What Happens After You Press Enter

Two things leave a spinout when a founder pastes an invention into a chat window, and only one of them is the thing everybody worries about.

Faraz Rizvi × Foundry · 28 July 2026 · 18 min read · Markdown

Faraz Rizvi is a UK operator-practitioner writing about the work between a research breakthrough and a fundable company. He runs SpinUp Forge, which provides fractional hands-on operator resource and expertise to build the company around the science. Foundry is SpinUp Forge’s custom agentic harness.

An isometric night scene on a deep ink-blue field. At lower left, a small pale blue-grey floating island carries a dark workbench, a figure in a bone beanie and ember dress, and an ember-topped ledger, with a two-block stack of retained data resting on the deck beside it. Two lanes of small identical pale parcels leave that deck and climb a single inclined plane towards the upper right, stopping short of a much larger floating island crowned by a three-tier tower and a glowing violet gem. Three further trails of the same parcels run in towards that tower island from beyond the edges of the frame — from the upper left, the upper right and the lower right — each thinning out as it recedes.

A chat window is a text box with a button under it. You put words in the box, you press the key, and the words go somewhere: onto a computer in a building you have never visited, owned by a company you have no contract with. That last part is the whole of the matter, and it is the easiest part to lose sight of, because the box sits on your screen and behaves as though it belongs to you. In the spring of 2023 Samsung told its staff to stop using ChatGPT after an engineer put confidential internal source code into one of these boxes (Forbes, 2 May 2023). A founder six months out of a licence agreement, working on an invention with no patent granted yet, doing the same thing this week on a free account, is making a larger bet than that engineer was. A global manufacturer has a legal department to absorb what follows. A spinout has nothing of the kind.

The instinct to use the tool is sound, and I have no argument with it. This series has already made the case that for a small founding team in 2026 the model itself is rarely the constraint — The Bottleneck Has Moved. Take that as settled. What the argument left standing is a plainer question, and it is the sort worth asking slowly: when you press the key, what actually happens? Not what the thing is called. Not what the policy language says about it. What happens.

Two things happen, and they have nothing to do with each other, which is precisely why the trouble goes unnoticed. Something of yours leaves. And something else — the thing you made by correcting the answer — fails to arrive anywhere at all. Almost all of the attention goes to the first. The second is the one that will keep adding value over time. Neither is unusual: as far back as the 2024 Work Trend Index, Microsoft and LinkedIn found seventy-eight per cent of AI users bringing their own tools to work rather than waiting for an approved one.

Where the words go

Press the key and the sentence travels. It lands on a machine belonging to OpenAI, or to Anthropic, or to whoever built the box, and at that instant a second party holds a copy of whatever you wrote. The question that follows is neither technical nor hidden: what are they permitted to do with the copy? Both companies publish the answer, in public, for anyone who goes looking.

On ChatGPT’s Free and Plus tiers the default is that your content can be used to train the next model unless you go and switch that off yourself; the Business, Enterprise and API tiers are excluded from training by default (OpenAI, consumer data-usage policy). Anthropic sets the same switch the opposite way on Claude’s Free, Pro and Max tiers: it trains on your conversations only if you turn the setting on (Anthropic, consumer terms update). Two companies, two opposite defaults, both written down where anyone can read them. Nobody had to deceive anyone for this to become a problem. All it takes is a founder typing fast at eleven at night who has never had a reason to go looking for a settings page.

And what goes into the box is not, on the whole, a shopping list. Cyberhaven’s 2025 AI Adoption and Risk Report puts the share of enterprise data shared with AI tools that counts as sensitive at about a third — thirty-four point eight per cent, in their count. For a spinout six months out of a licence agreement, some part of that fraction is the invention itself: a formulation, a method, a few lines of code that nobody outside the building has ever described. It is now sitting on a server the company does not control, held by a party under no obligation to keep it secret.

Where the learning goes

Now the other half, which almost nobody counts. It is late, and a founder is fixing the model’s draft of an investor update. The model has assumed the round closed in March. It closed in May, and it was a bridge, not a priced round. The founder types the correction and carries on.

Something was produced in that exchange, and it was not the paragraph. It was a piece of judgment — a fact about this company that only someone who was in the room could supply. So ask the bookkeeping question. Where did it go? It went into a browser tab. The founder still holds it, for now, in the way people hold things. The company’s systems learned nothing, because there were no systems, and the tab will be shut by morning.

That this is worth something is not my inference; it is the going rate. In June 2025 Meta paid $14.3 billion for a forty-nine per cent non-voting stake in Scale AI, in a deal reported as a purchase of the company’s data and its people rather than its technology (Reuters, 13 June 2025). A year later Satya Nadella described the same asset from the buying side. Writing about the loop a company builds each time a person corrects, refines or overrides what a model produced, Microsoft’s chief executive said: “This loop becomes the new IP of the firm. I think of it as a hill climbing machine. And unlike most assets, it compounds” (Nadella, June 2026, quoted in Srivastava, “Your Company’s Most Valuable Asset in the Age of AI Is Walking Out the Door”, LinkedIn).

Srivastava’s argument, which is where this piece began, is that most companies are building that loop for somebody else. Be exact about who ends up with what. If the correction is simply thrown away, nobody gets it, and the founder is only poorer than they might have been. If the setting is left on the training default, the correction is not thrown away at all. It goes into the thing everyone else will rent next year.

Which means the founder who pastes a grant application into ChatGPT to tidy the prose and the founder who has never opened one of these tools are not at opposite ends of a single scale. They can be the same person in the same week — handing over unfiled material on one side, keeping nothing of what the work teaches on the other.

Two questions, four answers

Two questions, then, and neither of them is technical.

The first is about exposure. Does this workflow send sensitive, unfiled or confidential material outside a boundary you control, to a party under no obligation to protect it?

The second is about custody. Does what the interaction teaches — the correction, the judgment call, the awkward edge case — end up inside something the company owns, or does it evaporate, or accrue to somebody else’s model?

Here is where the ordinary way of talking about this goes wrong. Most people treat AI use as a matter of degree: too little at one end, too much at the other, sensible somewhere in the middle. But the two questions above are independent. Knowing the answer to one tells you nothing whatever about the answer to the other. Two independent questions with two answers apiece do not give you three positions on a scale. They give you four cases, and the only honest thing to do is look at all four.

Low custodyHigh custody
Low exposureDormant — safe, banking nothingOwned — the target
High exposureRenting it out — the common default posture; the worst cell, not a middle oneFinancing the competition — real gains, captured by the vendor

The reason for drawing it out is the bottom-left cell. A personal chat account with no policy and no habit of capture lands there by construction — maximal exposure, minimal custody — and on the bring-your-own-tool figures above, that is the ordinary setup rather than the exotic one. It is also the cell that feels best from the inside. Drafts appear. Material moves. Nobody is waiting on permission from anybody. Rank it on a single scale and that experience lands in the middle, which is exactly the error: on the map it sits in a corner, worst on both counts at once. It costs money in the dull, ordinary way, too. IBM’s Cost of a Data Breach Report 2025 found organisations with high levels of shadow AI use averaged $670,000 more per breach than those with little or none.

Isometric night scene on a deep ink-blue ground — four identical pale blue-grey floating plinths with torn edges sit at the corners of a diamond, each carrying the same small dark workbench, and two short arrows lie on the ground beside the top plinth pointing away from it to the lower left and lower right. Each plinth has its posture name cut into its right-hand vertical face, reading clockwise from the top Dormant, Owned, Financing the competition and Renting it out; the right-hand and bottom plinths each carry a two-tier tower with a dark pyramid roof and a small ember-topped ledger slab at its foot. The left-hand and bottom plinths each shed a line of four small identical pale parcels off the plinth edge toward the lower left, the gaps widening as the trail runs out of the frame, and a single figure in a bone beanie and ember dress stands on the left-hand plinth.

What the law actually asks

A spinout in its first eighteen months is probably protecting something no patent office has granted anything on, and sometimes something no patent office has yet been told about. In that window the protection is a condition — the information is not public — and the law turns that condition into a test with three parts. The information must be secret. It must have commercial value because it is secret. And its holder must have taken “reasonable steps under the circumstances… to keep it secret” (Trade Secrets (Enforcement, etc.) Regulations 2018, regulation 2).

Read the third part again, slowly, because it is the one doing the work. It does not ask whether anything bad happened. It asks what you did. Paste unfiled material into a consumer tool with no confidentiality undertaking attached and you have not necessarily lost anything; you have handed a future court a question about your own conduct that you would much rather it never had cause to consider.

The National Cyber Security Centre has been saying the plain version of this since March 2023, advising organisations not to “include sensitive information in queries to public LLMs” and not to “submit queries to public LLMs that would lead to issues were they made public” (NCSC, 14 March 2023). Note carefully what that is and what it is not. Pasting a draft into ChatGPT does not, by itself, void a patent application or destroy a trade secret. No source here says so, and I am not going to say it either. The test the law actually applies sits uncomfortably beside an interaction most founders treat as routine.

I have been managing an innovation fund at the University of Surrey, advising academics from proof of concept through to licensing — which is mostly time spent with inventions in exactly this state: before a patent claim is drafted, when the only protection in place is that almost nobody outside the lab knows the thing exists.

A UK tribunal has already looked at the adjacent question and did not care for what it saw. In February 2026 an Upper Tribunal put it about as starkly as it can be put: “uploading confidential documents into an open-source AI tool, such as ChatGPT, is to place this information on the internet in the public domain, and thus to breach client confidentiality and waive legal privilege” (R (Munir) v SSHD [2026] UKUT 81 (IAC), 20 February 2026). Munir is an immigration and professional-conduct case. It is not about patents, and nothing here suggests a court would reach the same conclusion about a formulation typed into a chat window. The narrow fact is the useful one: asked the neighbouring question, a UK tribunal was willing to treat an open AI tool as publication. That is the last characterisation a trade-secret argument wants anywhere near it.

The counter-argument deserves better than a nod, because it is a good one. Used on a paid tier under binding terms that forbid training and onward disclosure, the same paste looks nothing like publication. It looks like a confidential disclosure to a supplier, which is a thing companies do every day and which courts understand perfectly well. That is right as far as it goes, and it is exactly why the fix is a tier rather than abstinence. What it does not do is help the founder who is still on the free tier.

The settings page and the habit

There is a settings page involved, and it accounts for very nearly half of this. Move any workflow that touches unfiled material onto an account whose terms exclude training by default: OpenAI’s Business, Enterprise and API tiers already work that way (OpenAI, consumer data-usage policy), and a locally run open-weight model, or a university’s own research infrastructure, does the same job for the most sensitive material. The tier exists in every case. The only missing step is choosing it. That is an afternoon’s work, and it is not a governance programme.

The custody side has no switch, which is why it is the harder of the two. It means writing the correction down instead of merely accepting the fixed draft. When the model gets the funding round wrong and the founder puts it right, the fix goes into a document, a prompt library, a decision log, or a knowledge layer somebody built on purpose — something the company owns and can still read next year. Do that across a handful of workflows and the company begins to hold the one thing no supplier can sell back to it: its own record of the judgment calls it made, and why it made them that way.

The reason to build that layer is not only defensive. If the model is the commodity input this series has already argued it is, then what a company knows about its own situation is the only thing in the building a competitor cannot also buy. For a founder starting now, that makes custody the opportunity rather than the precaution.

Doing one does not do the other. A business-tier account that never captures a correction is Dormant, not Owned — safer than renting it out, and still banking nothing. And nothing stays where it is left. From a free account with no habit of capture, the path of least resistance runs toward that bottom-left corner rather than away from it. Nobody chooses that cell. They arrive in it.

The cursor, for its part, does not know what it is being handed. It blinks at the same rate for a rewritten email and for the one method that makes the company worth owning, and everything after the key is pressed is bookkeeping. Theirs is kept automatically, in a data centre, under terms that are published and that almost nobody reads. Yours is kept only if somebody decides to keep it — which, on any given Tuesday, means opening a second document before you open the chat window.

Sources

Evidence note

  • Consumer AI retention. Anthropic’s consumer terms train on a user’s conversations only if they switch the “Help improve Claude” toggle on themselves; doing so extends retention to up to five years for new or resumed conversations, while leaving it off keeps the standard 30-day window (Anthropic, consumer terms update). OpenAI runs the opposite default: its Free and Plus tiers train unless a user opts out via Settings → Data Controls, while Business, Enterprise and API tiers are excluded from training by default regardless of any individual toggle (OpenAI, consumer data-usage policy).
  • The Meta/Scale AI deal. According to Reuters, the deal was $14.3 billion for a 49% non-voting stake at a valuation of roughly $29 billion. Its stated purpose — acquiring the company’s data and talent rather than its technology — is as reported, not independently audited here.
  • Shadow-AI breach rate. According to IBM’s Cost of a Data Breach Report 2025, one in five organisations reported a breach involving shadow AI, and organisations with high levels of shadow AI use averaged $670,000 more in breach costs than those with little or none.
  • A trend in the other direction. Netskope’s 2026 Cloud and Threat Report found generative-AI-platform users on personal, unmanaged accounts fell from 78% to 47% year-over-year as more organisations rolled out approved accounts, as reported by Cybersecurity Dive. It is secondary-sourced, and nothing in this piece rests on it.
  • The Work Trend Index figures. The 78% bring-your-own-AI and 75% generative-AI-use figures are from the 2024 Work Trend Index Annual Report, according to Microsoft and LinkedIn. They are a baseline for how widespread ad-hoc AI use already was two years ago, not a claim about today’s exact prevalence.
  • What the Munir case is and is not. R (Munir) v SSHD [2026] UKUT 81 (IAC) is an immigration and professional-conduct matter, not a patent or trade-secret ruling. Its “public domain” characterisation is used here only as evidence that a UK tribunal has treated open AI tool use as equivalent to publication in an adjacent confidentiality context — not as a patent-law precedent, and this piece does not claim the same outcome would follow in a trade-secret dispute.
  • The author’s Surrey role. The author has been Impact Acceleration Manager in the University of Surrey’s Faculty of Engineering & Physical Sciences since January 2020, advising academics from proof of concept through licensing and spinout. That passage is first-person attestation from lived experience rather than a public-sourced claim, and its closing clause is argument from the statutory secrecy test above, not recollection of any particular case.
  • Method and caveats. The Nadella quotation is taken from the Srivastava article and corroborated independently via EdTech Innovation Hub. No figure here is presented as a claim about UK spinout founders as a population: every population-level figure describes the population its source studied, named at first use, and the founder-specific argument is this piece’s own analysis applied to that evidence. Provider data-handling defaults were verified on 22 July 2026 against the providers’ published policies — these settings change, so check the live setting before relying on them.
← Back to SpinUp Forge