8/24/2026 at 7:53:55 AM
Yes your Chinese open model could have a time-release backdoor, just as your Chinese vibrator could have a hidden microphone that records everything you say and transmits it to the CCP. But does it? No.What's much more likely is that your US AI provider is promising not to train on your data but is doing so anyway. With a self-hosted model you can at least avoid that.
by zarzavat
8/24/2026 at 8:19:01 AM
Always assume someone’s training on ya (maybe not to point of losing competitive advantage, but on a personal level).Airgap your models from Country A, review outputs with model from Country B?
by Barbing
8/24/2026 at 8:38:27 AM
They’re talking about open-weight models you host yourself. Which are fundamentally incapable of spying on you unless you give them network access. We also haven’t seen any evidence of open-weight models exfiltrating data over side channels (DNS/steganography/etc) yet, so at this time internet access still seems safe enough to grant without worrying about spying.by nerdsniper
8/24/2026 at 9:35:41 AM
I can imagine scenario. Let's say you tell open-weight model to generate kitten video. It uses piezoelectric effect of some ceramic capacitor on gpu as microphone and adds recorded audio to the generated video in non audible range. You post kitten video on social media where ai company collects it and extract what you were saying while the video was being generated.by dvh
8/24/2026 at 3:17:34 PM
I too believe in paranoid magic.by cyanydeez
8/24/2026 at 1:56:15 PM
Degraded/sabotaged responses also present some risk. Some scenarios mentioned here: https://news.ycombinator.com/item?id=49416695by Barbing
8/24/2026 at 9:56:30 AM
> your Chinese vibrator could have a hidden microphone that records everything you say and transmits it to the CCPCould they be that desperate? Wow.
by skeledrew
8/24/2026 at 11:58:57 AM
https://www.theguardian.com/technology/2017/mar/14/we-vibe-v...by kkfx
8/24/2026 at 12:36:16 PM
Although, for completeness, the company in that case is actually Canadian.(Always nice to see decade old effort still get referenced on occasion. :) )
Source: Username checks out. :D
by follower
8/24/2026 at 1:49:25 PM
And less than a decade later we have multiple devices that are effectively fitbits for your genitalia, for both sexes. How times change.by jimz
8/24/2026 at 8:41:49 AM
> What's much more likely is that your US AI provider is promising not to train on your data but is doing so anyway.There's genuinely no evidence of this for OpenAI and Anthropic. It's impossible to disprove, but I don't think it's likely because:
* They get enough volume from consumer subs with data training enabled anyway.
* If this was happening, it needs serious work at the scale OpenAI and Anthroppic, from data pipelines, to ablation experiments, to the actual data mix and traces going in all the telemetry/diagnosis of large-scale training runs.
* It would need to involve a team. Employees at these companies leave, there have been numerous whistleblowers, allegations, etc. Nothing on this front that I can find.
* It would damage enterprise trust permanently and be a company and reputation-ending thing. Now that these tools are used by everyone from state governments to the DoW, the exposure radius is massive, investors (many of whom are customers/users too; and often have their stakes in not just a single company but multiple) would not be happy. Piss off enough powerful people, and anyone can join Sam Bankman-Fried in prison.
* There's a myriad of enterprise customers and bespoke contracts. I can't get into details, but not all enterprises accept a 'trust me bro' clause.
by dannyw
8/24/2026 at 7:08:34 PM
Did they not use mountains of copyrighted material to train their models, and get away with it (fair use, greater good, blah blah)? What would suddenly prevent them from acting sneaky once again? Imagine sitting next to a river of gold and not being allowed to touch any of it. All that precious material, gone to waste.. Temptation! My guess is that they are keeping and/or are training on at least some kind of residual signal (metadata, vectors, ... ?), gray zone stuff that's not explicitly covered in their policies and can be explained away by an army of lawyers, if worse comes to worst. Machiavelli would nod approvingly.by whythismatters
8/24/2026 at 8:47:04 AM
> It's impossible to disprove, but I don't think it's likelyIf something is impossible to disprove, we must assume it is happening from a threat modeling perspective.
by jjav
8/24/2026 at 9:32:56 AM
> * It would need to involve a team. Employees at these companies leave, there have been numerous whistleblowers, allegations, etc. Nothing on this front that I can find.You have to also note the incentives going on here. Employees who have extremely valuable stock options, they have good reasons to not come public with anything that would damage the reputation of the company before they can cash out
by dgellow
8/24/2026 at 9:03:59 AM
I'm not saying that Anthropic and OpenAI are definitely dishonest, there is no proof of that. However, when you have1) an extremely high financial incentive to be dishonest (trillions of dollars),
2) low-ish chance of being caught, especially if you launder the data through another model to remove identifying information,
3) the people in charge of said operations are generally agreed to be snakes,
then it should at least arouse suspicion. You may be right that get enough data from opt-ins that they don't need to do it. I do believe that they don't violate enterprise ZDR agreements, but for normal subscriptions I'm much less confident.
by zarzavat
8/24/2026 at 8:23:10 AM
my first thought reading the article wasn't that Qwen, or some other chinese open model, would do this, but rather that one of the many "unlocked" models on huggingface mightby Icy-Undivided-G
8/24/2026 at 8:26:09 AM
But but but, they're called .safetensors, surely they're safe then and could impossibly lead to me being hacked?The ecosystem is due for a rude awakening any day now. I've been slowly prepping by isolating absolutely everything on my machine from each other, not sure how people dare to YOLO run these sort of things "natively" on their computer today.
by embedding-shape
8/24/2026 at 3:16:49 PM
Your US AI provider may be actively doing what AT&T started doing after 911, but you know, under the permission structure of fascism.by cyanydeez