ATAILA Newsroom · Budapest · 2026-08-23
If it does not run on your hardware, someone else will one day decide what happens to your data
The Hungarian tech site hwsw.hu reports that Google paid ten million dollars for the data of a bankrupt airline. The news itself is short; its consequence is not: a company’s entire internal life — databases, e-mail, chat logs — changed hands as an asset and became AI training data. This is not an AI scandal. It is bankruptcy law working as designed, applied to the one asset most companies believe will never reach the market.
The article we are responding to
„Tízmillió dollárt fizetett egy becsődölt légitársaság adataiért a Google”
hwsw.hu · 2026-08-18
What hwsw.hu reports
According to the article, the databases of Spirit Airlines — which filed for bankruptcy in May — were put up for auction in the liquidation, complete with the company’s entire internal e-mail and its Teams history, and Google submitted the highest bid for the package.
The article itself introduces this as an unusual line item: in an airline bankruptcy the fleet is normally the biggest asset — the database is not the row you go looking for on a creditors’ auction list.
There is nothing to dispute in this diagnosis
We do not think anyone acted improperly here. That is exactly what makes it unsettling. A bankruptcy proceeding exists to find value in what remains; and a well-maintained data estate — now demonstrably — carries value in the AI market. No bad faith, no conspiracy, no data breach is needed for your internal e-mail to end up in someone else’s training set. An everyday corporate life-cycle event is enough: bankruptcy, acquisition, a change of owner, a change of strategy.
The industry’s standard answer is the contract: a DPA, a data-processing annex, deletion obligations, a subprocessor list. These matter, and we sign them too — but it is worth seeing precisely what they protect. A contract binds a living company. An estate in liquidation is no longer that company: the decision-maker is different, the interest is different, and the creditors’ interest outranks your data-handling preferences. There is one thing no bankruptcy can rewrite: where the bytes physically sit, and who can reach the iron they run on.
Which is why we think the right lesson is not “pick a more trustworthy provider”, but this:
What is confidential must run on infrastructure whose fate you decide. Private AI for the work you cannot put in the cloud. Your AI. Your data. Your hardware.
What ATAILA does with this
The article carries four lessons, and our answer to each is an engineering one, not a marketing one.
The article's finding
Your data is a line on your provider's balance sheet, and the fate of that balance sheet is not your decision.
Our answer
ATAILA Cloud is private, end-to-end EU-resident compute — Proxmox, MinIO, Vault, Harbor, Traefik, our own network — with monitoring and backups from day one and a written 99.9% availability commitment. Not a boxed hosting bundle: a sovereign environment built for production load, kept with the same care as our own systems. Your documents, your embeddings and your logs live in one place, not scattered across a public AI provider and three SaaS tools.
ATAILA Cloud →The article's finding
The most valuable training data is not the customer database but the internal e-mail and chat — the way a company actually thinks and decides.
Our answer
A prompt is data processing too. When you paste the contract, the patient file or the margin calculation into a question, that is a data transfer, not a conversation. With us, no model learns from your data, access and every egress path are auditable, and there is no American data processor on the route — because of the 2018 CLOUD Act, that is not fine print but a practical matter. At most companies the question is no longer whether they use AI, but where it runs.
GDPR-compliant AI in practice →The article's finding
If you do not run on your own iron, you also carry your provider's life-cycle risk.
Our answer
We have two editions. The fully managed, multi-tenant Cloud for those whose goal is EU residency and having operations taken off their hands. The licensed, single-tenant Enterprise for those whose hardware must also sit in their own jurisdiction, in their own ownership — the same platform, on your iron. Both come at a fixed monthly fee: the invoice does not depend on the month's traffic.
Cloud and Enterprise editions →The article's finding
The real question is not what happens while everything goes well, but what stays with you if the vendor disappears.
Our answer
No lock-in — and we phrase that not as a promise but as a package: the source code lives in your own GitLab from the start, on request you get a PostgreSQL dump, your files as a tarball, documentation of how the application builds and runs, and a migration guide so you can bring it up elsewhere without us. The components are recognisable, runnable open tools — no closed runtime, no closed format. The platform is a convenience, not a cage. In an Enterprise contract this can also be fixed as an exit clause and a source-code escrow provision.
Ownership and exit →This is not theory: our named references are our own products running in production on this same stack, built with private AI — the newest of them went live in hours by reusing existing modules.
What this does not solve
We do not claim that owning the hardware protects you by itself. A badly operated on-prem system is not safer, only less visible: an unpatched kernel, a database with no backups and admin rights handed to everyone add up to data loss all the same. Hardware only amounts to sovereignty when there are operations behind it — which is why we sell the two together, and why we do not sell bare GPU rental.
Nor do we claim that every consequence of a bankruptcy can be contracted away. If one day it is your company, your data becomes an asset too. What you can influence is how many other companies’ balance sheets it sits on until then — and whether, when the day comes, you can even say where all the copies are. Most organisations today cannot answer that question, and that inability to answer is the real risk, not Google.
And we are not legal counsel. We will not claim the final word on where liquidation law and the GDPR collide — the part we take on is the engineering question: where the AI runs, where the data sits, and who can reach it.
If this is your situation
If you have a workflow you would never paste into a public AI — contracts, patient data, client files, payroll — it is worth a confidential conversation. We do not want to show a demo: we want to understand where that data lives today and what would happen to it if someone else got to decide. We will give you the answer even when the answer is that you do not need us.
Source: Tízmillió dollárt fizetett egy becsődölt légitársaság adataiért a Google — hwsw.hu, 2026-08-18
← Back to the Newsroom Press inquiries: contact us