I always assumed that the hardware-accelerated servers running inference are separate from the servers running evals (connected only via an API channel), and that the inference servers are much more well-secured than the eval servers (making exfiltration unlikely). After all, if their model weights were exfiltrated or stolen, they could be used or reverse-engineered by OpenAI’s competitors, which would have a major financial impact on OpenAI, possibly more than from one of their models committing a felony. But my assumption that the servers are separate is only a guess, and I agree that OpenAI, and all other AI labs, should be much more transparent than they currently are.
I always assumed that the hardware-accelerated servers running inference are separate from the servers running evals (connected only via an API channel), and that the inference servers are much more well-secured than the eval servers (making exfiltration unlikely). After all, if their model weights were exfiltrated or stolen, they could be used or reverse-engineered by OpenAI’s competitors, which would have a major financial impact on OpenAI, possibly more than from one of their models committing a felony. But my assumption that the servers are separate is only a guess, and I agree that OpenAI, and all other AI labs, should be much more transparent than they currently are.