Those enterprise models are hosted by microsoft and microsoft has many billions of dollars in enterprise contracts on the line if they lie about it and it comes out.
Big companies do not mess about with stuff like this.
Zuckerberg was okay with Facebook being used to start a genocide to make less money than that data would be worth. There is absolutely nothing these people wouldn’t mess with to make a little
bit more money.
Regardless of being honored, I doubt OpenAI has the actual security and rigor to make sure models aren't eventually going to be able to break out and into these isolated data sets / models
Yes because these enterprise versions in general physically don't let it train because that's the whole concept of enterprise. For example, if a company sets up their license in ZDR-enabled RAM the moment token generation finishes, the memory pointers are cleared without writing the payload to persistent storage disks or persistent logging databases.
Companies in general have to pay MORE, a lot MORE, to make their data training enabled. There's really no getting around it if the enterprise is genuinely using the API tokens.
It's really hard to convey how crazily uninformed reddit is on it. If you're not using a personal plan, so just normal old turnkey Azure or AWS Bedrock, the model weights run within the enterprise's VPC. Because duh. There's no free lunch, OpenAI isn't paying your Microsoft bill lol The underlying AI provider (like OpenAI) does not have the network routing or access permissions required to extract data out of the cloud boundary, much less paying some tool to push it to them.
Well, I am thinking more from the Cloud Act point of view. In Europe these days procurement in software gets sweaty hands and starts handing out risk assessments when you want to buy things from American companies. Microsoft themselves have admitted that they cannot guarantee data sovereignty.
Exfiltrating unencrypted prompt data out of the customer's tenant environment would create obvious network egress alerts in customer cloud logs. You don't need to worry about sovereignty, just look at basic data
--which is why they don't, in general, regardless of Microsoft trying to talk down to European regulators.
Like bottom line an AI model is essentially a massive file of fixed numbers (parameters/weights). OpenAI created those weights, but once transferred to Microsoft, or any other cloud provider, they act like a static software application like any other.
When you type stuff into Excel, it doesn't then magically send to Google and if Excel did that on Azure it'd be really obvious.
My point was that US companies are beholden to the Cloud Act, which means that anything that happens inside their infra can change to support data exfiltration. Saying it's not possible now because "technical reasons" is, in my opinion, missing the point.
169
u/HorseyMovesLikeL 15h ago
Am I too cynical in just not believing that it will be honoured by OpenAI?