%20(1).jpg)
Zero data retention is today a promise, not an architecture. As enterprise knowledge flows into the models, a new trust layer of harnesses, on-premise AI, and AI-native security is opening up for builders, and India's AI startups are positioning to operate it.
Enterprise AI's binding constraint is shifting from what the models can do to what happens to the customer's data. For the first time, that gap can be measured at the wire. On 12 July, a security researcher publishing as cereblab routed xAI's Grok Build coding tool through an interception proxy and documented exactly what it transmits. The results were arresting. On a 12 GB repository of files the model never read, the coding task itself required about 192 KB of traffic. A separate storage channel moved 5.1 GB, a roughly 27,800x gap between what the model needed and what left the machine. The upload carried the entire Git repository, including files not accessed and the full commit history. A planted credential appeared verbatim and unredacted in the captured traffic. A second researcher, Hari Krishnan, reversed the binary itself and confirmed a background collector operating outside the tool's permission system.
The instructive detail is not the upload. It is that the controls pointed the wrong way. Disabling the “Improve the model” toggle did nothing to stop the transmission, because that setting governs training consent, not whether code leaves the machine. xAI switched the behaviour off within a day through a server-side flag, while the upload code remains in the shipped binary.
The remediation was fast, and the company says zero data retention customers were never affected. Both points deserve to be stated fairly. Yet, the episode confirmed what enterprise buyers have long suspected: zero data retention is today a promise, not an architecture. Closing the distance between the two is an engineering problem, and engineering problems can create market openings.
This is the third piece in a series for Inc42. The first argued that AI will be paid for outcomes rather than tokens. The second argued that control, not capability, will decide enterprise AI. This one is about the core of the applied AI thesis at work: the data it ingests.
Satya Nadella calls it intelligence exhaust. In an essay published on 12 July, the Microsoft CEO argued that AI has inverted the economics of information. Enterprises now pay for intelligence twice, once in money and once in “the proprietary knowledge you must reveal to make that intelligence useful.” Every engagement generates exhaust that gradually captures how an organisation operates, and every correction is distilled into institutional know-how.
Eleven days earlier, Palantir CEO Alex Karp told CNBC that his enterprise customers are livid because, in their view, the labs are “stealing the weights and alpha” of their businesses.
Both men have commercial positions in this fight, Karp selling the control layer and Nadella selling the cloud beneath the model, and their warnings should be read with that in mind. The signal is that a partner and a competitor of the frontier labs converged on the same alarm within a fortnight.
The mechanism under contention deserves precision. In the SaaS era, customer data sat inert in a vendor's database, fenced by contract and accessible only to the customer. AI interactions are different. Prompts, workflows, corrections, and approvals form trajectories that can improve a model, which means customer knowledge can, in principle, become vendor intellectual property.
Industry observers have noted that current zero data retention practice is a superficial form of privacy: even where the prompt itself is deleted, there is no strong technical guarantee that the surrounding interaction signals a user generates are not retained in some form, because the industry has not yet built the machinery to make that guarantee. They also note that when a specific technical accusation circulates, the absence of a specific technical rebuttal from the labs is itself information the market prices.
Enterprises will respond the way they always have, by rebuilding the perimeter, and this time it will be rebuilt in five layers.
Each of these layers is an opening for new companies, because the frontier labs are conflicted owners of every one of them. Three opportunities stand out.
Harnesses will be the first. The harness is the software through which people work with AI, and it is becoming the layer that encapsulates trust inside the enterprise. Whoever controls the harness controls what leaves the perimeter, what context the model sees, and what evidence exists afterwards. A lab that sells intelligence by the token cannot credibly referee its own data intake, which makes the harness a large, contestable category for independents.
Vertical AI deployed inside the customer's perimeter is the second. Enterprises will pay a premium for models trained and operated on-premise against their most sensitive assets: schematics, design documents, source code, and proprietary research. The economics of open-weight models now make this viable at a fraction of frontier API costs.
AI-native security is the third, and the least built. Detecting and preventing model-bound exfiltration is a new discipline, not an extension of data loss prevention. Confidential meeting notes, internal documents, and support tickets are all potential training inputs, and the tooling to police that flow barely exists. The wire-level canary methodology that exposed Grok Build is a preview of an AI auditing industry that does not yet operate at scale. India's GCCs and IT services firms are natural builders and operators of this trust layer for global enterprises. The institutions that ran the world's ERP systems, cloud migrations, and security operations centres are positioned to run its AI perimeter, and this is implementation revenue with a sovereignty premium attached.
The SaaS era rested on an accord that took two decades to establish: enterprises would place their data on vendor infrastructure, and vendors would guarantee they had no access to it and no use for it. That bargain underwrites trillions of dollars of market value today.
AI inherited this trust by default and is currently drawing the account down. The vendors and builders who restore it, with guarantees that are architectural rather than contractual, will win the enterprise phase of AI. Capability sets the floor of this market. Trust will set its ceiling.
DISCLAIMER
The views expressed herein are those of the author as of the publication date and are subject to change without notice. Neither the author nor any of the entities under the 3one4 Capital Group have any obligation to update the content. This publications are for informational and educational purposes only and should not be construed as providing any advisory service (including financial, regulatory, or legal). It does not constitute an offer to sell or a solicitation to buy any securities or related financial instruments in any jurisdiction. Readers should perform their own due diligence and consult with relevant advisors before taking any decisions. Any reliance on the information herein is at the reader's own risk, and 3one4 Capital Group assumes no liability for any such reliance.Certain information is based on third-party sources believed to be reliable, but neither the author nor 3one4 Capital Group guarantees its accuracy, recency or completeness. There has been no independent verification of such information or the assumptions on which such information is based, unless expressly mentioned otherwise. References to specific companies, securities, or investment strategies are not endorsements. Unauthorized reproduction, distribution, or use of this document, in whole or in part, is prohibited without prior written consent from the author and/or the 3one4 Capital Group.
At 3one4 Capital, the team has intentionally built a long-term commitment to responsible investing and to support the evolution of an ecosystem conducive to RI. This active commitment has helped the firm secure the signatory status to the UN PRI.
3one4 Capital has been ranked by Preqin, a global reference database for asset management, as India’s top performer for two of its funds, in the recent Alternative Assets report. The seed and early-stage funds managed by the firm have been recognized for their performance amongst the India-focused venture capital funds in this Asia Pacific-focused report published in 2021. With industry-leading Net IRRs, 3one4 Capital’s Rising I & Fund II are the top two amongst the best performing India-focused VC funds between the vintage years, 2010- 2018.