Why Enterprise Trust Is India’s Next AI Growth Frontier

Why Enterprise Trust Is India’s Next AI Growth Frontier
Enterprise AI's binding constraint is shifting from what the models can do to what happens to the customer's data.

Zero data retention is today a promise, not an architecture. As enterprise knowledge flows into the models, a new trust layer of harnesses, on-premise AI, and AI-native security is opening up for builders, and India’s AI startups are positioning to operate it.

The Gap Between AI’s Promises And Its Plumbing Is Now Measurable

Enterprise AI’s binding constraint is shifting from what the models can do to what happens to the customer’s data. For the first time, that gap can be measured at the wire. 

On 12 July, a security researcher publishing as cereblab routed xAI’s Grok Build coding tool through an interception proxy and documented exactly what it transmits. The results were arresting. On a 12 GB repository of files the model never read, the coding task itself required about 192 KB of traffic.

A separate storage channel moved 5.1 GB, a roughly 27,800x gap between what the model needed and what left the machine. The upload carried the entire Git repository, including files not accessed and the full commit history. A planted credential appeared verbatim and unredacted in the captured traffic.

A second researcher, Hari Krishnan, reversed the binary itself and confirmed a background collector operating outside the tool’s permission system.

The instructive detail is not the upload. It is that the controls pointed the wrong way. Disabling the “Improve the model” toggle did nothing to stop the transmission, because that setting governs training consent, not whether code leaves the machine. xAI switched the behaviour off within a day through a server-side flag, while the upload code remains in the shipped binary.

The remediation was fast, and the company says zero data retention customers were never affected. Both points deserve to be stated fairly. Yet, the episode confirmed what enterprise buyers have long suspected: zero data retention is today a promise, not an architecture. Closing the distance between the two is an engineering problem, and engineering problems can create market openings.

This is the third piece in a series for Inc42. The first argued that AI will be paid for outcomes rather than tokens. The second argued that control, not capability, will decide enterprise AI. This one is about the core of the applied AI thesis at work: the data it ingests.

Intelligence Exhaust Is the Next Most Valuable Data

Satya Nadella calls it intelligence exhaust. In an essay published on 12 July, the Microsoft CEO argued that AI has inverted the economics of information. Enterprises now pay for intelligence twice, once in money and once in “the proprietary knowledge you must reveal to make that intelligence useful.” 

Every engagement generates exhaust that gradually captures how an organisation operates, and every correction is distilled into institutional know-how.

Eleven days earlier, Palantir CEO Alex Karp told CNBC that his enterprise customers are livid because, in their view, the labs are “stealing the weights and alpha” of their businesses.

Both men have commercial positions in this fight, Karp selling the control layer and Nadella selling the cloud beneath the model, and their warnings should be read with that in mind. The signal is that a partner and a competitor of the frontier labs converged on the same alarm within a fortnight.

The mechanism under contention deserves precision. In the SaaS era, customer data sat inert in a vendor’s database, fenced by contract and accessible only to the customer. AI interactions are different. Prompts, workflows, corrections, and approvals form trajectories that can improve a model, which means customer knowledge can, in principle, become vendor intellectual property.

Industry observers have noted that current zero data retention practice is a superficial form of privacy: even where the prompt itself is deleted, there is no strong technical guarantee that the surrounding interaction signals a user generates are not retained in some form, because the industry has not yet built the machinery to make that guarantee. They also note that when a specific technical accusation circulates, the absence of a specific technical rebuttal from the labs is itself information the market prices.

The Enterprise Perimeter Is Being Redrawn Around AI

Enterprises will respond the way they always have, by rebuilding the perimeter, and this time it will be rebuilt in five layers.

  • The first is the model layer. Ownership or control of the model itself, through on-premise, private-cloud, and air-gapped deployment of open-weight models, is moving from a regulated-industry exception to a procurement default for sensitive workloads. Nadella’s own prescription points here: retain ownership of the data, build private learning environments, and add orchestration layers that can switch between models.
  • The second is the learning layer. Whatever a model learns inside the enterprise must belong to the enterprise. Fine-tuned weights, evaluations, and workflow adaptations are the customer’s compounding asset, and contracts must say so explicitly. This is the direct answer to the alpha leakage charge.
  • The third is the gateway layer, a control point between every application and every model that enforces policy before execution rather than auditing after it: per-user identity, scoped model access, spend limits, model selection and routing. The vacuum here is measurable. In Deloitte’s State of AI in the Enterprise 2026 survey, data privacy and security tops the list of AI risks at 73%, yet only 21% of companies planning agentic deployments report a mature governance model for their AI agents.
  • The fourth is the perimeter layer: scope of use, context limitations, access controls to third party dependencies, and coverage of the AI tools employees run on their own devices. The Grok episode proved that the threat model now includes the official binary itself, not merely unsanctioned tools.
  • The fifth is the verification layer. Trust must be checkable per transaction, through immutable logs, independent audits, and the technical ability to confirm that deletion means deleted. Anonymisation cannot yet substitute for deletion, so verified deletion becomes a standard.

The Trust Layers Are The Emerging Insertion Points In The AI Supply Chain

Each of these layers is an opening for new companies, because the frontier labs are conflicted owners of every one of them. Three opportunities stand out.

Harnesses will be the first. The harness is the software through which people work with AI, and it is becoming the layer that encapsulates trust inside the enterprise. Whoever controls the harness controls what leaves the perimeter, what context the model sees, and what evidence exists afterwards. A lab that sells intelligence by the token cannot credibly referee its own data intake, which makes the harness a large, contestable category for independents.

Vertical AI deployed inside the customer’s perimeter is the second. Enterprises will pay a premium for models trained and operated on-premise against their most sensitive assets: schematics, design documents, source code, and proprietary research. The economics of open-weight models now make this viable at a fraction of frontier API costs.

AI-native security is the third, and the least built. Detecting and preventing model-bound exfiltration is a new discipline, not an extension of data loss prevention. Confidential meeting notes, internal documents, and support tickets are all potential training inputs, and the tooling to police that flow barely exists.

The wire-level canary methodology that exposed Grok Build is a preview of an AI auditing industry that does not yet operate at scale. India’s GCCs and IT services firms are natural builders and operators of this trust layer for global enterprises. The institutions that ran the world’s ERP systems, cloud migrations, and security operations centres are positioned to run its AI perimeter, and this is implementation revenue with a sovereignty premium attached.

The SaaS Accord Must Be Renewed For The AI Era

The SaaS era rested on an accord that took two decades to establish: enterprises would place their data on vendor infrastructure, and vendors would guarantee they had no access to it and no use for it. That bargain underwrites trillions of dollars of market value today.

AI inherited this trust by default and is currently drawing the account down. The vendors and builders who restore it, with guarantees that are architectural rather than contractual, will win the enterprise phase of AI. Capability sets the floor of this market. Trust will set its ceiling.

The post Why Enterprise Trust Is India’s Next AI Growth Frontier appeared first on Inc42 Media.