What are you learning from your company’s prompts?

Everyone's arguing about who owns AI "exhaust." The more useful question is whether anyone has actually looked at what's in it.

What are you learning from your company’s prompts?

Satya Nadella dropped a blog post last week that TechCrunch framed as a "shocking warning" to enterprises using AI. I want to cool that down for a second, because underneath the headline, there's a genuinely useful idea buried in there, and it has almost nothing to do with the drama around open versus closed models.

Nadella's core argument: enterprises are paying for AI twice. Once with money, via token usage. And a second time with something far more valuable, the proprietary knowledge you have to feed the model to make it useful. Every prompt, every correction, every "no, not like that, like this" is a signal. Nadella calls this byproduct "exhaust." I don't love the name, but I understand exactly what he's pointing at.

It's Not a Distillation Debate. It's a Data Ownership Problem

Most of the commentary on Nadella's post has gone straight to the fight everyone wants to have: should enterprises be allowed to distill proprietary models the same way those models were trained on public web data? That's a real debate, and a fair one. Model makers scrape the open internet freely, then write terms of service that restrict customers from doing anything similar with the outputs they're paying for. Nadella isn't wrong to call that a little hypocritical.

But I think that fight is a distraction from the more immediately useful question sitting right next to it: what is actually in that prompt history, and who's looking at it?

Not every enterprise using AI at scale now has a running record of exactly how its employees are using it. But if you do, it's a source of great insight. Not hypothetically, literally. Every prompt, every tool call, every correction is sitting in a log somewhere, and most companies aren't looking at it as anything other than a bill from their model provider, or policy-driven alerts around what type of AI usage is or is not allowed in their organization.

Three Fundamental Issues Hiding in Plain Sight

  1. Prompt history is an amazing telemetry source, and almost nobody treats it that way. If an employee is pasting a customer contract into a chatbot to "summarize the risky clauses," that's a data exposure event, and it happened in a place most security teams have zero visibility into.
  2. The correction pattern is the tell. Nadella is right that corrections are where the real institutional knowledge leaks out. But flip that around: corrections are also where the real risk signal shows up. A user repeatedly re-prompting to get around a refusal, or iterating toward a jailbreak, leaves a trail. That trail is detectable, if anyone's actually looking at the aggregate.
  3. Topic and intent, not just content, is the missing layer. Most organizations can't tell you who used what AI services last month, much less how many tokens were used last month. Even fewer can tell you, topically and semantically, what their finance team is actually asking AI to do versus what their engineering team is asking, or where those two populations start overlapping in ways that might give interesting insights to the company.

Why This Matters More Than the Open-Source Fight

Here's the thing Nadella's post gets right even if the headline oversells it: this data is valuable, and right now, most enterprises are giving it away for free without even auditing what's in it first, or even thinking about how they can use it themselves. Before you build a "proprietary learning environment" or stand up your own orchestration layer to shop between model providers, you should probably know what your employees have already been telling these models for the last twelve months.

That's a security, operational and efficiency question before it's an ownership question. You can't protect, govern, or even meaningfully negotiate over data you haven't observed.

The Real Takeaways

  • Nadella's "exhaust" is really two things bundled together: a legitimate IP and competitive-advantage argument, and a much more urgent security, visibility and observability gap. Don't let the first distract you from the second.
  • Your prompt logs are an underused security dataset. Treat them the way you'd treat any other log source: aggregate, analyze, and alert.
  • Semantic and topical analysis matters more than raw volume. Knowing what your organization is asking AI to do is more actionable than knowing how much they're asking.
  • Get ahead of the ownership debate by getting ahead of the visibility problem. Whatever you decide about distillation rights or model portability, you'll make a better decision with a clear picture of what's actually flowing through your prompts today.

This is exactly the gap we built FireTail's Prompt Intelligence feature to close: taking the full prompt history across your organization and distilling it down into something a security or governance team can actually act on, topically, semantically, and by risk. Nadella wants enterprises to own their exhaust. Fair enough. But you can't own, govern, or extract value from a dataset you've never actually looked at.

Looking for a way to see what your teams are really doing with AI? FireTail can help. Schedule a demo and get a complete inventory of AI usage across your organization in 15 minutes.

Discover your AI exposure now

See how FireTail provides a single platfrom to discover, assess, and protect all AI usage across your organization.