
Palantir, Nvidia and Booz Allen Hamilton are placing tighter limits on how employees use some advanced AI models for sensitive work, showing that the enterprise AI race is increasingly about data contracts as much as model quality.
Reuters reported that the companies' concerns include whether prompts or outputs may be retained and whether proprietary information could be exposed. Palantir is seeking strong, irrevocable zero-data-retention commitments, while Nvidia limits certain sensitive uses and Booz Allen restricts proprietary cybersecurity work.
What the companies are worried about
| Risk | Why it matters |
|---|---|
| Prompt retention | Sensitive text may remain with a provider |
| Model training | Customer data could influence future systems |
| IP exposure | Code, designs or methods may leave company control |
| Contract changes | Today's privacy promise may not remain permanent |
These restrictions do not mean the companies are rejecting AI. Nvidia builds the chips that power much of the industry, while Palantir sells AI-enabled data platforms. The issue is whether external models meet the security conditions required for classified, regulated or commercially sensitive information.
What zero data retention means
Zero data retention generally means a provider does not keep customer prompts and outputs after processing, except where narrowly required for service operation or law. The exact meaning depends on the contract, architecture and logging system.
An “irrevocable” commitment is important because enterprise buyers do not want a provider to change the terms after a workflow becomes deeply integrated. A security promise in marketing material is weaker than a binding contract supported by technical controls and audit rights.
Companies also need to examine metadata. Even if prompt text is deleted, logs may contain user identifiers, timestamps, model selections or error details. For highly sensitive deployments, those records can matter.
Why this could reshape enterprise AI
The most capable model will not automatically win every corporate contract. Banks, defence suppliers, healthcare groups and infrastructure operators may choose a model with clearer isolation, regional hosting and auditability over one that scores slightly higher on public benchmarks.
This creates an opening for private deployments, on-premises models and multi-model systems. A company might use a frontier cloud model for public research, an internally hosted model for confidential documents and a tightly controlled tool for code.
It also increases pressure on model providers to publish precise retention terms and make enterprise controls easy to verify. Vague assurances become harder to defend when customers are handling government or trade-secret information.
What businesses should do now
Organisations should classify information before connecting it to an AI tool. Public, internal, confidential and regulated data may require different models and permissions. Employees need a clear approved-tools list, not only a general warning to “be careful.”
Security teams should review retention, training use, subprocessors, data location, deletion, incident reporting and audit rights. They should also test whether users can paste sensitive data into consumer accounts that bypass corporate controls.
Sources: Reuters and NIST AI Risk Management Framework.
Frequently asked questions
Are Palantir and Nvidia banning AI?
No. They are reportedly restricting certain models or sensitive uses because of data-security concerns.
What is zero data retention?
It is a commitment not to store customer prompts and outputs beyond the processing required to provide the service, subject to exact contractual terms.
Can businesses safely use public AI tools?
They can be useful for non-sensitive work, but confidential or regulated data requires approved tools and reviewed contracts.