Tech brief

What the contracts actually guarantee

Enterprise training, Zero Data Retention, and the All-In leak claim — 16 September 2026.

Last updated: 2026-09-16

This is the contract follow-on to The Door They Meant. The math essay keeps the theorem and the process in separate columns. This page answers the question the All-In episode then asked in public: what do enterprise AI plans actually promise, what Zero Data Retention covers, and why a Codex session is not the same object as Microsoft Copilot.

It does not choose a vendor. The worked example is a Canadian federally regulated credit union, because that is a shop that already has a Data Protection Addendum for email and is now being told the same cloud “leaks IP into the models.”


Why this matters now

A federal credit union already sends member files, staff email, and internal drafts through Microsoft 365. Microsoft Copilot, used under a commercial tenancy, sits under the same Data Protection Addendum as Exchange and SharePoint: Microsoft is the processor, and prompts, responses, and Graph data are not used to train foundation models. That is a real contractual default. It is not a physics law, and it is not Zero Data Retention.

On 11 September 2026 the All-In Podcast told a different story. Chamath Palihapitiya called Zero Data Retention a commercially best-efforts promise. David Friedberg said a later model recited unpublished scientific work from an earlier chat. The same week, NYU mathematician Tristan Buckmaster alleged that OpenAI’s Navier–Stokes effort may have been steered by rumor and by Codex sessions. OpenAI first wrote that it could not rule out “de-identified data derived from their usage,” then updated on 10 September that those Codex prompts could not have influenced the system, including through training.

Those three stories are being treated as one fact: “corporate IP leaks into the models.” They mix consumer Codex, an API storage control, a Copilot tenancy, and the ordinary truth that a language model can later sound familiar without having stored your prompt.

OSFI’s revised Guideline E-23 – Model Risk Management, published 11 September 2025 and effective 1 May 2027, already treats vendor AI as a model. The United States’ SR 26-2 does not treat generative and agentic systems the same way. Canada does. Every AI option in this paper — Copilot, Azure-hosted models, a direct OpenAI or Anthropic API, a consumer ChatGPT login — belongs in the model inventory if its inherent risk is non-negligible.

This primer answers the three questions in order. What do enterprise plans actually guarantee? What does Zero Data Retention guarantee? Why is All-In saying IP leaks into models?


The tech ladder

The market sold one slogan. The stack is six different machines. Mixing them produces a sentence no auditor can test.

Step 1 — Inference has to see the prompt. A foundation model is a general-purpose system trained on a large public corpus, then aligned so it answers instructions. Inference is the live step: your prompt goes in, a completion comes out. Nothing useful happens unless the provider’s computers temporarily hold the text. “The vendor never sees our data” is false for every hosted model, including Copilot. The live question is what happens after the answer returns.

Step 2 — Consumer products train unless you opt out. OpenAI’s individual ChatGPT and Codex products may use conversations to improve models unless the user turns off “Improve the model for everyone.” Even after that opt-out, a thumbs-up or thumbs-down can put the whole thread back into training. Codex has a separate control for training on full coding environments. This is the surface Buckmaster used. It is not ChatGPT Enterprise, and it is not Microsoft Copilot.

Step 3 — Enterprise products default to no shared-model training, and still keep logs. OpenAI does not train on ChatGPT Business, Enterprise, Edu, Healthcare, or API inputs and outputs by default. Anthropic’s commercial terms say Anthropic may not train on Customer Content from the Services. Google’s Workspace Service Specific Terms contain a Training Restriction. Microsoft Copilot says prompts, responses, and Graph data are not used to train foundation models. Azure’s “models sold by Azure,” including Azure OpenAI, add that prompts are not available to OpenAI and are not used to train foundation models without permission.

None of that is Zero Data Retention. Default API products still retain prompts and completions for about 30 days so the vendor can run the service and watch for abuse. Anthropic’s commercial API deletes backend copies within 30 days unless a longer-lived feature, a Zero Data Retention deal, Usage Policy enforcement, or law says otherwise. Claude for Work keeps chats so the product works; deleted chats leave backend storage within 30 days.

Step 4 — Zero Data Retention is a storage control on named endpoints. OpenAI’s 19 August 2026 definition is the cleanest public sentence in the category: eligible API customers get a promise that OpenAI does not retain prompts or model responses after a request is processed; personnel do not get those prompts for review, except where law requires it; enterprise data is not used to train models unless the customer opts in. Anthropic’s Zero Data Retention arrangement, for approved commercial API customers, is the same idea: do not store inputs or outputs except to comply with law or combat misuse, while still keeping UserSafety classifier results.

ZDR is not automatic. It is sales-approved, endpoint-limited, and full of features that require storage. It is also not the Copilot control. Microsoft does not sell Copilot under that name. The Azure analogue is modified abuse monitoring: eligible customers can stop Microsoft storing prompts for human abuse review. Classifiers still run.

Step 5 — Safety, files, search, and personal logins reopen the pipe. Anthropic’s Covered Models (Mythos-class and Fable 5 / 5.1) require 30-day retention of prompts and outputs even in Zero Data Retention organizations; those models error or sit disabled unless retention is turned on for that workspace. OpenAI still retains CSAM-flagged images for manual review under Zero Data Retention, as 18 U.S.C. § 2258A requires. OpenAI can move a customer to Eyes Off or Safety Retention. Files APIs, Assistants, threads, batches, fine-tunes, and vector stores keep application state even when the org flag says Zero Data Retention. Google Search grounding stores derived queries for up to three days with no off switch; Maps grounding stores prompts and output for 30 days. Microsoft Copilot web queries go to Bing under the consumer Microsoft Services Agreement, not the commercial Data Protection Addendum. They are not used to train foundation models. They are also outside HIPAA/BAA coverage and the EU Data Boundary.

Step 6 — A later similar answer is not proof of training. Language models are pattern machines. They can later produce a method that looks like yours because the public literature already contained adjacent work, because a colleague pasted the same problem into a consumer app, because someone clicked feedback, or because you were never on the enterprise SKU. Friedberg’s anecdote is a reason to ask which product was used. It is not, by itself, evidence that Microsoft Copilot trained on a credit union’s Graph.

The ladder’s unresolved tension is the one a credit union can actually govern: which product did the staff member type into, not whether Zero Data Retention is a metaphysical seal.


Strategic implications

What enterprise plans actually guarantee

Four promises show up in every serious commercial pack. They are not interchangeable.

Promise What the contract is doing What it is not doing
No shared-model training (default) Prompts, completions, and connected workplace files are not used to train or fine-tune the vendor’s general models unless you opt in or instruct otherwise. The model cannot later emit a similar idea. Staff cannot paste the same work into a consumer app. A thumbs-up, a Files API upload, or a “de-identified” derived-data clause is always off.
You own inputs and outputs As between you and the vendor, you keep inputs and own outputs to the extent law allows. A copyright indemnity for whatever the model writes. Microsoft sells a separate Customer Copyright Commitment. The others are narrower.
Processor / Data Protection Addendum The vendor processes customer data on documented instructions, with subprocessors, standard contractual clauses, breach notice, and deletion on exit. Data never touches vendor GPUs, safety classifiers, support staff, or lawful process.
Retention / Zero Data Retention How long prompts sit at rest after the response, and whether abuse-monitoring logs exist. Inference-time processing, in-memory or GPU prompt cache, conversation history you turned on, or third-party tools.

Provider evidence, graded against first-party pages rather than podcasts:

Contracting route Training position (Grade A/B) Default retention Zero Data Retention or analogue Human / operational access E-23 inventory
Microsoft Copilot / Copilot Chat under a commercial tenancy Prompts, responses, and Graph data are not used to train foundation models. Same DPA as Exchange and SharePoint. (A: Microsoft Learn EDP page, updated 18 August 2026.) Conversation history follows Microsoft 365 retention and audit, not a 30-day API log. Not sold as ZDR. Web search is a separate Bing path. Microsoft as processor. Copilot inherits identity, sensitivity labels, retention, and audit. Yes. Vendor model in a staff workflow.
Azure “models sold by Azure,” including Azure OpenAI Prompts are not available to other customers or to OpenAI; not used by model providers to improve their models; not used to train foundation models without permission. Models are stateless at inference. (A: Azure data-privacy page.) Uploaded files, Assistants, Responses API, and stored completions persist in the customer tenant until deleted. Global/DataZone deployments may process in other geographies while data at rest stays in the designated geography. Modified abuse monitoring, by application, stops human review of sampled prompts. Classifiers still run. Default: automated review, with human review of sampled abuse on Secure Access Workstations unless modified monitoring is approved. Yes. Third-party model, including ones used inside a workbench.
OpenAI API, ChatGPT Business / Enterprise By default, no training on business inputs or outputs. Opt-in exists (Playground feedback). (A: enterprise-privacy page, 8 January 2026; Help Centre business section.) API: up to 30 days for service and abuse, then delete, unless law requires longer. Enterprise chat: admins set retention; deleted conversations leave systems within 30 days unless law requires longer. Sales-approved ZDR or Modified Abuse Monitoring on eligible endpoints. Forces store=false on chat/responses. Many endpoints remain ineligible. Enterprise: employees for incidents, recovery with permission, or law. Business: employees plus specialized contractors for abuse. Yes, if used for non-negligible decisions or operations.
Anthropic commercial API / Claude for Work “Anthropic may not train models on Customer Content from the Services.” Customer Content is Confidential Information. (A: Commercial Terms, 17 June 2025.) API: delete within 30 days except Files API, agreed otherwise, Usage Policy, or law. Claude for Work: chats persist for the product; deleted chats leave backend storage within 30 days. Approved API / Claude Code on Claude for Enterprise. Does not cover claude.ai chat, Cowork, Workbench, Files API, prompt caching, web search, or Covered Models. Flagged misuse: retain up to two years. Automated safety first. Human review of flagged content is a narrow, logged exception. Yes, including Claude Code if used in production workflows.
Google Workspace Gemini (qualifying edition) Training Restriction in Service Specific Terms: no training or fine-tuning without prior permission. (A: Workspace Privacy Hub, 14 August 2026.) Gemini in Workspace: 90 days to indefinite, as admins set. Gemini app: up to 36 months. History off still keeps new chats up to 72 hours to run the service and process feedback. Gemini Enterprise Agent Platform: ZDR is a configuration outcome (disable abuse-log exceptions, Search/Maps grounding, request logging, Interactions store=true). In-memory cache with 24-hour time-to-live is described as not violating ZDR. Processor under the Cloud Data Protection Addendum. Gemini sees only content the user can already access. Yes.

Two holes that legal reviews miss because the training sentence is clean.

First, connected search. Copilot web queries are generated from the prompt, stripped of user and tenant identifiers, sent to Bing, not shared with advertisers, and not used to train foundation models. They still leave the commercial Data Protection Addendum. Anthropic and Google write the same kind of exception for web search and third-party MCP servers. An MCP server is a third-party tool the model calls; that vendor’s retention policy governs what you just sent.

Second, the SKU sitting next to the SKU. ChatGPT Enterprise does not train by default. The same employee’s personal Codex or ChatGPT login does. Anthropic Zero Data Retention covers Claude Code only when the developer authenticates into the Zero Data Retention organization. A personal claude.ai login is not that organization. Google’s Gemini app with history on is not Gemini in Docs. Azure Global deployment is not Canada-at-rest processing.

For a federal credit union the practical map is simple. Copilot under the existing tenancy is the governed path. Direct lab APIs are a different contract, a different log, and a different Zero Data Retention conversation. Consumer apps are not an “AI strategy.” They are an unmanaged model.

What Zero Data Retention guarantees

Zero Data Retention means: this organization, these endpoints, these models: after inference, we will not keep your prompt and completion at rest, except law, child-sexual-abuse-material reporting, misuse flags, and the features you turned on that require storage.

It does not mean the bytes never existed in GPU memory. It does not mean a 24-hour encrypted prompt cache never sat on the machine that served the request. It does not mean a safety classifier never scored the text. It does not mean a later model cannot emit a similar method. It does not mean Files, Assistants, conversations, fine-tunes, or batch jobs were included. It does not mean Covered Models were included. It does not mean Bing, Google Search, or an MCP server was included.

OpenAI’s own endpoint table is the document to read before anyone repeats “we have ZDR.” Chat completions and responses can be eligible, with limits. Conversations, Assistants, threads, files, fine-tuning, evals, batches, vector stores, and videos are not. When Zero Data Retention is on, store is forced false even if the request sets it true. Prompt caching may still store encrypted key/value tensors in GPU-local storage for up to 24 hours.

Anthropic is equally explicit about product scope. Zero Data Retention applies to the Anthropic API and to products that use the commercial organization API key, including Claude Code. It does not cover claude.ai chat, Cowork, Workbench, Files API, prompt caching, web search, or Covered Models unless separately agreed. Flagged misuse can be retained for up to two years.

Google is the vendor that says the quiet part in documentation: you achieve zero retention by turning named features off. Interactions API store defaults to true. Search grounding cannot be made zero-retain. In-memory Gemini cache is called compatible with Zero Data Retention because it is not at rest.

Microsoft’s Copilot path does not need Zero Data Retention to be a serious enterprise control. It needs the Data Protection Addendum, tenant isolation, identity, labels, retention, and audit — and a conscious decision about Bing web search. Azure needs a second decision: standard deployment versus Global/DataZone, and whether modified abuse monitoring is worth the loss of human review accuracy.

The honest sentence for a risk committee: Zero Data Retention is a bounded API configuration, not a substitute for knowing which product staff used.

Why All-In says corporate IP leaks into models

Three events were stacked into one slogan.

Chamath’s claim is about exceptions and incentives, not about Copilot’s training clause. He is right that Zero Data Retention is qualified: eligibility, endpoint tables, Files APIs, feedback clicks, Covered Models, CSAM, “combat misuse,” and the vendor’s right to impose Eyes Off or Safety Retention. He is right that a like button on a consumer surface is an explicit training opt-in for that thread. He is right that a CIO who signs a rate-card API deal and then lets developers paste member files into personal Codex has a firing offense. He is wrong if the takeaway is that Microsoft Copilot’s “not used to train foundation models” sentence is empty. That sentence is in the same family of processor terms the institution already accepted for email.

Friedberg’s claim is an anecdote about a later model sounding like an earlier chat. Independent write-ups of the episode repeat his story. They do not audit logs. The inference-governance test is the one that belongs in a credit union: which product, which tenant, was feedback clicked, was it consumer Codex, was the “novel” method already in the public literature. Treat the story as a reason to forbid consumer SKUs for unpublished work. Do not treat it as a finding that Copilot trained on Graph.

The Navier–Stokes fight is a consumer-Codex and rumor-steering dispute, not an enterprise Zero Data Retention failure. Buckmaster and Alpöge used Codex and Claude on a rare forced-Euler attack. OpenAI launched an internal evaluation after hearing rumors, then announced a forced Navier–Stokes proof. OpenAI first could not rule out de-identified derived data; on 10 September it said those Codex prompts could not have influenced the system, including through training. Those are competing public statements, not a court finding, and not a Copilot tenancy.

The fact that travels to a credit union is narrower. If unpublished work cannot safely live inside a consumer coding agent, staff must not put unpublished work there. That is an acceptable-use problem. It is not proof that the enterprise Data Protection Addendum is a lie.

Satya Nadella has said enterprises want weights they control, visible chain of thought, and IP that does not leak. That is an architecture preference for some workloads. It is not a finding that Copilot’s training default is on.

Appropriation risk and dependency risk are different. Appropriation is the vendor using your prompts to improve a shared model. On named enterprise SKUs, public terms do not support that as the default. Dependency is the institution creating evaluations, traces, memory, and workflows it cannot export. Zero Data Retention does not fix dependency. It can make dependency worse, because the features that store reusable state are the ones ZDR turns off.

Implications for a federal credit union

Risk. The material leak is not Microsoft training on Copilot prompts. The material leak is a lender pasting a credit file into personal ChatGPT, a developer authenticating Claude Code with a personal account, a Copilot web-search toggle that sends derived queries to Bing, or an Azure Global deployment that processes prompts outside the geography the board thinks it bought. Member-trust damage from the first of those is immediate. E-23 and B-10 damage from an uninventoried vendor model is slower and more certain.

Opportunity. First West Credit Union has already put Microsoft 365 Copilot in every team member’s hands, on a closed system, and has said some data will not touch agents until content is clean, owned, and governed. That is the peer move: use the processor path you already pay for, do not confuse it with a lab API, and do not let shadow consumer use sit beside it.

Competitive position. A credit union that panics from All-In into “bare metal or nothing” will stall the coworkbench work that actually reduces cycle time in lending intake. A credit union that treats Copilot as magically private will miss Bing, personal logins, and agent plugins that carry their own terms. The middle is boring and correct: Copilot for M365 work, Azure or a lab API only with a named endpoint list and a tagged test, consumer apps blocked for corporate data.

Regulatory trajectory. E-23 is principles-based and operationally prescriptive. It wants a comprehensive model inventory, an inherent-risk rating, and assurance that scales with that rating. Vendor and third-party models are in. Generative and agentic systems are in. SR 26-2’s United States carve-out is not the Canadian file. B-13 still covers technology and cyber risk. B-10 still covers the third party. PIPEDA and, for Quebec members, Law 25 still care whether inference left Canada even when data at rest did not.

Member impact. Members do not distinguish Copilot from ChatGPT. They distinguish “the credit union lost my file to a chatbot” from “the credit union used the same cloud that already holds my email.” The second sentence is defensible when the first product is actually the one in use.


Quick-start actions

These are the next 90 days. They are not a four-year horizon.

  1. Model-risk and the CIO should put every AI surface on the E-23 inventory this quarter, including Microsoft Copilot, Copilot Chat web search, Copilot Studio agents, Azure Foundry deployments, any OpenAI or Anthropic API, Claude Code, consumer ChatGPT/Codex, and vendor tools that embed a model. A low-risk spelling assistant and a lending-memo draft are not the same rating. Both are models if inherent risk is non-negligible.

  2. The CISO should treat personal ChatGPT, personal Codex, and personal claude.ai as unmanaged models, not as “the same AI we already approved.” Block them for corporate identities and for devices that can reach member files. The Navier–Stokes dispute is the cautionary tale for this control, not for Copilot.

  3. Enterprise architecture should write a one-page data-flow for Copilot that names three pipes: Graph-grounded prompts under the Data Protection Addendum; optional Bing web queries under the Microsoft Services Agreement; third-party agents under their own terms. Turn web search off for roles that handle member, HR, or privileged files until that page is signed.

  4. Do not buy Zero Data Retention as a Copilot substitute. If a lab API is required, legal and security should confirm the named organization, project, endpoint, and model against the vendor’s eligibility table, capture the enabled setting in the account, and run a tagged non-production payload through the institution’s own gateway and SIEM. Sales email is not the control.

  5. Keep reusable work in systems the credit union owns. Prompts, retrieval corpora, evaluation sets, and traces belong in the tenancy or in a file-backed workbench. Zero Data Retention that deletes the only copy of an evaluation is not privacy. It is amnesia.


Watch list

If Covered Models or Private Safety Processing become the only way to use the models staff actually want, this primer should be rebuilt as a full strategic brief. Until then, the decision is SKU control, not a new cloud.


References

← EssayResearch appendix →