AI privacy is fragile and brittle, with non-obvious data-leak vectors lurking even in well-intentioned products, so a 'zero data retention' promise from a model company cannot actually guarantee data won't leak — as shown by Grok Build silently uploading full codebases despite a privacy setting meant to stop it.
Following xAI's Grok Build data leak, Chamath argues that even well-run AI companies have unknown 'trap doors,' so ZDR promises can't be trusted and enterprises need an independent third-party layer between themselves and model providers. ✦ AI generated
Chamath Palihapitiya · All-In Podcast · 2026-07-18 · original ↗
starts at this moment · 44:18
“You got any kind of thoughts on this? Obviously, this was not intentional, but trust is important uh with these models as we've been talking about for the last couple of months here on the All-In podcast.”
Privacy in AI is very fragile and it's very brittle. And this is despite the best efforts of great businesses. Like, you know, you may not like Elon for personality quirks, but he is incredibly trustworthy. He's overly transparent. And so, to their credit, they shut it off immediately. But my takeaway is that there are all kinds of non-obvious data leak vectors lurking in AI.
verbatim transcript · starts at 44:18
44:18comments the week before. Privacy in AI is very fragile and it's very brittle. And this is despite the best efforts of great businesses. Like, you know, you may not like Elon for personality quirks, but he is incredibly trustworthy. He's overly transparent. And so, to their credit, they shut it off immediately. But my takeaway is that there are all kinds of non-obvious data leak vectors lurking in AI. And so if you think that you're
44:55going to flip a ZDR switch, zero data retention, which is the magic term that the industry uses to tell you that everything's going to be okay. I think the answer and the message should be it's not going to be okay because you can't guarantee any of it. So the model companies when they give you these zero data retention policies are probably trying their best. But I think the reality is you are leaking
45:19information where you don't know it. and they despite their best efforts may still have trap doors that they don't even know about until it's figured out by somebody else like in this example. So all of this speaks to you have to have a stratified ecosystem. You have to have third parties. Now look that's very biased for me because it's in part what we do for large enterprises at 8090 when
45:39we implement our software factory. But the reason why it's working so well is this exact reason. You need an independent third party layer to interface to these models to manage this exposure because there are trap doors everywhere. >> And that's what Sachi just said in a really interesting blog post. Did you guys see that? >> Yeah, >> I thought that was excellent. >> The reverse information paradox.
46:00>> Yeah, >> that's exactly the the takeaway that he left with. He was building on Alex Karp's supposed crash out. You know the point that Kart made about how enterprises who have technical ability want control over their compute models, weights, data and alpha. But he he went further with that idea. I mean he started with Karp's idea but then he kind of provided a recipe a road map for