What OpenAI Can No Longer Guarantee About Your Drafts: Lessons From the Navier-Stokes Affair

On the evening of Tuesday, September 8, OpenAI published a few lines on X in response to a mathematician who had asked whether its model had learned from his drafts. The sentence that matters, rendered as closely as I can: while unlikely, we cannot rule out that de-identified data derived from their usage of our products helped improve our models.

The background takes three lines; the details are in the box further down. Tristan Buckmaster (NYU) and Levent Alpöge (Anthropic, working in a personal capacity) spent a year on a family of fluid dynamics problems, feeding every draft they wrote into Codex, OpenAI’s coding assistant. On September 8, OpenAI announced that an internal model had solved the Navier-Stokes Millennium Prize Problem by way of an approach the two researchers describe as theirs and as nearly deserted, a characterization OpenAI partly disputes. Buckmaster asked whether the model had been trained on their sessions. The answer is above. Let’s be precise about what it establishes: we do not know whether those drafts contributed anything at all; we do know the vendor declines to say no.

I am not a mathematician, and I will not be passing judgment on the proof. What I can read is a company statement and a set of terms of service, and that is what this piece is about, because the question Buckmaster asked is the one every developer should be asking of their coding assistant.

Three claims, only two of them signed

OpenAI’s response has to be read in two stages. On Tuesday morning, in a press briefing, chief research officer Mark Chen stated that no one, human or system, had searched through user data to solve this problem, and said he was disappointed by the suggestion of a massive breach of user trust. Sébastien Bubeck, who led the project, added that neither his researchers nor his agents had seen the pair’s work before it was published. On Tuesday evening, the official statement repeated both points, then added the « we cannot rule out. »

These are three distinct claims. « We did not look at your data. » « Our agents did not use your prompts. » « The model did not learn from your data. » OpenAI signs the first two and explicitly declines to sign the third. And the third is precisely what Buckmaster had asked on the phone the previous Sunday, and to which, he writes, he received no answer. He has one now, and it is: maybe.

The reassurance offered, that OpenAI’s team had no research-level expertise in fluid dynamics and therefore could not have steered the mathematical content, is plausible and beside the point. The suspicion is not about the humans. It is about what the model already had inside it when they set it loose.

What the terms actually say

The caution in that statement makes sense once you read OpenAI’s own documentation, which VentureBeat did the same day.

For Business, Enterprise, Edu, and API accounts, inputs and outputs are excluded from training by default, and the documentation specifies that the exclusion holds when the workspace uses Codex. For individual accounts, Free, Plus, and Pro, it is the reverse: content may be used to improve the models unless you turn that off by hand in the settings, with a separate control for Codex full-environment data. No one has said publicly which regime governed Buckmaster and Alpöge’s sessions. In other words, « private session » means nothing on its own: it all depends on the product, the account type, and whether a box was checked.

And that is not the whole picture. Not training on something is not the same as not keeping it. Ordinary API requests generate abuse-monitoring logs containing prompts and responses, retained for up to thirty days; some features hold persistent state because they cannot function otherwise. Zero data retention does exist, extended to frontier models on August 19, 2026, but it is limited to approved API customers, and features such as the code interpreter are not compatible with it.

So there are three separate controls: training, which decides whether your data improves the model; access, which decides who at the vendor may read what is stored; and retention, which decides how long it stays stored. A blanket promise of « privacy » collapses all three into one word, and the September 8 statement shows what that word is worth: the company guarantees access, guarantees direct use, and on training answers in the conditional.

Why this is your problem

You are probably not working on Navier-Stokes. But if you use a coding assistant, you hand it every day what those two researchers handed it: the exact state of what you know how to do and your competitors do not. A year of drafts is a year of expertise, and that expertise passes through the servers of a company whose next product is, by construction, a competitor to everyone.

Axios boils the trust question down to a single line: can researchers safely use frontier labs’ tools on an unpublished discovery? Until this week, the implicit answer was yes. Satya Nadella and Alex Karp were already accusing the labs this summer of learning from their customers’ data in order to build competing products, and back in November I wrote that LLMs are full of holes and that a paid subscription does not buy the confidentiality people think it does. The Buckmaster affair is the high-end version: two leading researchers, a million-dollar problem, and a vendor whose answer is « unlikely, but we cannot rule it out. »

The technical answer

It exists, and I laid it out in Sovereign AI: why local open source became the only independent choice: with an open-weights model running on a machine you control, the three controls collapse into one, and you are the one holding it. The trade-off is not all or nothing, it is a matter of sorting. Buckmaster and Alpöge would almost certainly not have gotten their results in a year on a local model, and it would be absurd to give up frontier-grade power for code that will be public in six months. The question is which part of your work genuinely sets you apart and has not been published yet; that part runs locally, and the rest can go to the cloud. Before September 8, that sorting was the precaution of a crank. It is now the plain reading of a company statement.

The affair in ten lines

  • A year ago. Buckmaster and Alpöge take up a method developed by Diego Córdoba and Luis Martínez-Zoroa, working with Claude and Codex.
  • August 15, 2026. They obtain finite-time blowup for the Euler equations and the Boussinesq system. Formal verification in Lean completed on August 22. Terence Tao calls the work remarkable; Charles Fefferman, who wrote the official problem statement, names Córdoba and Martínez-Zoroa the heroes of the story.
  • September 1. A rumor credits Anthropic with resolving two Millennium Prize Problems. That same day, OpenAI turns its agents loose on the remaining problems, using an internal model whose training began on August 28.
  • September 3. Buckmaster writes to OpenAI to say the project is a personal collaboration.
  • September 5. Ten thousand agents produce a resolution of forced Navier-Stokes, after 88 hours and 130 billion tokens.
  • September 6. Two calls with Bubeck. By Buckmaster’s account, he is offered a choice: publish the day before OpenAI does, with his priority acknowledged, or write up OpenAI’s proof himself without Alpöge, deemed a complication because he works at Anthropic; then, « why would you ruin your career? » Bubeck disputes that he ever sought to remove Alpöge from Alpöge’s own work, says the discussion concerned a rewrite of OpenAI’s proof, admits to the line about the career, and says he retracted it on the spot.
  • September 7, 11:58 p.m. Buckmaster publishes his statement and three papers.
  • September 8. OpenAI announces its resolution, says it does not intend to claim the Clay million, and that evening publishes the statement quoted at the top. Nothing has been validated by Clay or reviewed by peers. Córdoba, whose method started all of this, comments: if it’s done, that will be a big surprise for us.

My take

Three closing remarks.

The first belongs to Tao, who compared the labs’ rush at open problems, before the announcement was even made, to strip mining that destroys the ecosystem out of which the next generation’s techniques and mathematicians would have come. A Millennium Prize Problem attacked in 88 hours to answer a rumor, by a team that admits to having no expertise in fluid dynamics: the pit was dug, the seam was stripped, and the two geologists were left standing at the edge.

The second is that Bubeck, in his own account, may say more than he means to. His texts to Alpöge show a man trying to do the right thing and promising credit to both researchers. But the line about the career, which he admits, and the notion that an Anthropic employee cannot co-author OpenAI’s work, which he stands by, say the same thing: here, affiliation came before priority. A mathematician at NYU may write up OpenAI’s proof; his collaborator of a year may not, because he carries the wrong badge. Two disputed phone calls do not make an industry doctrine, but that is how it played out, and no one at OpenAI has said it should have played out any other way.

The third is the simplest. The Clay prize is worth a million dollars, and OpenAI says it will not claim it; what is worth more than a million are the drafts of everyone who will open Codex tonight without having read the statement of September 8. What will be remembered is that a lab was asked whether its model had learned from its users’ drafts, and answered that it could not rule it out. In my September 10 column I wrote that everyone is speaking in the future tense and no one is rereading the past. Here there was a past to reread. It sat on OpenAI’s servers, and OpenAI will not say whether it read it.


Écrivez quelques éclats d'âme...

Dans l'ombre vacillante d'une chandelle, où les murmures du vent se mêlent aux secrets d'un vieux parchemin, je vous invite à tisser une toile de mots. Écrivez quelques éclats d'âme – rêve, étoile, abîme, étreinte, brume – et laissez-les danser sur la page, comme des lucioles dans une nuit d'encre. Que diriez-vous de les entrelacer dans une phrase, un souffle, une histoire ?

S’abonner
Notification pour
guest
0 Commentaires
Le plus ancien
Le plus récent Le plus populaire