Enterprise AI has a trust crisis. Back in July, Palantir CEO Alex Karp made headlines in an interview with CNBC’s “Squawk Box”, criticizing an AI usage model where organizations “chillax” with tokens and hand over their IP.

That same month, Microsoft CEO Satya Nadella released a blog post warning enterprises about the dangers of giving away too much information to AI labs, warning that they could be paying twice, in the form of token costs and handing over proprietary knowledge.

Agentic AI platform Writer is aiming to address these concerns head on, today launching Enterprise Brain, a governed universal context layer designed to capture everything a company knows about its brand, including brand systems, messaging, customer history, compliance logic, decisions and reasoning, to make that knowledge accessible to AI agents while limiting IP exposure.

Enterprises are facing a challenging landscape where agents need context to perform a given task effectively, but providing too much context can expose IP to unauthorized third parties. Writer’s approach captures context for agents to use, but keeps it separate from the model layer, enabling the agent to replicate brand messaging while limiting the exposure of IP. The context layer is fully owned and controlled by each organization and portable across systems.

Handing IP Over To Silicon Valley

While frontier AI tools like Claude and ChatGPT have seen widespread adoption in the enterprise, there are growing concerns over whether using these tools raises the risk of IP being reverse engineered to create competing products.

Back in April, Figma CEO Dylan Field called out Anthropic for being “not consistently candid in their communications,” after the company launched Claude Canvas, an adjacent solution, just three days after Anthropic CPO Mike Krieger left Figma’s board.

This incident, and others like it, have been criticized by a number of commentators. For instance, Ole Lehmann, founder of the AI Solopreneur newsletter, posted on X that “OpenAI and Anthropic are just gonna keep cannibalizing all their biggest customers."

Likewise, when OpenAI CEO Sam Altman offered free tokens to Y Combinator startups in May, VC investor Jason Calacanis released a post arguing that “if you take these tokens, there’s a non-zero chance that OpenAI will study exactly what your startup is doing, copy your idea and put your app into their free offering.”

For May Habib, cofounder and CEO of Writer, there is a significant lack of trust among enterprise leaders and frontier AI vendors. “There isn’t a single C-level conversation that I have where folks aren’t proactively bringing up some lapse of trust, right, that they’ve experienced with the labs,” Habib told me in a video interview.

“I’ve had multiple CIOs tell me that there is nothing stopping the labs from taking their data and reverse engineering a bank,” Habib said. “This is absolutely top of mind for CxOs as they interact, and it’s what’s driving so much of the desire to build context, memory and sovereign AI in-house.”

Habib says that Enterprise Brain is Writer’s way of helping capture “enterprise know-how” across verticals like product marketing, sales enablement and brand architecture, and turn context that into an IP moat that is kept separate from the model layer, so it doesn’t end up in the training data of the model.

It’s worth noting that the release comes just a month after the launch of Writer’s Palmyra X6 model, built with GLM 5.2.

Concerns of Reverse Engineering

When considering IP protection, it’s worth noting that OpenAI claims ChatGPT Enterprise doesn’t train on conversations, files or outputs by default, and Anthropic says it doesn’t use inputs or outputs to train its commercial models by default. On paper, organizations have some protections against having their IP exposed, but there are other concerns around leakage.

Roger Beharry Lall, an IDC research director, told me in a video call that if organizations are contracting properly and setting the right guardrails, there are some protections in place, but there remain risks. For instance, even with controls in place, employees may leak intellectual property to unwanted third parties by using consumer-grade versions of ChatGPT and other tools as part of their workflows.

“For a lot of smaller businesses that maybe use cheaper versions or lesser platforms or freemiums etc., there is some risk that you may well be, you know, sharing your customer success, your secret sauce, your go-to-market strategies, etc. with an intermediary that is then learning from that to apply it to others," Lall said.

Paddy Lambros, founder and CEO of AI recruiting platform Dex, noted via email that “many companies are increasingly seeing the frontier labs emerge as challengers within their core markets.”

He also shared reservations over frontier AI’s IP protections.“It is often unclear what data the labs are and aren’t training on, and whilst most enterprise agreements come with commitments that models are not trained on client data, these companies have grown so fast, competition for proprietary data is so fierce, and most models are a bit of a black box, who would really know," Lambros said.

Protecting IP From Exposure

It is these types of concerns that Writer will need to address to attract companies away from the frontier AI labs. So far, its approach to building an agentic platform that can plan and execute work across multiple tools has attracted a range of Global 2000 customer organizations, including Mars, Clorox, H&R Block, Vanguard, Marriott, Salesforce and Accenture.

When asked about Enterprise Brain, Lall said he thinks Writer is seeing an opportunity to add a harness that is marketing-specific, that understands the logic of workflows, that “simply isn’t there at the foundational model level.” More broadly, Writer’s approach provides an example for how to grant agents access to shared context to automate marketing workflows.

Many organizations attempt to withhold context from agents to prevent exposure of intellectual property, but this practice also limits the capabilities of agents in the process. Finding ways to increase agent’s access to context, while limiting the exposure of IP can help to increase the value of agentic adoption long term.