← Insights

Your AI Tool's Privacy Promise Isn't What You Think

Model instructions and product behavior are two different things. The Grok Build leak made that concrete — here's the board-level test every exec needs before signing off on an AI tool.

The Grok Build Leak Is the Case Study You Should Be Using

When the Grok Build incident surfaced, the detail that mattered most got buried in the noise: the model followed its instructions and declined to open restricted files. The product uploaded the entire repository anyway.

That gap — between what the model is told to do and what the product actually does — is the most important AI governance concept most non-tech executives still don't have a crisp mental model for. Nate Jones's private AI briefing uses this incident as the clearest public proof point yet that model-layer instructions do not constitute a product-layer security boundary. Approving a tool because its model card says "your data stays private" is like approving a contractor because they signed an NDA, then skipping the access controls.

What Bayer and Discovery Bank Are Actually Doing

Bayer and Discovery Bank didn't wait for better vendor promises. They're fine-tuning smaller local models on proprietary rules using LoRA — a technique that lets you adapt a model without sending your data anywhere. The setup Jones walks through runs on a laptop with the network switched off. This isn't a research project; it's a production approach to keeping sensitive compliance and financial logic off shared cloud infrastructure entirely.

For operators outside of tech, the practical implication isn't necessarily "run everything locally tomorrow." It's that a viable private-AI path now exists below the enterprise contract threshold, and the organizations stress-testing it first will have a real negotiating advantage when vendor conversations get serious in 12 months.

The One Question Every Board Should Ask Right Now

Jones offers a single sovereignty test worth handing to any exec approving AI tooling: Is the value locked in the model, or in your organization's corrections, permissions, and configurations layered on top of it? Microsoft's durability as a platform isn't the model — it's the institutional memory your team builds inside their permission and feedback systems. Migrate away and you leave that behind.

That's a vendor dependency that doesn't show up in a procurement checklist, and it compounds quietly over 18 months of normal usage.

Actionable takeaway: Before your next AI tool renewal or expansion decision, map which layer holds your organization's value — model, product, or data. If you can't answer that question, you don't have enough information to evaluate lock-in risk. Run Jones's laptop test with a small internal dataset this week. The result will tell you more than any vendor security questionnaire.