Part I — THE PROBLEM
1.Rented Intelligence
the specific things an organization gives up when it consumes AI through vendor-controlled services. Assumes: the Introduction.
A compliance officer at a mid-sized health insurer receives a routine request from a regulator: describe how the AI-assisted claims summaries produced last quarter were generated, what data the system accessed, and what controls governed its behavior. The summaries came from a vendor-hosted AI assistant. The officer can produce the subscription invoice, the vendor's marketing security page, and the outputs themselves. She cannot produce the model version that ran in March, the reason it ran differently in April, a log of what context was sent with each request, or any way to re-create a single one of those summaries today.
Nothing in that scene involves a failure. Every product worked as designed. The problem is the design: the organization is a tenant, and tenants do not get the keys to the building's mechanical room.
What the lease actually costs
Most organizations consume frontier AI the same way: API access to models that run on vendor infrastructure, under vendor policies, at vendor prices, with vendor-controlled behavior that can change without notice. The whitepaper's opening section catalogs what this arrangement costs, and the list is worth reading as a lease agreement rather than as a technology critique.
Three of these compound, and get the longer look here.
Opacity. An organization that cannot inspect the system producing its work cannot audit that work, cannot reproduce it, and cannot explain it to a regulator, a customer, or a court. In unregulated contexts this is an annoyance. In healthcare, finance, government, and law it is disqualifying, and an increasing share of the economy is regulated context.
Lock-in. Dependency on a vendor's API is dependency on that vendor's pricing, roadmap, deprecation schedule, and behavior changes. The switching cost grows with every workflow built on top. Anyone who managed enterprise software through the last two decades of SaaS knows how this movie ends: the lease terms tighten as the tenant's alternatives shrink.
Context dissipation. The subtlest and, the paper argues, the most expensive. Every organization using AI is constantly teaching it things: terminology, policies, preferences, style, process. Under the rented model that teaching either evaporates when the session ends or accumulates in the vendor's logs, on the vendor's side of the property line. Section 2 is devoted to why this particular leak matters more than the others.
The market's own diagnosis
The strongest evidence that this is a real structural problem, rather than an infrastructure vendor's convenient framing, is who else says so.
A model's weights are the numerical parameters produced by training, the file that, copied and run, is the model; controlling the weights means controlling the model itself, which is what makes Nadella's sentence a sovereignty claim rather than a procurement preference. And the paper's observation about the pairing is fair: when the chief executive of the world's largest software vendor and one of the largest private owners of enterprise software arrive at the same diagnosis from opposite ends of the market, the diagnosis is probably not a niche complaint.
Why "buy instead" is not currently an option
Here is the part of the diagnosis that is easy to miss. An organization that reads the failure-mode table and decides to own its AI instead cannot simply purchase ownership, because there is no standard form of it. What does an owned AI deployment consist of? How do its capabilities get packaged, updated, replaced? How does the organization's knowledge get into it, and how is the work it produces checked? Every organization answering these questions today answers them alone, bespoke, at consulting rates.
The absence of a standard is itself the market failure. Everything else in this guide is, one way or another, a description of what that standard would have to contain.