The One Selling You AI Could Be Your Next Competitor!
Imagine you buy an AI system for your company to help with data analysis and service improvement. After a while, you discover that the same company that sold you the system now knows all your secrets and has started offering services that compete with yours. This is not a science fiction scenario — it’s what Satya Nadella, Microsoft’s CEO, warned about in a shocking post last Sunday.

What’s the Problem Exactly?
Nadella says that companies using closed AI models (like ChatGPT from OpenAI and Claude from Anthropic) pay twice:
- Once with money: usage fees for the model (tokens)
- And once with your company’s secrets: which you unknowingly share with the model
How? Every time you write a command (prompt) for the model, correct its mistake, or let it use certain tools — you’re actually training the model on your work methods and business secrets. “Every correction you make becomes corporate experience that the model retains,” according to Nadella.
What Does This Have to Do with Saudi Arabia?
Saudi Arabia is currently undergoing a major digital transformation as part of Vision 2030. Many government agencies and private companies have started using AI in their services:
- Ministry of Health: using AI to analyze health data
- Banks: smart chatbots for customer service
- Telecom companies: analyzing customer data to improve services
- Education sector: customized smart education systems
All these uses mean that highly sensitive data is flowing through AI models owned by foreign companies. Nadella’s warning raises a big question: are Saudi citizens’ data protected?
What Solution Does Nadella Propose?
The man didn’t just come to warn — he also has solutions:
- Keep ownership of your data: don’t leave your data (commands, corrections, feedback) with the model provider
- Build a private learning environment: use the cloud to run your own models
- Use an “orchestration layer”: a system that lets you switch between different AI models instead of being tied to one

Open-Source Models: The Safe Alternative
It’s clear that Nadella (and Microsoft behind him) is encouraging companies to use open-source models and run them on private servers. And he’s not the only one — companies like Vercel and OpenRouter have seen a significant jump in the use of open models. Just last month, 29% of all traffic on the Vercel platform was for open-source models.
Solo.io, a company that provides AI security solutions, says its clients have started asking: “Why should I pay a lot of money for big models when I can use an open-source model that covers 90% of my work and costs much less?”
Important Points for Saudi Companies
- Data Sovereignty: government and citizen data needs extra protection according to Saudi regulations
- Regulation and Oversight: the Digital Government Authority and the Data and AI Authority (SDAIA) have clear controls for data use
- Local Hosting: using data centers within Saudi Arabia (like stc and Center3) reduces risks
- Research and Development: the Kingdom supports innovation in

❓ Frequently Asked Questions
Who needs these warnings?
Any company or government entity using AI in their operations — from banks and hospitals to schools and e-commerce stores. Even individuals using ChatGPT for work need to be cautious.
Where can AI models be run safely?
In local data centers in Saudi Arabia (such as stc or Google Cloud in the region), or on company-owned servers (on-premises). Some entities use approved government cloud solutions.
How much does it cost to run an open-source model?
Much cheaper than closed models. Some open models run on regular devices with costs starting from a few hundred riyals per month for basic use, while large commercial models can cost thousands of dollars per month.
How long does it take to adapt a model for local use?
From one week to one month, depending on the company size and system complexity. Ready-made models can be installed in two days, but extensive customizations may require more time.
How do I start protecting my data from AI models?
First step: Review the privacy policy of your current service provider. Second step: Consult an information security specialist. Third step: Try an open-source model (such as Llama or Mistral) on a test server. Most importantly — do not share sensitive data with any AI model without clear controls.
