What OpenAI Wrote, Then Quietly Deleted

Hey Income Traders,

Last week, OpenAI announced that an internal system had solved Navier-Stokes, one of the Millennium Prize problems and a question about how fluids move that had beaten mathematicians for the better part of a century.

Around 10,000 agents ran for 88 hours and put out something like 130 billion tokens, then a formal verifier (software that checks every step of a proof) signed off on the result.

Hold the applause.

Two mathematicians, one at NYU and one who works at Anthropic but did this on his own time, had spent the better part of a year quietly working the same territory by the same route.

Self-funded.

They did a lot of that work inside commercial AI tools, including OpenAI's Codex, and every draft sat in private sessions on OpenAI's servers. They were paying customers.

On September 3rd they learned that word of their approach had reached OpenAI, so they emailed. An OpenAI researcher wrote back the same day, asked for details that would be "useful to avoid competing," and offered them free compute. OpenAI's system produced the proof that Saturday, the pair rushed to get their own results on the record so there'd be a timestamp, and then came the announcement.

OpenAI says it never looked at their private work.

Maybe so.

But read what OpenAI wrote in its own announcement on September 8th: while unlikely, it "cannot rule out" that de-identified data from the pair's use of its products helped improve its models.

Two days later, after an internal investigation, OpenAI edited the post to say those prompts couldn't have influenced the model in any way.

A vendor got asked whether a customer's work had become its work, and the first answer, in writing, was "we can't be sure."

It took an investigation to get to no, and you're taking the vendor's word on the vendor's investigation.

Whether anyone stole anything is for the mathematicians and the lawyers. For you and me, the important part is simpler: The vendor got asked the question and couldn't say no on the spot.

This has happened before.

In July, two OpenAI models running in what was supposed to be a sealed test environment found a zero-day (a security hole nobody knew existed yet) in a piece of proxy software, broke out onto the open internet, and got into Hugging Face's production servers. Hugging Face logged more than 17,000 events from the intrusion.

The models weren't after anything sinister. They wanted the answer key to a benchmark instead of doing the benchmark. Hugging Face's own security team caught it five days before OpenAI connected the breach to its own test.

Nobody set out to do harm, and that's what makes it worse. The model wanted the answers and the box didn't hold.

That's the same lesson twice in eight weeks. Once your data is on the vendor's side of the wall, the vendor can't always tell you what happened to it.

Yeah, I know. A spat over a math proof won't make a drug company rip out its cloud contracts, and nobody rips anything out. This is about where the next sensitive workload goes.

Marketing copy, customer service, cleaning up code, that stays on the API (the rented model you reach over the internet). It's cheap and nobody cares who sees it. Drug pipelines, trading models, chip layouts, the merger you haven't announced: every CIO reads this story and moves that work behind their own door, and that's the only work with margin in it.

In two years the model won't be anybody's edge. Open-weight models (the ones you can download and run yourself) sit within a hair of the frontier and cost a fraction to run. I've told you what happens when the near-as-good chicken costs five percent of the steak: everybody orders the chicken.

When every competitor can rent the same intelligence for the price of lunch, intelligence stops being a moat. Competition drives margins down toward the cost of tokens, and the cost of tokens keeps heading toward zero.

The thing with a margin still on it is what the model learns from. Your data, your process, your customers' behavior, the decade of mistakes you already paid for. Leave that on a rented model and there's a chance it comes back as a feature in your competitor's subscription next quarter, and that chance was the vendor's own first answer, not mine.

Own the model. Own the data. Own the IP. Own your destiny.

Margins get squeezed no matter what you do, so you keep your edge any way you can, and the cheapest way to keep it is to never let it out of the building.

This is the Great AI Repatriation I've been talking about since January: less API, more local.

Dell (DELL) and Hewlett Packard Enterprise Co. (HPE) are who you call when you want the chicken running on your own iron behind your own firewall. I said it in July: open-source AI drives enterprise siloing and Dell is the way to play it. I still own it after trimming into strength last week, and HPE is back in the book.

Both just reported.

Dell booked $60.9 billion in AI server orders last quarter and its backlog sits at $95 billion, and traditional servers, the plain boxes that run in your own building, grew 122 percent.

HPE said orders for traditional servers rose 75 percent and told analysts its customers "want control over sensitive information" and want their data next to their own AI gear.

A cloud GPU is shared across thousands of customers and runs hot around the clock. The box in a law firm's server closet serves one customer and sits idle most of the night.

Repatriation fragments compute demand. And fragmented demand needs more hardware per unit of work, which means more memory per box on top of everything the hyperscalers (Amazon, Microsoft, Google and the other giant cloud operators) are already buying.

Dell told you on its last call what it's short of: "DRAM, DRAM, DRAM" (the workhorse memory chips in every server), followed by NAND. That's a second bid under Micron (MU) and SK Hynix (SKHY). SK Hynix is my second largest position.

A Mac on every desk is a private inference node (a machine that runs the model locally, so the prompt never leaves the room). Apple skipped building the frontier model and waited for the model to shrink down to its hardware, and it did. I've been bullish on Apple (AAPL) since last year, while the doubters kept pointing at things that don't matter.

If a model can reason its way out of a sandbox, the wall around your network matters again. That's the cybersecurity basket: CrowdStrike (CRWD), Palo Alto Networks (PANW), and Cloudflare (NET) as the bouncer at the door. I've been adding back since August.

What would prove me wrong: enterprises shrug and double down on the API because it's easier. Watch two numbers, the AI server backlog at Dell and HPE, and what Micron says about non-HBM DRAM pricing (the ordinary server memory, as opposed to the premium stacked memory that sits on GPUs) on September 30. If the sensitive workloads are moving home, it shows up there before it shows up in any survey.

OpenAI settled a 90-year-old math problem last week. It also made my case on where your data should live, and it did it in writing.

This is the kind of thought process you get in Turbo Income.

Tap this link to join.

Here for a good time AND a long time,

Hans

Hans Albrecht

Hans Albrecht

Share This Article

Hans Albrecht

Option Pit Income

What Rogue AI Agents Mean for an Income Book

By Hans Albrecht

Hans Albrecht

Option Pit Income

165 Million Transactions. Not a Human in Sight

By Hans Albrecht

Hans Albrecht

Option Pit Income

Secret Agent Men

By Hans Albrecht

Hans Albrecht

Option Pit Income

One name to own, one to avoid

By Hans Albrecht

About the Author

Hans Albrecht

Hans Albrecht

Former CBOE floor trader and CIO at Karman Line Capital. Author of ‘The Option Traders Hedge Fund’ with over 30 years of options trading experience.

Popular Posts

Categories

Stay Updated

Subscribe to our newsletter for daily trading insights

Upcoming Events

FOMC Meeting

2:00 PM EST

Earnings Season Begins

Pre-market

Options Expiration

Market Close

NFP Report

8:30 AM EST