ZEROCK

Hand Your Proprietary Data to AI and Your "Moat" Disappears: Why a Major Drug Maker Turned Down Anthropic's Request

Published2026-07-26Ryuta Hamamoto

A major drug maker is reported to have turned down a request from Anthropic to hand over its proprietary data. Why is that a reasonable call? Proprietary data is the moat of competitive advantage, and once an external model learns from it, that advantage commoditises. This piece works through the strategic risk, which applies just as much to Japan's manufacturing, medical and agricultural data, and the design that keeps data inside your own walls.

Hand Your Proprietary Data to AI and Your "Moat" Disappears: Why a Major Drug Maker Turned Down Anthropic's Request
シェア

Hello, this is Ryuta Hamamoto from TIMEWELL.

As using AI becomes the norm, a quiet but serious question is rising up: how far may we hand our company's proprietary data to an external AI model? It sounds simple, and yet the more you sit with it, the more it opens onto the heart of business strategy.

The trigger was a story that spread abroad. A major drug maker holding vast proprietary data is reported to have turned down a request to collaborate from an AI company. At first glance it may look like a plain piece of news. But the reasoning behind it is, to my mind, deeply fundamental, and it maps directly onto Japan's manufacturing, medical and agricultural sectors. In this article I take that one episode as a starting point and think through how we ought to protect the "moat" that proprietary data represents. For the factual parts I show the basis in footnotes, and I keep the parts that are my own opinion clearly separate, labelling them as "my view."

A major drug maker is reported to have declined an AI company's request

Let me first set out, accurately, what has been reported.

The investor David Friedberg is said to have spoken to the following effect on the podcast "All-In," in the episode released on 4 July 20261. Namely, that the AI company Anthropic approached large life-science and pharmaceutical companies holding vast proprietary data, proposing that if they shared their data, it would provide some form of proprietary value, such as early access.

Friedberg then said, to the effect, that nearly everyone he had spoken with had woken up to the fact that "they are trying to commoditise everyone's business"2. Commoditisation, put simply, is the state where the same sort of thing can be had at any company, a flattening into sameness. Differentiation stops working, and you can compete only on price. For a company it is a frightening word, because it means the slow erosion of the very source of profit. Most of the companies approached, it is reported, concluded that sharing data would lead to the commoditisation of their own business, and declined.

Here I want to add one important caveat. This is, in the end, Friedberg's own remark, reported at second hand. Anthropic and the drug makers have not officially said any such thing, and I have not been able to confirm the full verbatim of the episode myself. So in this article I treat it not as an established fact but in the form of "this is how it is reported."

On the other hand, there are background facts that can be confirmed. On 20 October 2025 Anthropic officially announced an initiative called "Claude for Life Sciences"3. It supports life-science research from drug discovery through to commercialisation, with features such as integration with research databases and skills that assist specialist work. The announcement named several major pharmaceutical companies and research institutions as adopters and partners. For the avoidance of doubt, I should add that whether the companies publicising these partnerships are the same as the ones Friedberg describes as "having declined" is not something we can know. The fair reading is that the two should not be casually joined together.

One more thing I want to stress: this is not a story about one side being in the wrong. Anthropic's proposal, to offer benefit in exchange for data, is a legitimate business proposal. And the drug makers' judgment, to keep data in hand as a source of competitive advantage, is a reasonable management decision. What sits here is not right and wrong but a divergence of interests over the value of proprietary data, and it should be viewed neutrally. That is how I see it.

On that footing, please read the analysis from here on, of "why declining is reasonable," as my view. Incidentally, if you first want to know where your own company stands in terms of how ready you are to make use of AI, our free AI readiness check lets you begin with a self-assessment that takes only a few minutes.

Why is "declining" reasonable? Because proprietary data is the "moat" of competitive advantage

When I explain what makes a company strong, I often use the word "moat." The moat that rings a castle. The deeper and wider it is, the harder it is for an enemy to storm in. In business, the moat is exactly what a rival cannot easily copy.

Proprietary data is a prime example of such a moat. The experimental data and clinical knowledge a pharmaceutical company has accumulated over many years, for instance, is not something another firm can produce overnight. It takes vast time and cost, and a pile of failures, before it is finally in hand. That is precisely why only the company that holds it can stand at an advantage. Management scholarship has long organised this way of thinking as locating the source of competitive advantage in the distinctive resources a firm holds. The point is that data creates value only while you hold it exclusively.

Onto this is grafted a troublesome property of data as an asset. Unlike physical goods, data is easy to copy and does not diminish however much you use it. Hand it to someone, and that someone can hold the very same thing. And once it is blended with the data of others and generalised into the form of a model, it is no longer "yours alone."

Look again, through this lens, at the act of letting an external AI model learn from your proprietary data. Your knowledge dissolves into the model as one of its parts, and once other companies come to use that model too, the answer that once only you could give can now be given by others in the same way. Picture the water of the moat leaking little by little to the outside. You let go of your one differentiator with your own hands. This, as I understand it, is the substance of what "commoditisation from handing over data" means.

So the judgment that the drug makers are reported to have made, to decline the request, holds together in the sense of protecting the moat. Again, this is not a rejection of Anthropic's proposal. For the side handing over data, it is a matter of calculation, of whether the price and the benefit balance out. And in an industry where proprietary data all but decides the whole of competition, that calculation tends to tilt toward "do not hand it over." That, I think, is the shape of it.

Struggling with AI adoption?

We have prepared materials covering ZEROCK case studies and implementation methods.

Japan's manufacturing, medical and agricultural data share exactly the same structure

Now for the real subject as far as we in Japan are concerned. This is not a matter only for a distant overseas pharmaceutical industry. It is, I believe, the very structure Japanese companies are living inside right now.

Manufacturing makes it easy to see. Drawings, machining conditions, the intuition and the knack accumulated on the shop floor as countermeasures against defects. This design and production know-how is tacit knowledge that is hard to let out, and it is precisely for that reason that rivals cannot copy it and it has served as a source of competitive strength. Feed it as it is into an external AI's training and the strength Japanese shop floors have honed over decades can be generalised and redistributed. Years of accumulation could, before you notice, become the flattened standard. The issue of data sovereignty in manufacturing is, I think, in no way overstated.

Medical data is the same, or rather it demands even more care. Medical information is high in value and high in sensitivity. In Japan a framework called the Next Generation Medical Infrastructure Act sets strict rules on the secondary use of medical information4. The law was enacted in 2017, and a 2023 amendment added a scheme for pseudonymously processed medical information. When medical data is provided externally, the premise, that the parties should properly manage the ownership of the rights and the scope of use, is backed even at the level of the system.

Agriculture is no exception either. WAGRI, the agricultural data collaboration platform led by the Ministry of Agriculture, Forestry and Fisheries, advances the sharing and use of agricultural data such as growth, weather and soil, while at the same time working out the rules on who owns that data and under what conditions it may be used5. That agricultural data is a valuable asset, and that the parties should hold the terms of its provision, is recognised on the policy side as well.

And this reaches beyond the profit and loss of individual companies. In the context of the Economic Security Promotion Act and the like, the Japanese government has placed the management of industrially important technology and data on the policy agenda6. The point is that a company's proprietary data and technical know-how can, in effect, take on the character of a national asset. Of course, this data is not defined as a "national asset" in law. But carelessly letting the proprietary data of fields like manufacturing, medicine and agriculture flow out to external models can bear not only on a single company's competitiveness but on the industrial base of the country as a whole. Holding it that way is, in my view, not going too far.

Countermeasure one: first make "no training use" explicit in the contract

So what should we do? From here I turn to countermeasures.

The first step is to state plainly, in the contract, that "the data you input will not be used for training." Many of the major AI vendors offer, in their services for businesses, a setting of "we do not use input data for training" for API use and enterprise use. Simply not neglecting to confirm this already lowers much of the risk.

This way of thinking sits in line with the direction the administration points to. On 2 June 2023 the Personal Information Protection Commission published its "Alert Regarding the Use of Generative AI Services"7. It flags the point that information entered into a generative AI may be used for machine learning, and asks businesses to confirm sufficiently that the provider will not use that input data for training and so on. The stance shown in the field of personal information applies, in my view, by the same reasoning to proprietary data such as technical information and trade secrets. Put a line into the contract, confirm the setting. It is unglamorous, but this is not a step to skip.

That said, to be honest, I cannot go so far as to say the contract alone is enough for peace of mind. Adherence to the promise is subject in part to the vendor's operation and to revisions of the terms, and it is structurally subject to the jurisdiction of the country where the vendor is located. On this point, in the companion piece Data Sovereignty and Export Control in the Age of AI, I dig in more deeply, working from primary legal sources. Read the two together and the limits of the contract come clearly into view.

Countermeasure two: fundamentally, step into a design that "cannot be taken out"

So to the surer second countermeasure. For proprietary data that must be protected, step into a design in which the AI vendor physically cannot learn from it or take it out in the first place. This is my central proposal.

Concretely, that means running the AI under your own management, placing the execution environment for data and models inside the country, and completing the processing in a closed environment that does not connect to the outside. If everything from input through processing to output is closed within your own walls, the very route by which data is drawn up into a model and generalised ceases to exist. You block the outlet through which the moat's water would leak, right from the start.

The global debate over AI is, in fact, echoing this direction. A move that avoids lock-in to a specific vendor, that keeps an organisation in a state where it can choose for itself where it puts its own data and where it deploys, in other words that values sovereignty, is spreading alongside a current in support of open models. I set out this background in Open Weights and American AI Leadership. The point is that where you source your models from, and where you place your data, is no longer a technology selection but is becoming a management decision.

Of course, walling everything up inside your own company is not always the right answer. There are certainly situations where teaming up externally is reasonable, given a no-training contract, appropriate anonymisation, or the benefit gained from joint development. Which is why I have no intention of stoking a blanket "never hand data to AI." What matters is the line: separate the information that must be protected from the information that need not be, and for the former choose a design of "do not hand over, do not let out." That judgment is, I think, the crux of data strategy from here on.

The reason we offer a service called ZEROCK is that we feel we are getting somewhere with this very challenge. ZEROCK is an enterprise AI that runs on domestic AWS servers, designed to put internal knowledge to use without letting it leave the company. It carries a knowledge-control mechanism that manages who can use which information and how, so you can enjoy the convenience of AI while keeping proprietary data in hand as your own moat. It is, as I see it, a service born to face head-on the question we have discussed today: whether to hand over your proprietary data.

To sum up

It ran long, so let me organise the key points.

  • A major drug maker holding vast proprietary data is reported to have declined an AI company's request to provide data (Friedberg's remark, reported at second hand; not the official position of Anthropic or of any company)
  • Why is it reasonable? Because proprietary data is the "moat" of competitive advantage, and once an external model learns from it and it blends with the data of others, you let go of your one differentiator with your own hands and commoditise (my view)
  • Both Anthropic's proposal and each company's judgment are legitimate and reasonable. This should be viewed neutrally, not as right and wrong but as a divergence of interests over the value of proprietary data
  • Japan's manufacturing know-how, medical data and agricultural data share exactly the same structure. In the Next Generation Medical Infrastructure Act, WAGRI, the Economic Security Promotion Act and more, the management of data and the ownership of rights are important issues at the system level too
  • The countermeasure comes in two stages. First make "no training use" explicit in the contract (in line with the Personal Information Protection Commission's thinking), and for information that must be protected, step fundamentally into a design that cannot be taken out (self-managed, domestic servers, a closed execution environment)

While you wait for the system and the rules to firm up, data keeps flowing somewhere every day. Start by taking stock of what counts as a "moat" for your own company, and which information must never be let outside. If you would like to work through, in concrete terms, a structure that protects proprietary data while making use of AI, please talk to the ZEROCK team. We will start with you from bringing a design that protects the moat down to the practical work in front of you.

References and primary sources

Footnotes

  1. David Friedberg's remark on the All-In Podcast episode 279, "The AI Ownership War Has Started" (released 4 July 2026). This article treats it as Friedberg's own remark, reported at second hand. Understood via a secondary summary (Podcast Alpha). https://podcastalpha.substack.com/p/ai-ownership-war-has-started

  2. Ibid. The wording attributed to Friedberg ("They're approaching these large companies with large proprietary data sets and saying, if you share your data, we will give you early access, some sort of proprietary value." and "I think nearly everyone I've spoken with has woken up to the fact that they are trying to commoditize everyone's business.") is based on reporting and quotation rather than the verbatim of the episode, and the exact wording is unconfirmed. https://podcastalpha.substack.com/p/ai-ownership-war-has-started

  3. Anthropic, official announcement of "Claude for Life Sciences" (20 October 2025). https://www.anthropic.com/news/claude-for-life-sciences

  4. Act on Anonymously Processed Medical Information to Contribute to Medical Research and Development (Next Generation Medical Infrastructure Act, Act No. 28 of 2017; the 2023 amendment added pseudonymously processed medical information), e-Gov Law Search. https://laws.e-gov.go.jp/law/429AC0000000028

  5. Ministry of Agriculture, Forestry and Fisheries, "Agricultural Data Collaboration Platform (WAGRI)." https://www.maff.go.jp/j/kanbo/smart/wagri.html

  6. Act on the Promotion of Ensuring Security by Taking Economic Measures in an Integrated Manner (Economic Security Promotion Act, Act No. 43 of 2022), e-Gov Law Search. https://laws.e-gov.go.jp/law/504AC0000000043

  7. Personal Information Protection Commission, "Alert Regarding the Use of Generative AI Services," 2 June 2023. https://www.ppc.go.jp/news/careful_information/230602_AI_utilize_alert/

Ready to optimize your workflows with AI?

Take our free 3-minute assessment to evaluate your AI readiness across strategy, data, and talent.

Share this article if you found it useful

シェア

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

無料ダウンロード資料

AI Security & Vendor-Dependence Risk Self-Check Sheet (by level, 2026)

A fill-in self-check across five dimensions (supplier diversification, data region, re-training prevention, output governance, geopolitical/export risk) by level (L0–L3), based on the NIST AI RMF (AI 100-1) and the PPC alert (June 2, 2023).

無料でダウンロード
無料診断ツール

御社のAI導入準備、どこまで進んでいますか?

戦略・データ・人材の観点で準備度を可視化。3分の無料診断で次の一手が分かります。

Learn More About ZEROCK

Discover the features and case studies for ZEROCK.

Related Articles