Or is there something fundamental in the way these models get deployed (encryption or something or than legal contracts?) at this scale that prohibits the owners of the infra from gaining this level of insight / access?
Or is there something fundamental in the way these models get deployed (encryption or something or than legal contracts?) at this scale that prohibits the owners of the infra from gaining this level of insight / access?
The contract can stipulate a penalty at a high enough amount to discourage this behavior.
2) Output from models & intra-datacenter communications can be encrypted if customers truly cared.
3) There is no reason do this, because there are far better ways to exfiltrate data from Anthropic models. Chinese companies are already doing this at an industrial scale where they are reselling Claude tokens for 10-20% of the cost while retaining the data to train their own models. https://www.chinatalk.media/p/how-to-buy-cheap-claude-tokens...
If we look at Deepseek V4-pro, created by Deepseek who Anthropic formally accused of harvesting Claude tokens at scale, it performs the same as Claude did 6 months prior.
1. OpenRouter is based in New York, and offers a 1% discount when users enable logging of their inputs/outputs; it doesn't take a genius to figure out why they might incentivize that
Thanks for the chuckle. ;)
I guess as a European I want the legal system to be robust in terms of protecting the citizen’s interests against corporations. I can see how you can also want robustness in terms of protecting corporate interests against citizens, so, yes, the statement remains technically true in terms of robustness.
In terms of justice, again as a European, I think of Justitia, the Roman Godess, who judges based on “ideals of truth, fairness, honesty and justice“, “applied without regard to wealth, power, or other status”, evaluating “the goodness of the heart”. I don’t see these values represented much in the US so-called “justice” system.
Both aspects sufficiently documented for example over and over again in Matt Levine’s financial reporting.
Cambridge Dictionary: “the quality of being strong, and healthy or unlikely to break or fail”
I provided two dimensions in which I consider the US justice system to have failed. I can provide more. You of course can prioritize different dimensions, but that doesn’t invalidate that I am also talking about robustness. Robustness is not an absolute, but always an adjective - related to a specific aspect.
None of this means you don’t have the same rights as an individual to enforce contract terms. I think the top commenters discussed corporate law because that is where most IP theft occurs, and corporate customers have strong contracts covering data protection.
To give yet another personal reason for my chuckle besides the ones I already gave: I don’t consider a legal system where I can simply move state when I don’t like the law not very robust. Or one that can “look back to (a mere) 200 years of case law” - especially given how that is being (re)interpreted in recent years.
That is my personal opinion. You’re entitled to your opinion, your definitions, your perspectives. I remain chuckling :) we don’t have to always agree or dig holes of rational debate, we can just find stuff funny or not. I volunteered why it is funny to me when that causes irritation with some. I read the high number of upvotes as potential agreement.
I think you missed the part where Anthropic stopped displaying their thinking tokens over the past few months, and instead now provides “summarized thinking”, letting Haiku summarize Opus’ thoughts.
So it is now much more difficult (impossible?) to distill the models.
I also think you over-estimate how well the legal systems works in the US nowadays, and under-estimate just how much power Elon has in the government.
In Feb Anthropic called out three Chinese labs for "distillation attacks", but a lab missing in their post actually had most Claude generated tokens among all Chinese labs in their midtrain data :p
Deepseek kept its pace of improvement nonetheless.
It's generally far easier to install spying software under a computer under your control than to detect it.
If Elon REALLY wanted to do anything like that he would be better off poaching talent from competitors, less legal hell to go through.
I hear that it is very much up there in _one_ domain. You know the one.
How do you trust space infra? You can't show up and audit some kind of airgap. Whatever encryption keys you have are likely accessible in memory sometime.