A wooden horse-shaped USB drive plugged into a laptop on a mathematician's desk covered in chalk equations, warm morning light through a window, dossier folder open beside it
AI & Singularity

The Audit Files #1: The Trojan Horse — When Your Unpublished Work Ends Up in the Machine

OpenAI promised researcher data would not train its models. Two mathematicians who fed unpublished work into ChatGPT say the results look familiar, and OpenAI cannot rule it out. Case file one: the input problem.

OpenAIAstraresearch integrityintellectual propertyNew Zealand

📁 CASE FILE 01 — THE TROJAN HORSE Subjects: OpenAI · Andreas Thom (TU Dresden) · Tristan Buckmaster (NYU) Period: July – September 2026 Status of central claim: 🟡 UNPROVEN — OpenAI’s written position is that it cannot rule out the conduct alleged Companion file: Case File 02: The Relay

This is part one of a two-part dossier on the chat-input problem: what flows into the models, and what flows back out. Every major claim in these files carries a confidence tag — 🟢 verified, 🟡 unproven, 🔴 denied — because the honest version of this story is the only version worth running.

Last month OpenAI invited the world’s researchers to bring it their hardest problems — free access to frontier AI for 10,000 scientists, expanding to 100,000 through 2027. Six weeks later, two mathematicians are asking a question that turns the gift into something darker: did their private, unpublished work end up inside the machine that solved the problems first?

The company’s answer, in writing, is that it cannot rule it out.

What is the non-sofic group?

What is this maths, in plain terms? In 1999, the legendary mathematician Mikhail Gromov asked whether every infinite mathematical structure of a certain family — a “group” — had a property called being “sofic,” which roughly means it can be approximated by well-behaved, finite tables of numbers. For 27 years every group anyone examined turned out to be sofic, and nobody could prove they all were — or find one that wasn’t. In August, OpenAI announced its unreleased model, Astra, had built the first-ever exception: a non-sofic group, with a proof verified by computer. Andreas Thom, a group theorist at TU Dresden, had published key techniques behind that exact construction in 2019.

The timeline that raised the red flag

The sequence matters more than any single event.

Late July: OpenAI launches ChatGPT for Academic Researchers, a program giving scientists, mathematicians and engineers free frontier-model access. OpenAI’s own announcement stated that “researcher data is not used to train our models by default.” 🟢

August 1: OpenAI announces Astra resolved or made major progress on ten long-open problems, including the non-sofic group — with Lean-verified proofs and a 249-page manuscript. 🟢

September 6: OpenAI tells the world an internal model had produced a 100-page proof for the Navier-Stokes problem, one of the seven million-dollar Millennium Prize problems — solved via 10,000 AI agents in an 88-hour run. 🟢

September 8-9: Tristan Buckmaster, the NYU mathematician who had spent a year chasing the exact same Navier-Stokes route with Anthropic researcher Levent Alpöge, publishes a public statement. The same day, Andreas Thom publishes his email exchange with OpenAI researchers. 🟢

Two mathematicians. Two OpenAI flagship results. Both noticed their own unpublished techniques staring back at them.

Exhibit A: The Thom emails — months of chats, an answer that changed

Thom’s situation is the cleaner story, because he documented it. For months before OpenAI’s announcement, he and a colleague in Dresden had actively discussed with ChatGPT the matching problem on expanders and extensions of his 2019 work with Gábor Kun — the exact technical foundation of Astra’s non-sofic construction. When he saw the model display mastery of his own techniques, he asked OpenAI directly whether his conversations had been used.

As reported by Italian tech writer Pasquale Pillitteri, Thom first received a written assurance that OpenAI had not touched his maths chats. Pressed further, the company revised its position to something much weaker: it could not rule out that his conversations had contributed to training. Thom published the exchange. 🟢 that the exchange says this · 🟡 that training actually occurred

There is an uncomfortable detail here that will feel familiar to almost anyone who uses ChatGPT. Training on consumer chats is on by default; users must actively opt out. Thom — a world expert in his field — did not opt out until June 29 of this year. If he didn’t know the toggle existed, the average researcher certainly doesn’t.

Exhibit B: The Buckmaster case — a year logged on Codex, the same route, and an authorship offer

The Navier-Stokes story is more tangled and more serious. Buckmaster and Alpöge had spent a year using AI tools — including OpenAI’s Codex — to push a highly specific mathematical programme toward a smooth-forcing blow-up proof, one of the exact formulations the Clay Mathematics Institute would accept for the $1 million prize. Buckmaster logged their project drafts in Codex for months. 🟢

On September 6, OpenAI’s Sébastien Bubeck told Buckmaster on a call that an internal model had produced a 100-page proof — of the exact same formulation, via the exact route Buckmaster and Alpöge had been grinding down. When Buckmaster asked point-blank whether his private Codex sessions had been used to train that model, OpenAI said the model “did not look up user data.” Asked specifically about training on his data, OpenAI did not answer. The Hindu’s write-up of the statement lays out the rest: an offer that Buckmaster post his Euler result one day before OpenAI announced Navier-Stokes, and a proposal to remove Alpöge — an Anthropic employee — from authorship entirely, in exchange for OpenAI publicly backing him for the Clay Prize. 🟢 that this was offered · 🟡 what it implies

Buckmaster called the convergence of route a “bright red flag” and rushed his own work out with a public statement. OpenAI then held a press briefing claiming 10,000 agents had cracked the problem in 88 hours at a cost of millions — an account that sits awkwardly beside Bubeck’s reported first framing that the model had simply been prompted with the problem statement and given “very little human input.”

Confidence ledger — File 01

ClaimStatus
The timeline: researcher program → Astra proofs → Navier-Stokes, six weeks🟢 Verified
Two mathematicians fed closely-related unpublished work into OpenAI tools beforehand🟢 Verified
OpenAI conceded in writing it cannot rule out training on Thom’s chats🟢 Verified
OpenAI’s models were actually trained on that unpublished work🟡 Unproven — no external audit of the training run is possible
The Astra maths itself is wrong🔴 Denied by independent reconstruction — a Cambridge group theorist rebuilt the non-sofic construction; the maths stands

The prior Scientific American reporting on the ten proofs — missing citations in the sphere-packing result, “the big PR machine that wants to sound as impressive as possible” — is about attribution and packaging, not fabrication. We covered that first wave of misconduct claims a fortnight ago; this is the same story getting a second, more serious wind because now it is about private work, not published papers.

The pattern that should worry New Zealand

Zoom out from the drama and the structural problem is simple: researchers are feeding their best unpublished ideas into systems they cannot audit, run by companies that cannot prove they didn’t use them.

For New Zealand this is not an abstract ethics debate. Our research pipeline — universities and CRIs working on agritech, geothermal energy, earthquake engineering, health data, marine science — runs on exactly the kind of niche deep expertise that is both our competitive edge and, in training-data terms, very small, very concentrated, very valuable fuel. The Thom case shows what happens to niche experts who trust the chat box: the technique comes back to them wearing someone else’s logo.

We have written about this risk from the infrastructure side — the case for New Zealand building its own AI stack on renewable energy and open-weight models. The Auckland event framing was “pick your hard.” An opinion piece at the University of Auckland put the economic version bluntly in August: an AI hub is no guarantee of wealth, and a country that only supplies land, water and power for other people’s data centres ends up a concierge, not an owner. The Thom and Buckmaster cases add a sharper, upstream version of the same warning: ownership of the stack matters less than ownership of what goes into it. Ideas extracted at the chat-input stage never make it to the investment stage at all.

Intellectual property protection for NZ innovators is now a live election topic, with parties proposing cheaper, stronger IP pathways. Fine — but no IP office can protect an idea that was pasted into a chatbot a year before the paper was filed. The protection that matters in 2026 is behavioural: unpublished work and AI chat boxes need to be treated like oil and water. The opt-out toggle exists, but a toggle nobody knows about is not consent — it is a liability shield.

There is a fair objection: researchers get enormous value from these tools, and frontier models are genuinely accelerators — the same Buckmaster used AI heavily in his own (legitimately credited) work. Nobody is arguing mathematicians should stop using them. The argument is about sequence: published work, or work you are happy to donate, goes in. The crown jewels do not. And institutions — universities, CRIs, royal societies — should be saying this out loud, because individual researchers are clearly not hearing it.

Case assessment — File 01

OpenAI’s researcher program was pitched as a gift: free frontier compute for science. Six weeks later, the two most famous results from that pipeline are shadowed by mathematicians who believe their private work fed the machine, and the company’s own written position is that it cannot rule that out. Maybe nothing improper happened. The problem is that nobody — not the mathematicians, not the public, not even OpenAI, apparently — can verify it either way. A research economy built on trust needs verifiability, and the chat-input stage has neither. New Zealand’s researchers, and every small country’s, should read the Thom emails as a case study in what happens to the trustor.

One caution before the next file. It is tempting to file this under “OpenAI bad, its rivals principled.” The next case file closes that door: the one verified instance of chat-input abuse on record involves the other end of the industry — and the accuser there has an audit-asymmetry problem of its own.

Continue to Case File 02: The Relay — how Kimi users paid for Kimi and got Claude.

❓ FAQ

Has OpenAI been proven to have trained on the mathematicians’ chats? No. OpenAI says a model “did not look up user data” and, in the Thom exchange, that it cannot rule out training on his conversations. No external audit of the training data is possible.

Did the Astra maths results hold up? The non-sofic group construction was independently reconstructed by a Cambridge mathematician, so the core maths stands. The criticisms have centred on attribution, credit and PR framing rather than correctness. Earlier scrutiny also found missing citations in the sphere-packing result.

What should NZ researchers actually do? Treat consumer chatbots as untrusted infrastructure for unpublished work: check the training opt-out settings, keep pre-publication crown jewels out of chat inputs, and push institutions to set clear policy rather than leaving it to individual judgement.

📰 Sources


— CJ Murden, editor of Singularity.Kiwi. Former digital technologies teacher, author of AI-focused books. Writing with a New Zealand focus.

Sources: Scientific American, The Hindu, NYU (Buckmaster statement), SiliconANGLE, University of Auckland, Pillitteri, OpenAI