model to perform, the more of your knowledge you have to hand it. He calls this the reverse information paradox.

His answer is a trust boundary: a hard perimeter inside which your data, traces, evals, tuned weights, and memory accumulate together, and across which nothing passes without consent. Own your evals. Build your learning environment inside your own tenant. Keep the orchestration layer decoupled from any single model. Compound.

Now the other end.

The labs are spending trillions on chips and data centers. The thing they sell, model inference, is close to a perfect commodity. The leading models behave alike, cost about the same to run, and carry almost no switching cost.

Narayanan and Kapur ask a blunt question. The labs are spending trillions on chips and data centers. The thing they sell, model inference, is close to a perfect commodity. The leading models behave alike, cost about the same to run, and carry almost no switching cost. Sell a commodity into a competitive market and the price falls to the cost of production. So how does any lab ever earn back the buildout? Their answer is that it cannot be earned back by selling tokens. The labs have to move up the stack, into products, workflows, and embedded deployments, and they have to build moats. One of those moats is a flywheel: train the models and systems on customers’ own material, their data, their execution traces, their evaluation suites, until the product pulls ahead in a way a rival cannot copy.

Set the two arguments side by side and the picture sharpens.

Your judgment is not an incidental byproduct of the labs’ business. Capturing it is the business, because it is the one thing that turns an undifferentiated model into something with a moat around it.

What Nadella calls exhaust leaking out, Narayanan and Kapur call the flywheel that powers the labs’ escape from the commodity trap. It is the same substance. The traces, the corrections, the evals. Nadella watches them leave your building. Narayanan and Kapur explain why the firm on the other side needs them so badly. Your judgment is not an incidental byproduct of the labs’ business. Capturing it is the business, because it is the one thing that turns an undifferentiated model into something with a moat around it.

That changes the stakes. The pull on your knowledge is not a quirk of one product or one vendor’s terms. It is structural, and it will not relent, because the economics of the entire model layer depend on it. The rest of this piece uses one instrument from the book to work out what to do.

What leaks is not your data

Start with the mechanism, because most people will read Nadella’s post as a data-protection argument and it is not one.

Nadella is specific. Models learn from exhaust. The prompts people write. The tools the agents call. And above all, the corrections people make when the model is wrong. Each correction is distilled into know-how. It leaks imperceptibly, he writes, trace by trace, correction by correction, eval by eval.

A correction is not a data point. It is a judgment. When your underwriter overrides the model’s risk score, she is not supplying a fact. She is encoding a standard. What good looks like in this market. What that number actually means when the counterparty is this counterparty. What your firm would never do, regardless of what the numbers say. She is teaching the machine your institution’s judgment, in the most compressed and machine-readable form that judgment has ever existed in.

That judgment is the one thing your competitors cannot purchase. I have argued elsewhere that as intelligence commoditizes, the advantage that remains is the one no vendor can sell you. Nadella reaches almost the same sentence from a different direction, that this is the kind of knowledge a competitor could never buy.

The reverse information paradox is not primarily an intellectual property problem. It is a coherence extraction problem. Not the capacity itself, which no one can take from you, but everything the capacity produces, exported decision by decision.

Which is exactly why the leak matters. The reverse information paradox is not primarily an intellectual property problem. It is a coherence extraction problem. Not the capacity itself, which no one can take from you, but everything the capacity produces, exported decision by decision. The cruelty of it is structural: the act by which an organization encodes its judgment into its systems, correcting the machine until the machine reflects how the firm actually thinks, is the same act by which it exports that judgment to whoever owns the model.

If a single competitor lets the vendor learn from its work, the model that serves your whole industry improves, and the vendor’s hand strengthens against every buyer in it, including the ones who kept their discipline.

Narayanan and Kapur add the part Nadella leaves out, which is that you cannot hold this line alone. The flywheel needs only one firm in a sector to start it turning. If a single competitor lets the vendor learn from its work, the model that serves your whole industry improves, and the vendor’s hand strengthens against every buyer in it, including the ones who kept their discipline. Your own boundary protects your specific corrections. It does not protect you from the sector arming the vendor around you.

You do not lose your moat in a breach. You lose it in a thousand small acts of being helpful, some of them your own, some of them your rivals’.

Two kinds of exhaust, and how to tell which one you are leaking

Nadella treats exhaust as a single substance. It is not, and the distinction is practical.

In the book I use a simple two-axis instrument. One axis is verifiability: whether a task’s success can actually be checked, and how fast a failure would be caught. The other is organizational complexity: how many units a deployment touches, how deeply other systems depend on it, and how hard it would be to reverse.

Run exhaust through those two axes and it separates cleanly.

Low verifiability leaks your judgment. These are the tasks where success is contestable and the model is often wrong: strategic assessment, valuation, anything where the right answer depends on tacit context. This is also exactly the work where a human should remain the decision-maker, which means the wrong answers get caught and corrected, and corrections are the most concentrated form of institutional judgment there is. Notice the twist: the safer your posture, the richer the exhaust. This is the highest-value leak in the building.

It is also where you are most easily held. Narayanan and Kapur point out that judgment-heavy work has no objective standard of quality, so a buyer cannot verify the output even after the fact. Writing, strategy, judgment calls are credence goods, like the work of a lawyer or a consultant. Unable to compare quality, you fall back on trust and reputation, and you stay put. So the same weak verification that makes these corrections precious makes the vendor that holds them hard to leave. Low verifiability is where your judgment concentrates and where your exit narrows at the same time.

High complexity leaks your architecture. These are the deployments woven deep into how the company runs. The model may be right almost every time, so there are few corrections. But the traces are a map. Which tools get called in what order, which systems depend on which, where the handoffs are, what the exception paths look like. That is a blueprint of how your organization actually operates, as opposed to how the org chart says it does.

High verifiability plus low complexity leaks almost nothing worth having. This is the commodity zone. Document classification, code execution, data transformation. Let it run. The exhaust is worthless to a competitor because the task is worthless as a differentiator.

So the first question is not “how do I protect my data.” It is “which of the two things am I giving away, and is it the one that matters.” The answer depends on where the deployment sits, and most enterprises have never asked.

Your evals are worth more than your data lake

Nadella makes a point in passing that deserves more weight than he gives it. Evals, he writes, define what good looks like inside the organization.

Follow that all the way down.

Data is a record of what happened. Evals are a specification of what you consider good. Those are not the same kind of object, and they are not remotely the same value.

A competitor who has your evals knows what you value, how you score it, and where you draw the line.

A competitor who steals your data still has to work out what you were optimizing for. They have the outcomes without the standard. A competitor who has your evals knows what you value, how you score it, and where you draw the line. They have the standard, which means they can generate their own outcomes.

If evaluation is where human effort is concentrating, the eval suite is where your people’s judgment is accumulating, and that is precisely why it is worth more than the data it scores.

This is not only an enterprise observation. In his ICML keynote this month, Narayanan argued that as AI absorbs the building, human effort migrates toward exactly this work: away from developing the systems and toward evaluating and monitoring them, toward the tasks that are hardest to verify. His frame there is the whole field and the whole economy. Bring it down to a single company and it lands on the same object. If evaluation is where human effort is concentrating, the eval suite is where your people’s judgment is accumulating, and that is precisely why it is worth more than the data it scores.

Most enterprises spend enormous energy guarding the data lake, and then hand the eval suite to whoever will run it for them, because building evals is tedious and the vendor offers to help. That is the wrong trade, made in the wrong direction, for the most understandable reason in the world.

If you protect one thing inside the boundary, protect the definition of good.

You cannot enforce a boundary you cannot see

Here is the prerequisite the boundary quietly assumes, and where I think the practical failure will happen.

Every one of Nadella’s recommendations presupposes an organization that knows what its systems are doing. Retain ownership of your traces, feedbacks, and decisions. Build learning environments inside the tenant boundary. Make sure nothing crosses without consent. Each of these requires that you can see what you have deployed, what it touches, and what leaves.

Most enterprises cannot.

IBM surveyed 2,000 chief information and technology officers this year. Seventy percent said teams were deploying AI faster than IT could track. Seventy-seven percent said adoption was outrunning their governance. Those two numbers describe an organization that does not know its own perimeter.

The failure will not look like a breach. Your general counsel is not going to paste the merger memo into a consumer chatbot. A junior analyst is going to paste the comparable transactions in at eleven at night, because the deadline is at eight and the tool is right there and nobody told her not to. Multiply that by every team that stood up an agent this quarter without telling anyone, and the hard boundary is a diagram in a slide deck.

The map of how you work is a prize for the vendor for the same reason it is a necessity for you. So there is no neutral option. Either you build the sensing layer inside your boundary, or you rent it from the vendor, who then owns the map.

Visibility is also contested from the other side. Narayanan and Kapur note that the labs’ most lucrative escape, charging for outcomes rather than tokens, requires them to see inside your business processes, which means migrating into your System of Record. The map of how you work is a prize for the vendor for the same reason it is a necessity for you. So there is no neutral option. Either you build the sensing layer inside your boundary, or you rent it from the vendor, who then owns the map.

This is why I keep arguing that coherence is not a governance problem in the usual sense. It is a visibility problem first. You cannot govern, audit, permission, or protect what you cannot see. Information sovereignty has a prerequisite, and the prerequisite is knowing what you have.

To be precise about scope: sensing is the first layer of a larger stack the book lays out. There are only four places to intervene on incoherence. You can sense it, constrain it, contain it, or price it, making the team that creates a coordination burden bear the cost it imposes on everyone else. Above all four sits human judgment, reserved for what the lower layers surface. Nadella’s boundary will eventually need the whole stack. But sensing comes first by necessity, not preference: you cannot constrain, contain, or price what you cannot detect.

Build that layer, or the boundary is decoration.

Where to spend the money

The last gap is a budget question, and it is the one that will actually decide whether any of this gets done.

Trust boundaries are not free. Private evals, tenant-bound training environments, a genuinely model-agnostic orchestration layer: these are real investments in engineering and in organizational discipline. No enterprise can build them around everything. Any advice that implies otherwise will be ignored by the people who have to fund it, and they will be right to ignore it.

Narayanan and Kapur draw a line that helps here. They separate the value AI creates from the value anyone manages to capture. The value created will be vast. The open question is who keeps it. Apply that line one level down, inside your own firm. Your people create judgment-value every time they correct the machine. The only question that matters is whether you capture it or the vendor does.

Spend where the exhaust encodes judgment you could not replace and where the deployment is deep enough that its traces map how you actually work. Tolerate leakage where the task is a commodity, the failure is cheap.

The two axes tell you where to spend. Not all incoherence is worth preventing, and by the same logic, not all leakage is worth stopping. Spend where the exhaust encodes judgment you could not replace and where the deployment is deep enough that its traces map how you actually work. Tolerate leakage where the task is a commodity, the failure is cheap, and the trace tells a competitor nothing they do not already know.

An enterprise that hardens every boundary equally has misread the problem exactly as badly as one that hardens none. The first will spend itself into paralysis. The second will donate its judgment one correction at a time, and never see the invoice.

What it does not mean

One caution, because this argument is easy to overcook and the overcooked version is wrong.

Keeping important work away from AI is just retreat dressed as strategy, and it loses. Abstention just gets you slower, with none of the benefits.

The lesson is not “keep your important work away from AI.” That is a retreat dressed as a strategy, and it loses. A competitor who brings AI to their hardest, highest-judgment work, in the posture that work allows, assistance where verification is weak, autonomy where it is strong, and does it inside a proper boundary, gets two things you do not: the compounding and the protection. Abstention gets you neither. It just gets you slower.

There is a real cost to engagement, and Narayanan and Kapur name it. Leaning on a vendor’s AI can erode your unaided skill while building a vendor-specific dependence, a lock-in that works through your own people rather than your contracts. But that is a cost of careless engagement, not of the engagement itself. The answer is the same one the whole piece has been building toward: engage hard, own the loop, keep the orchestration model-agnostic so the skill you build is yours and portable. Abstention avoids the behavioral moat only by forfeiting the capability, which is the worst trade on the board.

There is a reason to move now rather than later. The moat Narayanan and Kapur describe is not yet built. Enterprises have so far been reluctant to feed their material into the flywheel, and the orchestration layer is still, for the moment, thin and swappable. That window does not stay open. The time to build the boundary is before the lock-in compounds, which is to say now.

In consuming intelligence, you are creating intelligence, and what you create should belong to you. The goal is not to stop feeding the machine. It is to make sure the loop closes inside your own walls.

Nadella has the emphasis right. In consuming intelligence, you are creating intelligence, and what you create should belong to you. The goal is not to stop feeding the machine. It is to make sure the loop closes inside your own walls, so that the judgment you spend every day encoding accrues to you instead of leaking to the firm that sold you the model.

That is the difference between an enterprise that compounds and one that is quietly farmed.

That question, whether the judgment you encode every day accrues to you or leaks to whoever sold you the model, is the subject of my book, Coherence, and of everything I am writing here between now and launch. If you are deciding where the boundary has to be hard and where to let the exhaust go, the one-page tool behind the two axes in this piece is the first thing I send when you join the list at coherise.com.

Comments

One response to “Your AI Usage Exhaust Is Someone Else’s Moat”

  1. […] feeds into it can improve the version its rivals rent tomorrow, which is the leakage I traced in Your AI Usage Exhaust Is Someone Else’s Moat. Read that way, Kirkland’s exclusivity clause is that essay’s prescription written into […]