Of course that’s a risk, but is it a different risk than GitHub stealing code from your private repos? In other words, do you just trust the AI companies less or do they not offer “we don’t steal your code” contracts?
Has your company tried running the models locally, or is that maybe just presumed to be not worth the effort?
Same currently. This is actually a risk in itself though. /Some/ of your devs are going to circumvent policy and use an AI assistant. It is better at this point to have a tool available where you have a business level agreement vs. burying your head in the sand and believing that everyone is going to follow the org policy of 'no AI'.
Has your company tried running the models locally, or is that maybe just presumed to be not worth the effort?