“Never trust a computer you can’t throw out a window,” quipped Steve Wozniak in 1997, when computers were still defenestrable.
As a building-sized computer, AI is almost impossible to trust. Claude seems hell-bent on creeping out of the chat box and into the rest of your computer. You are never quite sure whether you are using ChatGPT or it is using you. Fear and Loathing in Las Vegas has nothing on Gemini for hallucinations.
For businesses, the trust deficit is a shackle on AI. Actively excluded from sensitive data, AI is kept away from the most useful context and limited to superficial use cases. Owning your stack changes that, and it is within reach of most companies.
Key idea
Frontier labs are built for exploration and are not designed to be fully trustworthy. Risk-aware businesses are forced to keep sensitive data out of AI, resulting in lukewarm solutions. Open-source software and open-weight models enable ownership of the full stack, paving the way for custom workflows and in-house AI products.
Untrustworthy by design
Lab leaders love messianic language. Part of it is marketing, and part of it goes back to the origin stories of companies with deep roots in sci-fi and rationalist communities. Can you imagine Salesforce musing about “humanity” or keeping philosophers on the payroll?
When labs talk about AGI and superintelligence, businesses see more risk than reward. They suspect that the apps are not designed to help them run more efficiently, but that their data is being farmed in the service of that weird and fuzzy purpose.
Behind this lies the Labs’ economic model. Models are becoming commodities: they perform similarly, and switching between them costs little. To mitigate this, the labs are moving “up the stack”, into products, knowledge, embedded engineers and eventually “digital workers”. Agents become employees you cannot fire. In Wozniak’s terms, you cannot throw it out of the window.
Businesses cannot be doing with all this. They need portability, risk management and governance. Outright bans on generative AI fell sharply this year, yet exposure of sensitive data still ranks among the top risks. When the context that makes AI useful is out of reach, it is little wonder that 95% of enterprises see no measurable return.
Trust is critical to adoption
Using commercial AI for critical workflows is a bit like running your corporate website on LinkedIn. Publishing on social media is intuitive and inexpensive but moves ownership, branding and workflows outside a company’s control. Bigger than your average window, social media cannot be trusted either.
Companies worked this out a long time ago. They keep a presence on LinkedIn, but they build the corporate website on a dedicated platform to own the content, control the brand and enforce their workflow. Above all, it runs reliably and consistently on infrastructure, processes and SLAs aligned with their requirements.
A trusted AI stack works the same way. Customer records, product information and staff data can all be put to work, held on your own database and servers, under the same governance rules as every other application.
Ownership also lets you map AI to your workflows and team structures. Build under your rules, and information flows faster between colleagues, across departments and to customers. Controlling the roadmap matters: AI solutions must be able to evolve with the company’s needs and strategy.
How to own your AI stack
Letting go of commercial AI and owning your own stack is surprisingly easy. Cloud providers and specialist products are the first area to explore. Knowledge platforms such as Glean and Nous AI connect to existing systems and put company knowledge to work.
To truly own the platform, go a step deeper. Open-source is enjoying a renaissance, offering cost-effective options across the stack. Ollama and LM Studio make it easy to run models on a laptop or server. Otari serves as a single gateway for both commercial and open-weight models, so you can route requests, enforce budgets and track usage in one place.
This enables plurality in the model layer. EU-based options such as Mistral and Chinese open-weight models such as Qwen and DeepSeek offer sufficient power for most purposes at a fraction of the cost. Keeping data and documents in your own environment ensures trust, as sensitive material never leaves your perimeter.
Multiple robust solutions also exist for the interface layer. Open WebUI, LibreChat and AnythingLLM let you create custom experiences for teams or customers, with full control over branding, context, collaboration and approval workflows.
Takeaways for business
The biggest myth peddled by AI Labs is that they own all the innovation. Once they move to their own stack, companies are discovering they can design their own AI products. To get there, business leaders should remember:
Remain vigilant of vendor lock-in. Business AI adoption is stalling because AI labs were never designed to be trusted and their business model now depends on being irreplaceable.
True adoption goes through trust. To go beyond shallow use cases, you need to train AI on your entire dataset, adapt it to specific workflows and control the roadmap.
You can own the entire AI stack. From open-source solutions to open-weight models, AI can be an interchangeable component that runs in your own environment.
Is it time to throw commercial AI out of the window? No. The frontier keeps moving, and many applications will still benefit from advanced capabilities. But leaders must put in place a system where every part of the AI stack can be trusted. To do that, they need to be able to chuck it out the window.
Further reading
Up the stack (AI as Normal Technology) – Why the labs’ business model depends on moving into your workflows.
What to expect for open source in 2026 (GitHub Blog) – The growth, and the growing pains, of the ecosystem a trusted stack is built on.
Otari: own your AI stack (Mozilla.ai) – Mozilla’s case for a self-run gateway, using almost exactly this post’s framing.
2026 data and privacy benchmark study (Cisco) – Companies are loosening AI bans but still worry about sensitive data.



