Three Alarm Bells: When AI Can Touch All Your Data, Where Is the Security Boundary?

2026-07-09 · By Liu Hongli · Harmonized Intelligence · Column Article No. 35

July 8, 2026 may be a day worth recording in the history of AI development.

Not because of any technological breakthrough that day, but because three things happened at the same time. The three things look unrelated, but all are asking the same question: when AI can access all your data, who guarantees safety?

The first: Microsoft began replacing OpenAI's models in its own products.

The second: Anthropic began forcibly requiring users to upload ID documents and facial data.

The third: China's Ministry of Industry and Information Technology (MIIT) issued an official warning that the AI coding tool Claude Code contains a security backdoor.

Three alarm bells, one direction.

First Alarm Bell: Why Microsoft Stopped Using OpenAI

Microsoft has invested tens of billions of dollars in OpenAI, its largest investor and closest ally. But on July 8, Bloomberg reported that Microsoft has already begun replacing OpenAI's and Anthropic's models with its in-house MAI model in core products such as Excel and Outlook. Tens of thousands of AI prompts have already been migrated each week.

On the surface, it is about saving money. Microsoft's AI chief Mustafa Suleyman put it plainly: "We have paid Anthropic a large amount of money, with the goal of reducing and ultimately eliminating this cost." The cost of in-house MAI is only one-quarter to one-half of rivals', and its efficiency in scenarios like Excel is ten times higher than GPT-5.5.

But saving money is only the surface. The deeper reason is: OpenAI and Microsoft are two completely different kinds of DNA.

OpenAI is built for the consumer side (C-end). It pursues capability leadership, user experience, and iteration speed; its core users are individual developers and tech enthusiasts. These people are most sensitive to capability and relatively lenient on safety. Enterprise clients were never OpenAI's strength.

Microsoft is built for the business side (B-end). Its clients are enterprises; what enterprises care about most is not how strong the model is, but whether the data is safe enough, the privacy controllable enough, the compliance solid enough. Using OpenAI's model means an enterprise's data must pass through OpenAI's servers. For many enterprise clients, this line cannot be crossed. Your code, your customer data, your trade secrets — passing through the servers of an American AI company, even with contractual promises not to use them for training, the moment the data leaves your own infrastructure, risk is already created.

So Microsoft's in-house MAI is not just about saving money, but about taking control of data back into its own hands. MAI is trained on "clean data": entirely based on publicly licensed, human-generated data, containing no synthetic data and no open-source training sets, specifically to help enterprises avoid copyright risk. Security is built in at training time, not patched as an after-the-fact protection.

Suleyman said one thing: Microsoft does not want to be merely a "distributor" in the AI age, but to become a true "manufacturer." The subtext is: handing core AI capability to others is an unacceptable risk for B-end enterprises.

Microsoft CEO Satya Nadella also said at the Build conference: "Artificial intelligence should serve human society rather than replace it; we must avoid technology concentrating power and diminishing human agency." In the context of July 8, this statement carries deeper meaning. Building in-house models is not for a technology arms race, but to let enterprises truly control their own AI capability, rather than handing their lifeline to others.

Top enterprise clients like McKinsey have already started using MAI's customized private models. Not because MAI is the strongest, but because keeping data in their own hands matters more than how strong the model is.

Knowing what their clients truly want — not chasing the strongest, but the most fitting — this itself is a kind of judgment.

Second Alarm Bell: Do You Have to Hand Over Your ID to Use AI?

Also on July 8, Anthropic's real-name verification policy officially took effect.

From that day, all Claude individual users must complete real-name authentication. Not phone-number verification, but uploading ID documents plus a real-time facial scan. All data is processed by a third-party company called Persona.

Anthropic's reason is to prevent abuse, which is understandable. But the question is: when an AI company demands that users worldwide hand over ID documents and facial data, who assesses the risk inherent in this act itself?

A leaked password can be changed; a stolen account can be recovered. But biometric data is different — your face cannot be swapped, your fingerprint cannot be changed. Once this information leaks, it is permanent, irreversible loss. This is the most fundamental difference between biometric information and all other personal data: other data, once leaked, still has room for remedy; biometric data, once leaked, has no possibility of remedy whatsoever.

For Chinese users, the problem is even more serious. A Chinese ID is bound to a complete chain of personal information: name, address, date of birth, ID number. Add a facial scan, and it can almost reconstruct a person's complete digital identity. If this information is improperly collected, stored, or leaked, the consequences are far more severe than a password leak. Identity theft, precision fraud, social-engineering attacks — the entry point for all these risks may be a seemingly ordinary AI real-name authentication.

A more critical question: where are the global ID and facial data that Anthropic collects through Persona stored? Who regulates them? If they leak, what recourse do users have? Both Anthropic and Persona are American companies; once Chinese users' data is submitted, it falls outside the jurisdiction of Chinese law. If something goes wrong, who do you turn to?

A natural question: if an AI company's own coding tool is found to have a security backdoor, what qualifies it to demand that users worldwide hand over ID documents and facial data?

Third Alarm Bell: AI Secretly Sent Your Information Back

On July 8, China's Ministry of Industry and Information Technology issued an official risk warning: the AI coding tool Claude Code contains a security backdoor, causing serious harm.

Claude Code is an AI coding tool developed by Anthropic that autonomously writes and fixes code based on text requests. MIIT monitoring found that the tool, in versions 2.1.91 through 2.1.196, had a monitoring mechanism built in that, without user consent, transmitted sensitive information such as users' region and identity identifiers to a remote server. MIIT recommended immediately uninstalling or upgrading the affected versions, and strengthening control over external-connection permissions of development tools to prevent sensitive data from being transmitted out in violation of rules.

This is not an ordinary security vulnerability. This is an AI tool that, without the user's knowledge, secretly sent the user's information back.

Claude Code sits on the developer's computer and can read and write code files, execute commands, and access project data. In other words, it has access to almost all data on the developer's computer. And on a developer's computer, there are often an enterprise's core code, trade secrets, and customer data.

This incident exposes a deeper problem than a single backdoor: the permissions of AI tools are too large.

Windows and Office have existed for decades; their security issues have been repeatedly polished, their permission boundaries are clear, and their trust foundation was built up over decades. Even so, vulnerabilities still occur from time to time. But at least everyone knows what Windows can and cannot touch, and when something goes wrong there is a mature emergency mechanism.

Today's new generation of AI tools is completely different. Right out of the gate they demand access to all files on your entire computer: your documents, code, email, chat history. They can read and write, copy, upload, and transmit over the network. Their permissions are greater than any traditional software, yet their trust foundation is the weakest. They have existed only a year or two; their security has not been fully tested, and there is no clear consensus on permission boundaries.

What is more fatal is that AI tools' behavior is not as predictable as traditional software. Traditional software executes preset logic, so you can roughly know what it is doing. An AI tool makes autonomous decisions, judging what to do from context, and even the developer cannot fully predict its behavior. An AI tool that can make autonomous decisions, access all your files, and connect to the network — if it secretly transmits data, you may never even find out.

This is not a problem of any single product. As all AI tools move in the direction of "installing into your computer and operating all your files," this is a systemic security proposition.

Three alarm bells, one question

Microsoft stopped using OpenAI because using someone else's AI means enterprise data must pass through a third party. Anthropic wants your ID and face because to use its AI you must first hand over your identity. Claude Code was found to have a backdoor because AI installed on your computer can touch all your files and may secretly send them back.

Three alarm bells, all pointing to one question: when AI can access all your data, where is the security boundary?

Microsoft's judgment strength is that it knows what enterprise clients care about most, so it has chosen to put control over its data back into its own hands. But Microsoft is only one company; not all enterprises can build their own AI models. Most enterprises face a dilemma: use AI, and data security is not guaranteed; don't use AI, and competitiveness falls behind.

This is not a problem of any single company; it is a structural proposition that AI development inevitably faces today. AI's capabilities are breaking through rapidly, which is a good thing. But breakthroughs in capability do not automatically bring safety and controllability. On the contrary, the stronger the capability and the greater the permission, the greater the potential damage.

When AI can read all your files, see your code, demand your ID and face, and transmit data over the network, its where is the security boundary safety cannot be guaranteed by corporate self-discipline alone. Security mechanisms must be built in from the design stage, not patched after incidents. It must be made clear who collects the data, who stores it, and who is accountable for leaks. All the more, in areas concerning personal privacy and biometric data individual rights, the ultimate control over data must remain in the users' hands.

On July 8, three alarm bells rang at once. It marks a turning point: AI development has reached a stage where we can no longer talk only about capability and not about safety.

Capability determines what AI can do. But boundaries determine whether it should.

AI and OPC

Every technology update brings three things: a wave of people celebrating, a wave of people anxious, and a wave harvesting the cognitive gap.

On July 7, OpenAI released GPT-5.6 and announced the merger of Codex and ChatGPT, officially renamed ChatGPT Work. On the same day, Tencent WorkBuddy announced that its daily active users had surpassed 13 million, shipping 43 versions in three months. In almost the same week, Alibaba fully banned Claude Code over security risks, while ByteDance's Doubao had quietly shut down its "app generation" feature as early as May 31. Every technology update brings three things: a wave of people celebrating, a wave of people anxious, and a wave harvesting the cognitive gap. Those who learned to build agents last year find themselves obsoleted by Skills this year; those learning Claude Code this year may find next week that their company has banned it. The faster you learn, the faster you become obsolete. The tighter you chase, the deeper the anxiety. This raises a question: is chasing technology the core of running an OPC?

I. The Dilemma of Chasing Technology

There is a saying in tech circles: if you have studied a technology for three days and still don't get it, don't bother — because in a couple of days it will be replaced. It sounds like a joke, but it is more real than a joke. WorkBuddy shipped 43 versions in three months, one every two days on average. An ordinary person has just mastered the previous version's operations when the new version has already changed the interface, the features, and the interaction logic. The tricks just learned may be unusable tomorrow. The iteration speed of technical tools always outpaces the speed of individual learning. And the reaction speed of enterprise organizations is always slower than the iteration speed of technical tools. Chasing technology, you can never catch up. It is not that you chase too slowly; it is that the direction is wrong.

II. Clients Do Not Pay for Technology

Many people running an OPC think that because they use the most advanced AI, clients will pay. This is a common thinking trap. A client has ten thousand needs, but only pays for the one need that solves a specific problem. A client pays always because you solved their problem, not because of what technology was used in the process. If, after using AI, you provide a solution different from others, or drive costs lower, the client is willing to pay for that. The client's reason to pay is "different" and "cheaper," not "used AI." AI plays no decisive role in an OPC's business model. It is an amplifier. If there is unique value, AI helps amplify it; if there is nothing, it amplifies nothing. This is the correct order: first think clearly about what you have, then think about how AI can help amplify it.

III. Three Questions to Think Through Clearly

If you want to run an OPC — whether starting a company as an entrepreneur or building a super-team inside a corporation — there are three questions you need to think through clearly, and honestly, not telling yourself a story. First, why does the client pay? It is not whether the client has this need; there are many needs, but few the client is willing to pay for. What you must find is the need for which the client is willing to part with real money. Second, why does the client buy from us and not from others? What exactly is the differentiation? Many people cannot answer past this question. If you feel you should be stronger than everyone at everything, that is not confidence, it is self-deception. Third, why does the client keep paying? If the client buys once and leaves, that is not a business model, it is a traffic game. A traffic business is always anxious, because you are forever hunting for the next client. A truly good business model is one where the client buys and comes back, even refers others. These three questions have nothing to do with AI. What industry to enter, what problem to solve, what unique value to offer — that is the commercial essence of an OPC. AI only helps amplify, accelerate, and implement the answer after those three questions are answered.

IV. The Essence of OPC Is Entrepreneurship

At the end of the day, an OPC is essentially an act of entrepreneurship. Whether registering a company outside or building a super-team inside a corporation, the essence is creating a commercial closed loop: make the thing, sell it, earn a profit, and sustain it. But many people do OPC in reverse order: learn AI tools first, then think about what business to do. After learning a bunch of tools, they start wondering: what am I good at, what resources do I have, what do I know. That is not entrepreneurship; it is self-indulgence — imagining for yourself a seemingly self-consistent business model, only to be stumped at a shareholders' meeting by the question "who do we sell this to, and why would a client buy from us and not others." A business model is told to yourself, not to the client. A client will not pay just because there is a good business model; it has nothing to do with the client. The correct order of thinking starts from "what problem to solve." Peter Thiel, in Zero to One, says the essence of entrepreneurship is one question: on what important problem do you have a different view from others? That is differentiation. Either you can drive costs lower, or you solve things differently from others. If you think the same as others and do the same, why would a client buy from us? This returns to three levels: have you spotted an unmet need? Have you seen an undervalued technological shift? Do you have a contrarian business logic — when everyone thinks this way, we think that way? The answers to these questions do not come from AI tools, but from deep accumulation in the industry. It is not about knowing a bit more information than the client; the information gap is being flattened by AI. What is truly valuable is deep, structured, and battle-tested judgment: knowing what direction works, knowing what approaches will go wrong, knowing what kind of client suits what kind of solution. This capacity for judgment is honed over many years in the industry, through repeated mistakes, reviews, and accumulation. It cannot quite explain why it judges this way, but it just knows. This is the most core asset of an OPC.

V. Rural OPC: Technology Is Not the Barrier

This April, we partnered with Xiaomi Group on a "rural OPC" project. We selected 30 village officials from across the country to train in Beijing; about 10% of them were flying for the first time, visiting Beijing for the first time. Can they do OPC? Their strengths are clear: they understand their village's agricultural products, know what is good, and have a heart to serve the countryside. Their weaknesses are equally clear: they cannot shoot short videos, cannot do livestreaming, cannot write public-account posts, cannot promote their own products. Yet in this era, the most important capability for selling goods is precisely short videos and livestreaming. How can AI help them? Cannot shoot short videos — AI helps write scripts, helps with positioning, helps generate content. Cannot do livestreaming — AI helps design the pitch, helps arrange the flow, helps with livestream review. A village official who may never have shot a short video in their life can get started in half a day. This case illustrates one thing: technology is not the barrier. Village officials on their first flight can learn AI applications in half a day; what does an MBA or an office worker have to be anxious about in learning technology? The real question is not whether you can use AI, but whether, like them, you have good products, people who genuinely want to serve, and real value. They have the best agricultural products and the most sincere hearts; all they lack is a tool to spread the good things out. AI happens to fill exactly that gap. If you have nothing, AI cannot help either. If you have it, AI becomes wings upon a tiger.

VI. Do Not Start OPC with Technology

Every technology update creates a wave of celebration and anxiety, but neither celebration nor anxiety is a business judgment. A business judgment is: what problem can be solved, what value can be created, why the client keeps paying. Once these questions are clear, tools will iterate, but value will not become obsolete. AI is an amplifier. What it amplifies is business value, not technical capability. If the value is zero, no matter how strong the amplifier, it cannot amplify air.

Harmonized Intelligence Back to Harmonized Intelligence