Nvidia is the lead general of the AI era.
It sells compute. The hotter AI runs, the more it earns. It goes around telling everyone that AI is the new electricity, the new internet. In this wave, nobody has pushed harder than it has.
And then it started saying it needed to protect itself.
According to The Information, Nvidia restricts Anthropic's most capable models to low-sensitivity work like open-source projects; anything involving proprietary information — supply-chain monitoring, for instance — runs on its own Nemotron instead. It is not alone in this. Palantir has said it will not put Claude inside its platform without "irrevocable zero data retention." Booz Allen barred employees from using it on projects involving proprietary cybersecurity software. Microsoft also restricted internal access for a while. The trigger was a policy change Anthropic made in June: customer logs retained for thirty days, and up to two years for anything flagged by its safety systems — with the "zero data retention" that some enterprise customers had come to depend on removed.
And here is the most awkward part of all —
Nvidia is an investor in Anthropic, and Anthropic is a major buyer of Nvidia.
By any normal logic, their interests are bound together. And Nvidia still pulled its own employees off Claude.
The one who lit the fire got burned first.
But I don't intend to just retell the irony. This series isn't written to satirize anyone — the irony here is a signal, and what it signals is that our understanding of this has not caught up yet.
A company that pushes AI hardest, earns the most from it, and holds equity in the model vendor on the other side — and it still has to guard against AI. There must be a structure here that we have not yet looked at squarely.
This is the first article of Part II. It is time to pull the camera back.
1. The shovel seller can't see the process information
Think about the industry chain the traditional way: hardware companies sell chips, platform companies sell cloud, brain companies sell models. Nvidia's original reasoning was — use as much as you like; the more you use, the more of my chips you buy.
That is not how the structure actually works. The chips run in your data center, on your cloud. But the prompts, the knowledge base, the training data, the inference context, the enterprise workflows — all of it stops at the software layer of the model vendors and the cloud vendors. The model vendors don't just run on Nvidia's chips; they also quietly learn who is using them and for what.
So Nvidia supplies the most expensive thing in the AI era — compute — and cannot see the most valuable thing: how people think with that compute.
Nvidia has the muscle. The AI companies have the nervous system. The muscle is working for someone else, and the nervous system is siphoning off all the cognitive assets.
The chips are running. The context is somewhere else.
So why does it push NIM and Sovereign AI so hard, selling "inference runs inside the customer's own environment" as the pitch? On September 10 it and Palantir jointly released a "sovereign AI" offering: Nemotron installed inside Palantir's Foundry and AIP, running in the customer's own machine room. And the first customer for that system is Nvidia itself — starting with its own supply chain.
Boiled down, it's one sentence: don't leave me just selling iron — I want to climb one layer up. Otherwise it is only a power plant feeding the AI companies. However large the output, it is still just selling electricity.
2. But the sharper part: it uses Claude too
At the same time, Nvidia uses AI heavily itself — designing chips, building its software stack, making internal efficiency tools.
And the more it embraces AI, the more its own R&D thinking, technical roadmaps, and strategic direction flow to the model vendors as conversation records.
What it most needs to guard against is the very business it raised.
It is like an arms dealer who sells weapons to everyone, and only when it steps outside to fight does it discover: the enemy's weapons are the ones it made, and through the chat logs from selling them, the other side already knows its hand.
This deserves to be treated as a signal precisely because it is the player with the least reason to admit the problem in this entire wave. Its business rests on "the better AI gets, the more companies use it, the more chips I sell." Admitting that using AI can wound you in return is tearing down its own growth story. It has the lawyers and the platform to bury this entirely, or simply declare that it isn't a problem.
And it still chose to protect itself.
The player best equipped to defend itself, and most motivated to deny there is anything to defend against, defended itself anyway.
Then what about the companies with no legal team to negotiate ownership, no influence, and no ability to build their own models? And the ordinary employees who just want the work in front of them to go a little faster?
This is not "some company wasn't smart enough." It is a problem in the structure itself — the act of using AI is where handing over your thinking sovereignty begins.
3. This is not just my own worry
Here I have to look back at something I worried about a year ago: whether my boss could see my conversations with AI, and through them see straight through how I think.
Set the two side by side, and the structure is clear enough to be uncomfortable — in both cases the thing being recorded is a person's thinking process; in both cases the party holding the record is the one with more power; in both cases the demand is "the record belongs to me." Identical.
The only difference is leverage. A large company can demand zero data retention, or simply build its own model. An ordinary programmer can hardly negotiate terms with their own employer. The core of this is not technology. It is power.
Still — I once ranked that worry too high. A model vendor getting my conversations and my boss getting my conversations are not threats of the same order. What the vendor gets is scattered fragments, mixed in among millions of people, used to improve model safety and investigate abuse, and not about me personally. What the employer gets is a continuous trail, with full context, tied directly to my interests — used to evaluate performance, set pay, and decide who stays.
The model vendor is a sentry in the distance. The employer is a foreman sitting across from you.
But "most direct" does not mean "most important." My original worry was not unnecessary — it was just low in the stack. It is only the bottom layer of this structure.
Moving upward, the risk scales up. An individual loses privacy and job security. A company loses its core competitiveness. A nation loses the collective thinking process of its industry, its research institutions, and its government systems.
4. Big companies have exactly two moves
The first is technical isolation — I'll do it myself. Build your own model, pull open weights into your own machine room, or put the model on an internal network, physically cutting off the channel that data would leave through. This is the road Nvidia's Nemotron takes. You can borrow a brain. You cannot hand over the family assets.
The second is contractual constraint — you sign on the line. Zero data retention, no training on our data, audit rights, deletion rights, data residency requirements — replacing technical trust with a contract. Palantir's approach is to force the commitment into writing, with no changing your mind afterward. You can come work in my house, but no cameras — you don't even get to keep your own memory of it.
Each move has a cost, and large companies usually run them in separate pools — technical isolation for core business, contractual constraint for everything else.
5. The third path: give the keys back to the data's owner
What is genuinely worth watching is the concession on the model vendors' side.
The original logic was: a frontier model has to retain logs for some period in order to investigate jailbreaks and attacks. The enterprise reaction was: "not used for training" does not mean "the data never left your servers."
So a third option appeared. Enterprise Frontier Safeguards, announced by Anthropic on September 1: retained data sits in the customer's own cloud, with keys the customer manages; the vendor's automated systems can scan for anomalous signals but cannot reach the raw data; and if something genuinely suspicious turns up, the alert goes back to the enterprise's security team, reviewed by the enterprise's own people, with no Anthropic employee handling it. The program begins rolling out in stages this autumn — it is not something you have the moment you install it.
It used to be this: you talk to the model, and the model vendor listens and takes notes in the next room.
Now it is this: you talk in your own meeting room, and the model vendor can only stand outside watching the warning light. Whether it comes through the door is your call.
6. The individual edition of the same thing
Writing this, I stopped and looked at what I've been building.
The three principles of ai-tracedoc are the ones I wrote down in the second article: local by default, entirely voluntary, no admin back office.
Isn't that just the individual edition of that same arrangement? The data sits on my own machine — the counterpart of "in the customer's own cloud." Whether to share it is my decision — the counterpart of "the keys belong to the customer."
And it holds in the other direction too: the enterprise version of that thing is the enterprise version of ai-tracedoc.
On one side, contracts and commercial terms. On the other, code and local storage. The means are completely different, but both are saying the same sentence — my thinking process is not something someone else gets to keep for me.
7. Which is why there is now a fourth layer
This Nvidia episode turns the old three-layer structure into four:
Individual vs. employer — whose is my thinking process?
Company vs. model vendors and cloud vendors — whose is my business logic?
Nation vs. cross-border platforms — whose is my citizens' data?
Infrastructure layer vs. application and model layer — when someone supplies the compute, who owns the knowledge that surfaces while it is being used?
The fourth layer is new. And the fear at every layer has the same shape: I put in the core resource, and the process information was intercepted one layer up.
8. One layer further up
The EU's General Data Protection Regulation sets conditions on data leaving the bloc — transfer to a third country must fall under an adequacy decision, standard contractual clauses, or binding corporate rules, or it does not go. It does not prohibit transfer; it requires you to clear a threshold first. The US CLOUD Act shows a different face: the overseas data of American companies can be compelled, regardless of which country it is stored in. US legislation has required ByteDance to divest TikTok; India banned 267 Chinese apps.
The stated reasons differ. The underlying logic is the same: every sovereign state is bringing data inside the jurisdiction of its own law.
But the moves point in opposite directions. The EU is conditional release; the US is unilateral compulsion — one is setting a threshold, the other is reaching across.
This is not an ideological contest. After territory, territorial waters, and airspace, data is becoming the fourth dimension of sovereignty. And when a nation's industry, research institutions, and government systems all depend on external frontier models, its collective thinking process is being observed and absorbed by an outside entity. This requires no conspiracy. It is the necessary result of the technical architecture.
9. One move, four scales
Nvidia poured money into compute and pushed AI as far as anyone, and in the end it cannot see the most valuable part. What that shows is:
Once process information can be recorded, transmitted, and accumulated, "who supplied the resource" stops being the answer to how power is distributed. "Who can see the process" is.
At the individual scale that sentence is called privacy. At the company scale, sovereignty. At the national scale, digital borders. At the infrastructure scale, ecological niche. They are four scales of one thing.
And the small thing I'm building happens to sit at the very bottom — because every sovereignty above it is ultimately built on an individual's command over their own thinking process.
Nvidia still has cards to play — build its own model, push Sovereign AI, issue an internal rule. Most companies can't do that. Most individuals certainly can't.
So this should not be filed away as "a game among giants" and forgotten. It is a problem sinking downward — it lands on Nvidia today, and on your desk tomorrow.
The only difference is: whether you've kept a ledger for yourself.
This is the first article of The AI Thought Quartet, Part II: Sovereignty and Practice. There is one more in the Sovereignty half: the recorded process information that is pushing the battlefield of data security from the "vault" toward the "stream."
Top comments (0)