Industry Analysis

Alex Karp Says Frontier AI Labs Are Putting Client Data at Risk

The Palantir CEO calls token-based AI pricing a "wealth tax" and warns that closed models are absorbing enterprise IP. Whatever you make of the argument, the exposure he describes is real, and it is not solved at the contract layer.

July 30, 2026 8 min read DataFence Security Team
Back to Blog
Palantir CEO Alex Karp speaking with both hands raised on stage at the World Economic Forum Annual Meeting in Davos, with the event backdrop behind him.
Palantir CEO Alex Karp at the World Economic Forum Annual Meeting in Davos.

What Karp actually said

Speaking on CNBC, Palantir CEO Alex Karp took aim at the API-driven, token-based business models of the frontier AI labs, naming OpenAI and Anthropic. His argument had three parts, and they are worth separating because they are not equally strong.

The core charge

Karp described frontier lab pricing as a "wealth tax" on enterprises, said customers are "livid" about the cost of token consumption relative to what they get back, and warned that companies routing their data through closed models are handing over the thing that makes them competitive.

1. The economics are broken

Karp's first claim is commercial. Enterprises are spending heavily on what he called "tokenmaxxing," consuming ever more inference for returns that are difficult to see on a balance sheet. He argued that customers are increasingly frustrated at paying a metered bill that scales with usage while the business case stays hypothetical.

This part is an argument about value, and reasonable people disagree. Plenty of organizations are getting real leverage out of these models. But the underlying observation is hard to dismiss: most enterprises still cannot say what their AI spend bought them, and a cost that scales with consumption is uncomfortable when the benefit does not scale with it in any measurable way.

2. The IP risk is structural

His second claim is the one security teams should sit with. Karp asserted that sending corporate data into closed, black-box models lets the labs capture a company's core competitive advantage, and framed the resulting model weights as something the customer contributed to and does not own.

It is worth being precise here, because the strong version of this claim is contestable. The major labs offer enterprise agreements that generally exclude customer data from training, and many organizations use them under exactly those terms. If your company has a negotiated enterprise contract and your people use it, the training-data concern is largely a contractual matter with a contractual answer.

The part that survives the pushback

The exposure is not mostly happening inside your enterprise agreement. It is happening beside it, in personal accounts, free tiers, and tools nobody has approved, where no contract applies, no logging exists, and no one can tell you afterwards what left.

That is the version of Karp's warning that holds regardless of what you think of his framing. An engineer pasting a proprietary algorithm into a consumer chatbot to debug it is not covered by your enterprise terms. A finance analyst uploading the model that prices your product is not covered either. The governing document in that moment is the consumer terms of service that person clicked through, and the company is not a party to it.

3. The national security framing

Karp's third claim widens the lens: that outsourcing critical enterprise and defense infrastructure to a handful of commercial Silicon Valley labs creates systemic vulnerability at a national level. This is the most contested of the three, and it is also the one furthest from what a security team can act on this quarter. It is a policy argument, and Palantir has an obvious commercial interest in how it lands.

We would note the interest without dismissing the point. Concentration risk is a legitimate category, and it is fair to ask what happens when a small number of providers become load-bearing for a large share of the economy. But a CISO cannot re-architect the national AI supply chain. They can decide what leaves their own organization.

The question Karp's critique leaves on your desk

Strip away the framing and a practical question remains: do you know what proprietary material your people are sending to AI services right now, and could you stop the part that matters?

For most organizations the honest answer to the first half is no, and the answer to the second half is "we blocked some domains." Neither is a control. Blocking domains moves people to alternatives, and there is always another alternative. Meanwhile the actual event, a person moving sensitive material out of the company, goes unrecorded.

How DataFence protects your IP across every site your people use

DataFence takes a different position than either "trust the vendor contract" or "block the vendor." It enforces on content, at the browser, before anything is transmitted. The browser is the last point at which data is still inside your organization and a mistake is still preventable, and it is the one place every web destination has in common, sanctioned or not.

That matters for exactly the gap Karp is pointing at. A control that depends on knowing which AI vendor to worry about is obsolete the week a new one launches. A control that inspects what is leaving does not care which logo is on the page.

Inspect the content, not just the destination

  • File uploads are intercepted before they are sent, across drag and drop, the file picker, and programmatic uploads. The file is classified, and policy decides whether it goes.
  • Typed and pasted text is inspected too, on Enterprise and Onyx plans, which is the path that matters most for AI. Nobody uploads their pricing model to a chatbot. They paste it into the prompt.
  • Classification does the deciding. The engine identifies PII, financial data, credentials and secrets, and confidential business material such as legal, financial, and strategic documents, rather than pattern matching on a keyword list.
  • Verdicts are allow, warn, or block, set per data category, so routine work moves freely while the material that would actually hurt you is stopped.
A DataFence block modal on ChatGPT reading Upload Blocked by DataFence, Detected pii classified as restricted, listing the detected entity types ANOMALOUS_ID, DATE, IP_ADDRESS, PERSON, CREDIT_CARD, ALPHANUMERIC_ID, ACCOUNT_NUMBER and PHONE.
The verdict is about the content, not the domain. ChatGPT was not blocked. This particular upload was, and the notice says exactly what was found in it.

That distinction is the whole argument. A domain block would have stopped every ChatGPT session, useful and harmful alike, and pushed the determined user to a different tool by lunchtime. What happened instead is narrower and more durable: the site stayed available, the specific payload carrying credit card numbers, account numbers, and personal identifiers did not leave, and the user was told why in terms they can act on.

See the AI usage you did not sanction

You cannot govern what you cannot see, and the AI tools creating your exposure are rarely the ones on your approved list. DataFence identifies AI destinations from enforcement data it already collects, and reports usage by service, by person, and by the type of sensitive data involved.

The DataFence AI Activity Reporting dashboard showing 602 AI events out of 3,459 total enforcement events, 178 blocked before leaving the browser, 23 warned, and 3 people across 7 AI services, with a verdict trend chart, a category breakdown of chat assistant and AI search usage, a table of AI services in use, and the sensitive entity types detected in AI-bound content.
One month of AI activity for a single office. 602 of 3,459 enforcement events were headed for an AI service, 178 were stopped before leaving the browser, and it took three people across seven services to generate that.

Two things in that view tend to surprise people. The first is the ratio: AI destinations are shown against total egress, so the report is honest about how much of the picture it is describing rather than presenting a number with no denominator. The second is how few people it takes. Three staff and seven services is not a rogue department. It is a normal week, and it is exactly the traffic that sits outside whatever enterprise agreement your procurement team negotiated.

  • AI activity reporting shows what went where: which assistants, coding tools, translators, and meeting notetakers your people are actually using, and what was in the traffic.
  • Unrecognized destinations are surfaced, not silently ignored. Anything the catalog does not know appears for review, and an administrator can promote it in one click, including an internal AI gateway or a vendor that launched last month.
  • Gap reporting identifies unprotected destinations across your organization, so shadow IT shows up as a list to act on rather than a surprise in an incident review.
  • Insider risk scoring ranks people against their own prior behavior rather than raw volume, so the signal is genuine change rather than whoever happens to handle the most data.

Let the work continue: exemption requests

A control people cannot live with gets bypassed, which is worse than no control at all because it also produces false confidence. This is the failure mode that quietly defeats most AI policies. The block is correct, the business need is also real, and the person with a deadline finds another route: a personal device, a home email address, a colleague with looser access. The policy stays on the intranet, and the data leaves anyway.

DataFence version 1.2.2 closes that gap. When an upload is blocked, the user is not dead-ended. They request a one-off exemption from the block notice itself, with a business justification, and get a tracking reference immediately.

A DataFence block notice on chatgpt.com reading Upload Blocked by DataFence, asking the user to request permission to upload a W-2 PDF, with a business justification field and a Submit Request button.
A tax document stopped on its way to a frontier model. The notice names the exact file and destination, and offers the one action that is actually useful.

The request goes to an administrator, who reviews it with the detection evidence attached. Not just the requester's description of the file, but what DataFence actually found inside it: the classification level and the specific sensitive entities detected. A reviewer can see at a glance that this really is a tax document heading to a public AI service, and decide on that basis rather than on a one-line justification.

Four properties make this an accountable exception rather than a hole in the control:

  • Immediate on approval. The user retries the upload and it works. No waiting period, no browser restart, no ticket queue. That speed is what stops people looking for a workaround in the first place.
  • Narrow by construction. An approval covers that exact file going to that exact destination. It does not open the site generally, and it does not apply to the next upload.
  • Revocable at any time, so an exception granted in a busy week is not a permanent one.
  • Recorded for audit. Approving and denying both require a written reason, so granting an exception is exactly as accountable as refusing one.

Enforcement stays server-side throughout. The extension never approves an upload on its own, so an exemption cannot be forged, replayed, or forced from the browser. It submits the request and honors a decision made elsewhere. We wrote up the full workflow in the v1.2.2 release notes.

Prove it afterwards

Karp's argument is ultimately about not being able to account for where your value went. Accounting is the answer. Every enforcement decision is logged with the user, the destination, the classification, and the entities detected. Compliance reporting maps that record to SOC 2, ISO 27001, HIPAA, and GDPR, and the administrative audit trail covers who changed which policy and when.

Where the boundary is, stated plainly

DataFence enforces in the browser. That covers the overwhelming majority of how employees reach AI services, cloud apps, and webmail, and it covers every website rather than a list of approved ones. It is not an operating-system agent and does not inspect native desktop applications or command-line traffic. We would rather tell you the edge of the control than let you discover it.

The practical takeaway

You do not have to accept Karp's economics, his characterization of the labs, or his national security framing to act on the underlying exposure. The useful reduction is simple. Enterprise AI contracts govern the traffic that goes through them. Most of your risk is in the traffic that does not.

The organizations handling this well are not the ones that banned AI, and they are not the ones that trusted a contract and moved on. They are the ones that can answer three questions: what sensitive material is leaving, where is it going, and what happened when we said no. Those are answerable today, without waiting for the industry to restructure itself.

Frequently Asked Questions

What did Alex Karp say about frontier AI labs?

Speaking on CNBC, the Palantir CEO criticized the API-driven, token-based business models of frontier AI labs such as OpenAI and Anthropic. He characterized the pricing as a "wealth tax" on enterprises, said companies are "livid" about paying for heavy token consumption that returns little financial value, and warned that sending corporate data to closed models puts a company's proprietary intellectual property at risk.

Does using a commercial AI model mean losing your intellectual property?

Not automatically. Major labs offer enterprise terms that generally exclude customer data from model training, and many organizations use them safely under contract. The risk Karp describes is less about the contract than about what happens outside it: employees pasting proprietary material into consumer accounts and unsanctioned tools, where no enterprise agreement applies and no record exists.

How can a company keep using AI without exposing its IP?

By controlling what leaves rather than which vendor is used. Enforcement at the browser inspects files and text before they are transmitted, so sensitive material can be blocked or warned on regardless of whether the destination is a sanctioned enterprise tenant, a personal account, or a tool nobody has approved yet.

Why does browser-level enforcement matter for AI data leakage?

The browser is the last point at which data is still inside the organization and a mistake is still preventable. Network filtering cannot read inside an encrypted session, and blocking domains only pushes people to alternatives. Inspecting content in the browser catches the sensitive upload or paste itself, whatever site it is headed for.

Can you see which AI services employees are actually using?

Yes. DataFence identifies AI destinations from enforcement data already collected, reporting usage by service, by person, and by the type of sensitive data involved. Destinations that are not recognized are surfaced so an administrator can add them, including internal AI gateways and vendors too new to appear in any vendor list.

Find out what is already leaving.

Schedule a demo and see the AI destinations your people are using today, what sensitive data is heading to them, and what it looks like when the answer is no.

About DataFence: DataFence is the leading data loss prevention solution and a real-time analytics platform built for data security. Our platform delivers real-time visibility and enforcement at the browser, the point where employees access AI tools, cloud apps, and sensitive data, stopping data exfiltration, surfacing shadow IT, and proving compliance before a breach happens.