28 September 2026

Does your AI provider train on your prompts?

Many providers say they do not. Some put it in the contract. No hosted provider gives you a way to check.

On 11 September 2026 David Friedberg described what happened to his company's research on the All-In podcast.

"I have had experiences where we've asked some fairly novel scientific questions, and (the AI model) identifies it as a novel insight. It's like, 'Oh, never thought about that, interesting.' And then using a different account, asking the next version (of the model) later, I've now experienced this. It's like, 'Oh, well, you could do this,' and it actually just describes this exact thing that we had in our chat in the previous version."

Friedberg runs a gene editing company. The questions were his. The model called them novel. A later version of that model handed the same idea to a different account.

There is no way to check

Friedberg is careful about what he claims. "Now, these are a handful of anecdotal experiences." His reasoning is the only kind a customer gets:

"I know the domain that we work in, and the niche of it, and the ideation of this stuff, and the novelty of this stuff, and the lack of papers being published, and so on. So I know that there isn't some new corpus of information out there that's training the new model."

That is an argument from the absence of any other source. He has no log. No audit right. No contract term to point at:

"We don't have any NDA or confidentiality provisions or protections with them being a service provider back to us."

OpenAI denies the related accusation from the same week. Both can be true. The company denies it and the customer has no way to check. Friedberg could not settle the question. He runs the company whose work it was.

Now change the payload

Friedberg lost an idea. Put your own organization's traffic in its place.

  • A patient history
  • An acquisition nobody has announced
  • A client file under privilege
  • A case number
  • An incident nobody outside the room knows about yet

Nothing about the arrangement changes when the payload changes. Same provider. Same terms. Same inability to check. If a research question can surface somewhere else so can a diagnosis.

What changes is the cost when it happens. Friedberg lost priority on an idea. A hospital loses a patient's privacy and answers for it under HIPAA. A firm loses privilege. Privilege does not come back.

The legal floor is lower than people assume

David Sacks makes a second point in the same segment. AI chat data carries weaker legal protection than email. A warrant and probable cause guard your email. A subpoena or a court order reaches your AI chat logs. Attorney-client privilege covers a question you put to a lawyer. It does not cover the same question put to an AI first.

Your prompt leaves the room two ways. Training takes it. A subpoena takes it. Neither one requires anybody to do anything wrong.

What Texas Inference does instead

Two things can stand between a prompt and the company holding it. A policy. Or a machine that cannot read it.

A policy is a promise plus an audit nobody will let you run. It lasts until the terms change. Or until somebody buys the company. Or until a court asks.

An encrypted lane is arithmetic. The GPU decrypts your prompt inside itself and nowhere else. The operator cannot read it. Neither can the administrator. Neither can the tenant next door. Neither can anyone arriving later with a subpoena. There is no policy to trust because there is no plaintext to hand over.

You do not have to believe us. Ask the hardware. Intel signs the processor. NVIDIA signs the GPU. The attestation reports which machine ran your work. It does not report where that machine sits. No attestation does. Our Texas commitment is a contract term and it lives in the Data Processing Addendum.

Friedberg's own answer was open source:

"This is why I care a lot about open source because I don't want them having my chat logs because they can use it for training to create an IP advantage that is now diffused to the rest of the market."

He is right about the problem. Running the weights yourself is one answer to it. Running them on compute the operator cannot read is the other. That one does not require you to build a data center.

Source

All-In released "AI Kills Everybody or Doomer Psyop? OpenAI's Math Breakthrough, Nike's $200B Collapse" on 11 September 2026. Friedberg at 1:12:05. Sacks on data privacy law at 1:10:41.