Back to Blog

The Confidant’s Dilemma — What the Big Four’s record tells us about handing your secrets to AI labs

Every professional services relationship rests on an awkward bargain. The client hands over its most sensitive information, and the adviser promises to use it only for the client’s benefit. Auditors see the books before the market does. Tax advisers see the structures before the regulator does. Strategy consultants see the plans before competitors do. The entire economics of the Big Four and firms like McKinsey depend on this asymmetry, and so does the temptation to abuse it.

Alex Karp, Palantir’s chief executive, went on CNBC in early July 2026 and argued that frontier AI companies now sit on the same bargain at a far greater scale. In his telling, enterprises routing their proprietary data, workflows, and business logic through OpenAI’s and Anthropic’s models are paying a premium for the privilege of surrendering their competitive edge, and doing so to counterparties that have started competing with them directly. “Something has gone completely wrong,” he told Squawk Box, in an interview that was nominally about a Palantir and Nvidia partnership and became something else entirely.

The claim deserves to be taken seriously. The more useful move is to test it against the historical record of firms that previously held such privileged access. That record is not reassuring, and the penalties, when they arrived, were often strikingly small relative to the value of the information involved.

How the access works, and why it corrupts quietly

The Big Four occupy a peculiar institutional position. Statutory audit gives them a legal right of access to client information that no other private actor enjoys, and the consulting and tax practices bolted alongside the audit function extend that access into strategy, systems, and government policy formation. McKinsey and its peers have no statutory rights, but the trusted adviser model produces something similar in practice: the client cannot easily evaluate the quality of the advice, so the relationship runs on a pledge that the adviser will not exploit its informational advantage [5].

The academic literature on why this pledge fails is more interesting than the popular account of rogue individuals. Moore, Tetlock, Tanlu, and Bazerman argued in a widely cited paper that auditor independence failures are less about deliberate corruption than about moral seduction, a gradual process through which professionals become compromised by conflicts of interest without ever perceiving themselves as biased [1]. Experimental work with practicing auditors supports this: the bias appears to operate unintentionally, beneath the level of conscious dishonesty [2, 4]. Sah’s work on conflicts of interest adds a further discouraging finding: namely, that the standard remedies, disclosure above all, tend to fail or backfire because they misunderstand the underlying psychology [3]. And at the level of the firms themselves, discourse analysis of Big Four executives testifying before the UK Parliament shows a well-rehearsed rhetorical machinery for deflecting reform while presenting the firms as indispensable [9]. Moore and colleagues called the macro version of this pattern strategic issue cycling: scandal, outrage, partial reform, quiet erosion, next scandal [1].

That framing matters for the AI comparison, because it suggests the risk is structural rather than a matter of finding trustworthy counterparties.

The record: abuses and penalties

The record of what actually happened, and what it cost, reads as follows.

Firm and case What happened Penalties and outcomes
PwC Australia, tax leaks (2013 to 2023) International tax partner Peter Collins sat on confidential Treasury consultations designing the Multinational Anti-Avoidance Law, then shared the confidential material internally. PwC built a global team around the intelligence and marketed circumvention structures to multinational clients, including US technology companies, before the law took effect. Internal emails reportedly reached over 140 names. Collins deregistered by the Tax Practitioners Board with a two-year ban (January 2023), then banned by ASIC from financial services for eight years. CEO Tom Seymour resigned; nine partners stood down; the firm divested its government consulting business and lost federal work; over 300 jobs cut. The AFP opened a criminal investigation. The PCAOB later fined PwC Australia US$600,000 for failing to report the TPB proceedings on time. The ATO’s penalties for false privilege claims, initially around A$1.4 million, were roughly halved and settled confidentially.
KPMG US, the PCAOB inspection leaks (2015 to 2017) Senior partners obtained stolen confidential lists of which KPMG audits the regulator would inspect, then revised completed audit workpapers to reduce deficiency findings. The SEC compared it to stealing the exam. KPMG paid a US$50 million SEC penalty in 2019, admitted the facts, and accepted an independent consultant. Cynthia Holder pleaded guilty; David Middendorf and former PCAOB employee Jeffrey Wada were convicted of wire fraud, though those convictions were later abandoned after prosecutors conceded the inspection lists did not qualify as property under the wire fraud statute. A supervising partner was censured and fined US$100,000 by the PCAOB.
KPMG US, Scott London (2010 to 2013) The partner in charge of the Pacific Southwest audit practice fed confidential earnings and merger information on clients including Herbalife and Skechers to a friend, who traded ahead of announcements for roughly US$1.2 to 1.3 million in profit and paid Scott London in cash, jewellery, and a Rolex. Scott London was sentenced to 14 months in federal prison and fined US$100,000. KPMG withdrew audit opinions and resigned from Herbalife and Skechers. The firm itself faced no SEC or PCAOB fine.
Deloitte US, Thomas Flanagan (to 2008) A vice chairman traded repeatedly in the securities of Deloitte audit clients, including Best Buy, Sears, and Walgreens, on inside information about earnings and an acquisition, generating over US$430,000 in profits, and tipped his son. Flanagan pleaded guilty to securities fraud and received 21 months in prison plus a US$100,000 penalty. Deloitte funded independence investigations; the firm was not sanctioned and no major client fired it.
McKinsey, Anil Kumar and Galleon (2003 to 2009) A serving senior partner sold material non-public information stolen from McKinsey clients, most notably AMD, to hedge fund manager Raj Rajaratnam for cash routed through offshore accounts. Kumar pleaded guilty, cooperated extensively, and received two years’ probation with US$2.26 million forfeited. Rajaratnam received 11 years. McKinsey the firm faced no charge.
McKinsey, Purdue Pharma (2004 to 2019) The firm advised Purdue on how to “turbocharge” OxyContin sales while separately holding advisory relationships inside the US health regulatory apparatus, a conflict it did not disclose. A senior partner deleted Purdue-related documents once litigation loomed. A US$650 million deferred prosecution agreement with the DOJ in December 2024, on top of nearly US$1 billion in earlier state settlements. Former partner Martin Elling agreed to plead guilty to obstruction of justice. McKinsey is barred from controlled-substance sales and marketing work.
EY US, ethics exam cheating (2012 to 2021) Hundreds of audit professionals shared answer keys on the ethics component of CPA licensing exams and continuing education tests, and the firm withheld evidence of the cheating from the SEC during the investigation itself. A US$100 million SEC penalty in June 2022, the largest ever imposed on an audit firm, with admissions and remedial undertakings.

Two patterns stand out. First, the firms almost always survive intact while individuals absorb the criminal exposure, and the corporate penalties, US$50 million here, US$100 million there, are rounding errors against global revenues in the tens of billions. Second, the PwC Australia case is the purest analog to Karp’s worry, because it was not a lone trader enriching himself. It was the institution converting privileged access into a product line, deliberately and at partnership scale, and the formal penalty that started the unraveling was a two-year practicing ban for one man. These were just examples where individuals or firms were caught. Much like customs officials checking for contraband, it is well known that only a small percentage are ever caught, which hints that the true scale of the problem is much larger.

Karp’s charge, and what it gets right and wrong

Karp’s argument, stripped of the cable television theatrics, has two parts. The economic part is that token-based pricing amounts to a wealth transfer from enterprises to the labs, and that customers have been, in his words, chillaxing their way through budgets without measuring return. The more serious part concerns information: enterprises want to “own the means of production,” he said, rather than transferring their alpha to OpenAI or Anthropic. David Sacks and Chamath Palihapitiya endorsed the warning on the All-In podcast, citing cases in which labs launched vertical products that surprised their own partners. The Apple lawsuit alleging that OpenAI misappropriated trade secrets through former employees landed the same month, and it seems to underscore Karp’s point.

The counter-case deserves equal weight. Fortune’s reporting on the rant noted that there is no evidence the labs literally absorb enterprise customer data into their models; both OpenAI and Anthropic maintain policies that enterprise prompts and outputs are not used for training absent explicit opt-in, and their research on usage draws on anonymized consumer traffic. Michael Burry, among others, read Karp’s intervention as straightforward book-talking from a company whose application layer competes with the labs’ new ventures, at a moment when Palantir’s stock had fallen substantially. Both readings can be true at once. A conflicted messenger can still identify a real structural problem, and the Big Four history suggests that formal policies and confidentiality undertakings are exactly the kind of safeguard that erodes under commercial pressure, usually without anyone experiencing themselves as having crossed a line [1, 3].

The forward-deployed turn

What gives the warning its bite is timing. Inside a single quarter, both major labs stood up services firms modeled explicitly on Palantir’s forward-deployed engineer playbook. OpenAI moved first, launching the OpenAI Deployment Company on 11 May 2026, backed by over US$4 billion from nineteen investors, including TPG, SoftBank, Capgemini, and McKinsey itself, and initially staffed through the acquisition of Tomoro and its roughly 150 engineers. Anthropic followed on 15 July with Ode, a US$1.5 billion enterprise services company launched alongside Blackstone, Hellman & Friedman, and Goldman Sachs, built on the acquired firm Fractional AI and aimed at embedding engineers inside businesses, with the investor consortium’s hundreds of portfolio companies as a ready client base. OpenAI had already been running eight-figure consulting engagements and had formalized partnerships with BCG, McKinsey, Accenture, and Capgemini months earlier. The stated pitch in both cases is closing the implementation gap. The structural effect is that the companies that see your workflows now also sell workflow redesign, against Accenture, against Deloitte, and ultimately against portions of their own customers’ operations.

The platform strategy literature has studied this movie before. Zhu and Liu’s analysis of Amazon found that the platform owner tended to enter precisely the product spaces of its most successful third-party sellers, appropriating value from complementors’ demonstrated wins, and that affected sellers subsequently pulled back from investing in the platform [6]. Eisenmann and colleagues describe envelopment as a general entry strategy in which a platform absorbs an adjacent market by exploiting shared user relationships [7]. Later work suggests the effects on complementors vary with timing and governance, and that only entry by the platform owner itself, not by other large firms, provokes defensive repositioning [8, 10]. Enterprises watching Ode and the OpenAI Deployment Company would be entitled to run the analogy: the most valuable deployments generate the clearest signal about which verticals are worth entering.

Where the analogy holds, and where it strains

Is Karp right that the labs have more access than the Big Four ever did? In one sense, plainly yes. An auditor reviews periodic financial statements and process samples; a deeply integrated model provider can, in principle, observe live decision logic, prompt by prompt, across the whole firm. In another sense, the comparison flatters the accountants. Audit access is compelled by statute and wrapped in professional licensing, inspection regimes, and bodies like the PCAOB and Australia’s TPB, feeble as their penalties proved. Access to AI labs is contractual and voluntary, governed by terms of service and self-declared training policies, with no inspector, no licensing body, and no equivalent to deregistration. If the moral seduction literature is even roughly correct, relying on the good intentions of well-incentivized counterparties has a poor base rate [1, 2, 3].

Enterprise exposure today runs less through data ingestion, where the contractual protections are real if unaudited, and more through the services channel: forward-deployed engineers accumulate exactly the tacit, experience-linked knowledge of a client’s operations that walks out the door with the engagement team, and no training policy addresses that. That was always the consultants’ true asset, too. The PwC scandal was not a database breach; it was people, meetings, and a marketing plan.

The Big Four record suggests three things worth expecting. Penalties will lag the conduct by years and will underprice the information. Individuals will carry the criminal risk while institutions settle. And governance will arrive only after the first scandal, in a cycle the literature has already named [1]. Enterprises negotiating with the new AI services firms might reasonably ask for what auditors were eventually forced to accept: structural separation between the services arm and the model business, contractual audit rights over data handling, conflict registers for deployed engineers, and cooling-off periods when engagement teams move between competing clients. Financial regulators, who already subject their supervised institutions to outsourcing and material service provider regimes, are unlikely to leave embedded AI engineering outside the supervisory perimeter indefinitely. Whether anyone insists on any of this before the sector produces its own Peter Collins moment is an open question, and nothing in the record above encourages optimism.


Sources and further reading

Academic literature

  1. Moore, D. A., Tetlock, P. E., Tanlu, L., & Bazerman, M. H. (2006). Conflicts of interest and the case of auditor independence: Moral seduction and strategic issue cycling. Academy of Management Review, 31(1).
  2. Guiral, A., Rodgers, W., Ruiz, E., & Gonzalo, J. A. (2010). Ethical dilemmas in auditing: Dishonesty or unintentional bias? Journal of Business Ethics.
  3. Sah, S. (2017). Policy solutions to conflicts of interest: The value of professional norms. Behavioural Public Policy.
  4. Guiral, A., et al. (2015). Can expertise mitigate auditors’ unintentional biases? Journal of International Accounting, Auditing and Taxation.
  5. Kvalnes, Ø. (2019). Conflict of interest (on the knowledge gap in professional-client relations).
  6. Zhu, F., & Liu, Q. (2018). Competing with complementors: An empirical look at Amazon.com. Strategic Management Journal.
  7. Eisenmann, T., Parker, G., & Van Alstyne, M. (2011). Platform envelopment. Strategic Management Journal.
  8. Shi, R., et al. (2023). Comparing platform owners’ early and late entry into complementary markets. MIS Quarterly.
  9. Harber, M., et al. (2023). Audit firm executives under pressure: A discursive analysis of legitimisation and resistance to reform. Critical Perspectives on Accounting.
  10. Kapacinskaite, A., et al. (2024). Competing with the platform: Complementor positioning and cross-platform response to entry. Strategic Management Journal.

News, regulatory, and primary sources

  • Tax Practitioners Board, Former PwC partner banned for integrity breach (2023); Accountants Daily on the ASIC eight-year ban; Queensland Law Society Proctor, Lessons from the PwC tax leak scandal; Thomson Reuters on the PCAOB fines; The Conversation on potential criminal liability.
  • SEC, KPMG paying $50 million penalty for illicit use of PCAOB data (2019); DOJ SDNY on the Middendorf and Wada convictions; Bloomberg Tax on the case’s collapse and aftermath.
  • SEC, charges against Scott London (2013); DOJ CDCA charging release.
  • SEC litigation release, Flanagan sentenced to 21 months (2012).
  • DOJ SDNY, Anil Kumar sentencing (2012).
  • DOJ, resolution of McKinsey Purdue investigations (2024); NPR coverage.
  • SEC, Ernst & Young to pay $100 million penalty (2022).
  • CNBC, Palantir’s Karp bashes OpenAI, Anthropic token model (1 July 2026); Fortune, Karp is paranoid about Anthropic and OpenAI; The Globe and Mail, Palantir’s CEO just called out OpenAI and Anthropic; TheStreet on the Apple lawsuit context.
  • OpenAI, launch of the OpenAI Deployment Company (11 May 2026); CIO Dive analysis; AI Business on both labs’ consulting moves.
  • Business Wire, Anthropic, Blackstone, and Hellman & Friedman Introduce Ode with Anthropic (15 July 2026); TechCrunch and CNBC on the US$1.5 billion venture; Fortune on the consulting industry implications.
Share this article