K Koda Intelligence
DEEP DIVE DEEP DIVE № · 15 September 2026DOCKODA-20260915-5FBAFADA779Csha-256 of date + article + 24 claims
FILED 15 SEPTEMBER 202624 CLAIMS CHECKED · 12 VERIFIED

The sellers are quietly caging their own product

Palantir and Nvidia both sell AI, and both now limit how frontier models from Anthropic and OpenAI run inside their own walls. In the same week, Microsoft published a provisional code of conduct on September 1404 and the three biggest labs opened talks on shared standards. None of it is about a benchmark. Deloitte finds 73%23 of enterprise leaders name data privacy as their top AI risk, and Cyberhaven traces 39.7% of data moving into AI tools to sensitive content.

7 MIN READ · BY THE KODA EDITORIAL TEAM · STRATEGY · DATA GOVERNANCE
TOP AI RISK73%VERIFIED CLAIM 23DELOITTE 2026
GENAI DEPLOYED30%VERIFIED CLAIM 24↑ 5X SINCE 2023
AGENT TRUST GAP71%NOT MEASUREDCAPGEMINI
TOP AI RISK73%DELOITTE 2026 GENAI DEPLOYED30%↑ 5X SINCE 2023 AGENT TRUST GAP71%CAPGEMINI SENSITIVE FLOWS39.7%CYBERHAVEN SHADOW AI COST$670,000IBM 2025 AI SECURITY SPEND$51.3B↑ 2X VS 2025 GENAI BREACH RATE89.5%↑ 14.4PP ON-PREM SHARE53.8%IMARC

Palantir sells AI to the Pentagon. Nvidia sells the chips that every frontier lab runs on. According to a report in The Information, both companies are now limiting how certain frontier models from Anthropic and OpenAI can be used inside their own walls. The fear is not that the models are dumb. The fear is where the data goes.

The same week brought three more constraints. Microsoft published a provisional code of conduct on September 1404 that proposes to commit its future models to refuse weapons and dangerous-substance requests before those models exist. OpenAI's CFO signaled a longer road to an IPO, and Sam Altman ruled out a 2026 listing on safety grounds. Google DeepMind, OpenAI, and Anthropic opened talks on a shared frontier standards body.

Four constraints. One week. Not one of them is about a benchmark score. Here is my read: enterprise AI adoption will be gated by data governance, not model capability. Builders who design for the trust boundary will sign contracts that benchmark chasers never see.

One admission up front. I do not have Nvidia's internal rulebook, and The Information's report is thin on specifics. What I have is a pattern, backed by survey data from Deloitte, Capgemini, AvePoint, and IBM. The pattern is strong enough to act on.

Perimeter Over Parameters

Every model launch fights over parameters. How big, how fast, how many points on which leaderboard. Every enterprise contract fights over the perimeter. Where do the bytes sit, who keeps them, and can you prove it.

PERIMETER OVER PARAMETERS · SEPTEMBER 2026DELOITTE · CAPGEMINI · IBM · CYBERHAVENBASE: 24 CHECKED CLAIMS, 4 SHOWN

What enterprise buyers actually audit before any model reaches production.

Data privacy named top AI risk Deloitte State of AI in the Enterprise 2026 · enterprise leaders VERIFIED CLAIM 23
73%
Sensitive content in AI data flows Cyberhaven 2026 AI Adoption & Risk Report · real-world movements NOT MEASURED
39.7%
Average deployment delay Governance gap · stalled enterprise rollouts NOT MEASURED
~6 MONTHS
Shadow AI added to average breach IBM 2025 Cost of a Data Breach NOT MEASURED
$670,000

Call the framework Perimeter Over Parameters. It has three tests, and I want you to memorize them as the three Rs. Residency: where does the data physically live during inference? Retention: who stores prompts and outputs, and for how long? Receipts: can you show an auditor the answers to the first two?

The numbers back this up. The perimeter is what buyers actually lose sleep over. Deloitte's State of AI in the Enterprise 2026 found 73%23 of enterprise leaders name data privacy and security as their top AI risk. Capgemini reports generative AI deployment rose from 6% of organizations in 2023 to 30%24 in 2025, a 5x jump. Yet the same Capgemini report found 71% cannot fully trust autonomous agents and only 46% have governance policies in place.

That gap costs time. The average delay was nearly six months. Six months of stalled deployment is six months of revenue that no model vendor collects, no matter how good the model is.

Sellers Caging Their Own Product

Alex Karp went on CNBC on July 1, 202618 and said something buyers should sit with. "Are we really going to outsource the battlefield of this country to the consensus view in Silicon Valley? That is effing insane." Strip out the politics and the argument is about residency. Karp treats every API call to a frontier lab as data leaving the perimeter.

The risk isn't AI itself; it's not understanding how AI is actually being used.· NISHANT DOSHI, CYBERHAVEN CEO · 2026

Palantir backed the talk with contract pressure. September reporting says Palantir pressed Anthropic for irrevocable zero-data-retention guarantees before allowing its models through Palantir's platforms. Palantir's own AIP security documentation says third-party model providers retain no customer data from prompts or completions. Provider personnel cannot access that data, and it is discarded immediately after the completion returns.

Look at what Palantir actually sells. Ontology sits between a customer's data and whatever model runs on top of it. It controls what the model can see and what actions it can take. Palantir is a governance company that rents intelligence, not an intelligence company that adds governance.

Nvidia's move rhymes. On October 28, 202501, at GTC in Washington, D.C., Nvidia announced it would integrate open Nemotron models and CUDA-X libraries directly into Ontology. Lowe's was among the first customers for supply chain logistics. The pitch was operational AI inside the customer's environment, with open weights the customer controls.

Here is the contrast that matters. Amateurs read the restriction story as abstinence. The evidence suggests it is a cage, not a fast. Reporting on Nvidia's internal rollout describes roughly 10,00002 employees using GPT-5.5 through dedicated virtual machines with zero-data-retention terms and read-only production access. Use the frontier model, but wrap it in steel.

Apply beginner's mind here, shoshin, and look at the situation as if you had never seen a leaderboard. A company holds sensitive data. A vendor offers a model that is a few points smarter. The downside of a leak is asymmetric to the upside of those points. IBM's 2025 Cost of a Data Breach report found shadow AI added about $670,000 to the average breach, and 63% of AI-breached organizations had no governance policy or were still writing one.

The actual data flows show the fear is rational. Cyberhaven's 2026 AI Adoption & Risk Report, built on billions of real-world data movements, found 39.7% of data moving into AI tools involves sensitive content. Cyberhaven CEO Nishant Doshi put it plainly: "the risk isn't AI itself; it's not understanding how AI is actually being used." A boundary you cannot see is a boundary you cannot defend.

Two honest caveats. Capability still binds in some domains: a governed but brittle agent fails in medical diagnosis just as surely as an ungoverned one. And it is unclear whether irrevocable zero-retention terms are available to any buyer smaller than Palantir. Anthropic can afford to give Palantir a bespoke contract. It may not give one to a 40-person startup.

The cage, the cap and the receipts

SHADOW AI
$670,000

Ungoverned usage is now a line item.

IBM's 2025 Cost of a Data Breach report found shadow AI added about $670,000 to the average breach. In 63% of AI-breached organizations there was no governance policy, or one still being written.

PERIMETER SPEND
$51.3B

Money is moving toward safer before smarter.

Gartner puts worldwide AI spending at $2.59 trillion in 2026, up 47% from 2025. Inside that, AI cybersecurity reaches $51.3 billion, nearly double the $25.9 billion spent in 2025.

MARKET SPLIT
2031

A regulated tier and a commodity tier.

IMARC already shows on-premises deployment holding 53.8% of the AI governance market, the shape of a tier that pays a premium for receipts. How large the middle stays is unresolved, and builders who assume every buyer wants the paranoid tier will overbuild.

2031: The Boundary Becomes the Moat

Pull back five years. Gartner forecasts worldwide AI spending of $2.59 trillion in 2026, up 47% from 2025. Inside that, AI cybersecurity spend reaches $51.3 billion, nearly double the $25.9 billion of 2025. Money is flowing toward making models safer faster than it flows toward making them smarter.

A flywheel is forming. Governance tooling lets more sensitive data reach production. More sensitive data in production makes breaches more visible. AvePoint recorded generative AI breach rates climbing from 75.1% of organizations in 2025 to 89.5% in 2026. Visible breaches buy more governance tooling, and the wheel turns again.

Think about impermanence. The frontier model that tops the leaderboard today is a commodity within eighteen months, and every release cycle proves it. The contract that says "our data never leaves our perimeter" does not expire when the next model ships. Benchmarks are accounting. Boundaries are cash.

The standards-body talks between Google DeepMind, OpenAI, and Anthropic push in the same direction. If the three biggest labs agree on shared capability ceilings, then capability stops being a differentiator among them. Microsoft's September 1404 code of conduct is the same move, made unilaterally. When vendors cap the top of the range themselves, buyers compare on trust.

Apple ran this playbook once. Its 2019 Las Vegas billboard, "What happens on your iPhone, stays on your iPhone," did not claim a faster chip. It counterpositioned against every ad-funded rival on a dimension they could not copy without breaking their business model. Palantir and Nvidia are counterpositioning against API-first frontier labs in exactly the same way.

I think the market splits in two by 2031. A regulated tier runs open weights inside the perimeter and pays a premium for receipts; IMARC already shows on-premises deployment holding 53.8% of the AI governance market. A commodity tier accepts standard SaaS terms for low-sensitivity work and picks on price. The data is mixed on how large the middle stays, and builders who assume everyone wants the paranoid tier will overbuild for a market that cannot pay.

Draw the Boundary Before the Demo

Most builders demo capability first and negotiate governance last. Flip it. Do the three Rs before you write a line of agent code, and you can do this without a CS degree.

First, pick one dataset your product will touch and classify it in plain language. Customer emails, support transcripts, source code, whatever. Write down who would be hurt if it leaked. That single sentence is your Residency requirement.

Second, write a one-page trust sheet with three headings: Residency, Retention, Receipts. Under each, state what your system does today, not what you hope. If the honest answer is "prompts go to a third-party API and we do not know how long they keep them," write that. A damaging admission on paper beats a discovery during a customer's security review.

Third, run every tool you are evaluating through the sheet. Take Botric AI, which pitches a customer service agent. Pilot it on one intent and measure containment, but also ask where the transcripts sit and who trains on them. Take Ramen Aura 1.010, the Unity and Unreal agent with persistent project memory. Persistent memory is a retention question by definition, so ask where that memory lives before you hand it a Blueprint task.

Do the same for the smaller ones. LINE Yahoo's Agent i task mode watches keywords and price drops on a schedule; check what the scheduled job can read. OneUp lets you reply to comments on Facebook, Instagram, LinkedIn, TikTok, YouTube, and Google Business from one place; that inbox is a data flow crossing your perimeter. Neither is dangerous. Both need a line on the sheet.

Things will break. Your first trust sheet will have three holes, and a buyer's security team will find a fourth. That is the job, not a failure. Decide at 70% confidence, ship the sheet with the demo, and fix the holes in public.

Get your reps in on the boundary. The model will change three times before your contract renews. The perimeter is the part you get to keep.

DOJO · BUILD THIS WEEKEND

Draw the trust boundary before you build the demo.

  1. Classify one dataset in plain language. Pick the single dataset your product will touch, name it (customer emails, support transcripts, source code) and write one sentence on who gets hurt if it leaks. That sentence is your Residency requirement.
  2. Write a one-page trust sheet. Three headings only: Residency, Retention, Receipts. State what your system does today, not what you hope, and if the honest answer is that prompts go to a third-party API with unknown retention, write that down before a customer's security review finds it.
  3. Run every tool through the sheet. Pilot a customer service agent like Botric AI on one intent and measure containment, but also ask where transcripts sit and who trains on them. With Ramen Aura 1.010, persistent project memory is a retention question by definition, so ask where that memory lives before handing it a Blueprint task.
Train the full skill in The Dojo
THE BOTTOM LINE

Benchmarks are accounting. Boundaries are cash.

Four constraints landed in one week, and not one of them was a leaderboard score. Palantir pressed for irrevocable zero-data-retention terms, Nvidia wrapped roughly 10,00002 employees on GPT-5.5 in dedicated virtual machines with read-only production access, Microsoft capped its own unbuilt models on September 1404, and the three biggest labs started talking about shared ceilings. When vendors cap capability themselves, buyers are left comparing trust, and Capgemini's finding that 71% cannot fully trust autonomous agents while only 46% have governance policies is the whole opportunity. Ship the three Rs first and the contracts follow.

LISTEN · AUDIO BRIEFINGThe conversation · ~19 min
WATCH · VISUAL NARRATIVEAnimated breakdown · ~2 min
PLAY · YOUTUBE
EDITORIAL RECEIPTKODA-20260915-5FBAFADA779C
As of15 September 2026MethodClaim extraction, dated-evidence review, and temporal consistency gate.CorrectionsContact the Koda desk
EVIDENCE24 CLAIMS CHECKED · 12 VERIFIED · 11 REPORTED · 1 FAILED
12 verified11 reported1 failed
  1. 01On October 28, 2025, at GTC in Washington, D.C., Nvidia announced it would integrate open Nemotron models and CUDA-X libraries directly into Palantir's Ontology.REPORTEDMOSTLY TRUEMODEL
  2. 02Reporting on Nvidia's internal AI rollout describes roughly 10,000 Nvidia employees using GPT-5.5 through dedicated virtual machines with zero-data-retention terms and read-only production access.VERIFIEDTRUEMODEL
  3. 03Palantir sells AI to the Pentagon.VERIFIEDTRUEFEATURE
  4. 04Microsoft published a provisional AI code of conduct on September 14 that commits Microsoft's future models to refuse weapons and dangerous-substance requests.REPORTEDMOSTLY TRUEFEATURECORRECTED IN COPY
  5. 05Palantir's AIP security documentation says third-party model providers retain no customer data from prompts or completions.VERIFIEDTRUEFEATURE
  6. 06Palantir's AIP security documentation says third-party model provider personnel cannot access customer prompt and completion data, and the data is discarded immediately after the completion returns.VERIFIEDTRUEFEATURE
  7. 07Palantir's Ontology sits between a customer's data and the AI model running on top of it, controlling what the model can see and what actions it can take.REPORTEDMOSTLY TRUEFEATURE
  8. 08Lowe's was the launch customer for the Nvidia and Palantir Ontology integration, for supply chain logistics.REPORTEDMOSTLY TRUEFEATURECORRECTED IN COPY
  9. 09Botric AI pitches a customer service AI agent.REPORTEDMOSTLY TRUEFEATURE
  10. 10Ramen Aura 1.0 is a Unity and Unreal agent with persistent project memory.VERIFIEDTRUEFEATURE
  11. 11LINE Yahoo's Agent i task mode watches keywords and price drops on a schedule.VERIFIEDTRUEFEATURE
  12. 12OneUp pulls replies from Facebook, Instagram, LinkedIn, TikTok, YouTube, and Google Business into one inbox.REPORTEDMIXEDFEATURECORRECTED IN COPY
  13. 13According to The Information, Palantir and Nvidia are limiting how frontier AI models can be used inside their own companies.REPORTEDMOSTLY TRUEATTRIBUTIONCORRECTED IN COPY
  14. 14OpenAI's CFO signaled a longer road to an OpenAI IPO.REPORTEDMOSTLY TRUEATTRIBUTION
  15. 15Sam Altman ruled out an OpenAI IPO listing in 2026 on safety grounds.VERIFIEDTRUEATTRIBUTION
  16. 16Google DeepMind, OpenAI, and Anthropic opened talks on a shared frontier AI standards body.REPORTEDMOSTLY TRUEATTRIBUTION
  17. 17Claim removed during the check; its text is not republished.FAILEDFALSEATTRIBUTIONCUT FROM COPY
  18. 18Alex Karp appeared on CNBC on July 1, 2026 and said: "Are we really going to outsource the battlefield of this country to the consensus view in Silicon Valley? That is effing insane."REPORTEDMOSTLY TRUEATTRIBUTION
  19. 19September reporting says Palantir pressed Anthropic for irrevocable zero-data-retention guarantees before allowing Anthropic's models through Palantir's platforms.REPORTEDMOSTLY TRUEATTRIBUTION
  20. 20Cyberhaven's 2026 AI Adoption & Risk Report is built on billions of real-world data movements.VERIFIEDTRUEATTRIBUTION
  21. 21Nishant Doshi is CEO of Cyberhaven and said: "the risk isn't AI itself; it's not understanding how AI is actually being used."VERIFIEDTRUEATTRIBUTION
  22. 22Apple ran a billboard in Las Vegas in 2019 reading "What happens on your iPhone, stays on your iPhone."VERIFIEDTRUEHISTORY
  23. 23Deloitte's State of AI in the Enterprise 2026 report found 73% of enterprise leaders name data privacy and security as their top AI risk.VERIFIEDTRUESTAT
  24. 24Capgemini reports generative AI deployment rose from 6% of organizations in 2023 to 30% of organizations in 2025.VERIFIEDTRUESTAT

Every claim listed here was extracted from this article and checked against live sources before publication. The verdict is the checker's, not the writer's. Claims the check removed are counted but not republished.

Audit receipt KODA-20260915-5FBAFADA779C
Filed underStrategyDeep Dive15 September 2026
Browse the Deep Dive archive

Get the morning Signal

172 editions so far, one a day. Unsubscribe anytime.