It is an LLM contract clause that enterprise buyers seem to take real relief in. But the risk is not in what it says. It is in what it leaves unsaid.
Executives often say, “The contract says they won't train on my data.” Getting that in writing is the right thing to do. But as Satya Nadella pointed out, protecting your knowledge takes more than protecting your data.
The clause usually covers your files as an input. It often says nothing about the patterns drawn from them — and patterns are the part that matters. How a company makes money is often the most valuable part of the business: the pattern is the key point.
Lawyers have a word for this. A contract is silent on anything it does not name. Silence is not protection. It is just a subject nobody wrote down. Nadella names it plainly, calling it ironic that providers impose strict terms on their own models while reserving “the right to learn from customer usage and interaction data.”
A model can study how your work is shaped, then generate artificial examples with the same shape. None of it is your actual data, but it behaves like your data. This is synthetic data, and it is now standard practice.
A vendor can honour “no training on your data” to the letter and still end up with a model that has learned how your business runs.
This is not an accusation. It is a gap between what the words say and what buyers hear.
When reviewing a contract, make sure to look for two additional terms, or the lack of these terms. Get clarification on each:
Older contracts often let a vendor use your activity to improve or enhance the service. That wording was written before AI training existed — and it is broad enough to cover it.
Unless the contract defines this term, anything built from your data may not count as your data at all. Statistics, embeddings and summaries can all sit outside the definition.
Five questions turn a vague promise into something you can hold a vendor to.
Every question above exists because the model sits somewhere you do not control. Run it on your own infrastructure and most of them stop being contract problems. AIPod Mini keeps the model, the data and the learning inside the building.
A promise not to train on your data is worth having, but that promise might not cover replicating your knowledge. The only version that holds without a lawyer is the one where the model never leaves your building.
Read: “The Reverse Information
Paradox” by Satya Nadella, Chairman and CEO, Microsoft — snscratchpad.com
(Jul 12, 2026). Why prompts, agent traces and corrections leak more than the files do.
Also: “From Static to Dynamic — The Next Frontier of Self-Learning
AI” — Iterate.ai. Why models that keep learning make every silence matter more
over time.
A joint educational series on private AI and the AIPod Mini. NetApp — the governed data-control layer. Iterate.ai — the private intelligence layer.
