Your policy says do not paste confidential documents into public AI. Public AI… meaning a language model that is shared with others, including your rivals. That’s a good policy. It also assumes the documents are the valuable part. But that is not entirely true.
You are driving and you see blinking lights half a mile ahead, an ambulance on the shoulder, brake lights spreading back. You know there has been a crash. You did not see it. Three ordinary signals were enough.
That is pattern recognition, and it is what a shared model receives from your company whether or not a single file is ever uploaded. What your people ask about. How often. In what words. When. What they correct, and what they quietly stop asking about.
One more thing leaves with every prompt: who sent it. You authenticate to use the service, so the account is known, and the role usually follows from the questions. “Somebody there asked about nickel” is a rumour. “Their VP of Engineering asked forty times in six weeks” is intelligence. Inside the model this is also a spatial problem: meaning is stored as coordinates, so a run of questions is not a list. It is a position, and a direction of travel.
The files were never the asset. The shape of what you ask is.
Stripping the specifics protects the record, not the shape: how often you asked, in what order, and what you corrected.
Who gains is the surprise. Two rival R&D teams on the same model are not mainly a risk to each other; both are already watching. The advantage lands with a third party outside the industry. It is Jeff Bezos at the 1994 American Booksellers’ convention, learning the book trade before competing with it. It is the supplier serving every manufacturer in a category, who knows who is scaling from order volumes alone.
The questions never become somebody else’s signal: prompts, responses and tool calls stay on NetApp® storage you own.
The Puzzle Effect — fragments assembling into a picture; this brief is its harder cousin, no fragments required. The One-Way Learning Loop — what a shared model keeps. Synthetic-data range from 2026 industry analysis, per the claims register.
A joint educational series on private AI and the AIPod Mini. NetApp — the governed data-control layer. Iterate.ai — the private intelligence layer.