AI That Doesn't Train on Your Data: What the Navier–Stokes Dispute Should Change About Your Vendor Contract
A signed contract is what keeps an AI vendor from training on your data. The vendor can rewrite a settings toggle. Hathr.AI runs Claude on AWS GovCloud (US) inside a FedRAMP High boundary, never uses customer data for model training, and includes a signed BAA on every web application account.
Three questions below separate a contract from a policy:
- At what layer do you retain my data, and for how long?
- Who and what tools can read, access, or process my prompts, and under what circumstances?
- What happens if the vendor does look at my work?
Key takeaways
- OpenAI has denied accessing the mathematicians' unpublished work, on the record, and that denial carries the whole lesson.
- A privacy policy describes what a vendor intends today. A contract describes what the vendor owes you when it stops intending that.
- Tristan Buckmaster asked whether his Codex sessions had been used for training and got no answer. His terms of service obligated none.
- Hathr.AI's Business Associate Agreement commits to breach notice within 20 business days and return or destruction of PHI within 30 business days of termination.
- Hathr.AI runs Anthropic's Claude models on AWS GovCloud (US) inside a FedRAMP High authorization boundary, so customer data never touches the commercial internet.
What happened with the Navier–Stokes proof
In early September 2026, OpenAI announced that an unreleased internal model had produced a proof of finite-time blowup for the forced Navier–Stokes equations, a result adjacent to one of the seven Millennium Prize Problems.
Tristan Buckmaster, a mathematics professor at NYU, then published his own account. He and his collaborator Levent Alpöge had spent about a year on a related approach. They obtained blowup results with smooth forcing for Boussinesq and 3D incompressible Euler on 15 August 2026, and verified them in Lean on 22 August. Buckmaster credited the underlying idea to Diego Córdoba and Luis Martínez-Zoroa, not to any model. The pair worked inside commercial AI tools throughout the project, including OpenAI's Codex and Anthropic's Claude.
Buckmaster describes a meeting on 6 September with OpenAI's Sébastien Bubeck, where he learned that an internal OpenAI model had resolved forced Navier–Stokes. He asked whether that model had been trained on, or had access to, the Codex sessions holding every draft of the project. By his account he received no answer to the training question. He also describes being asked to publish the result without Alpöge as an author, and being told, when he raised going public, If you don't want me to be nice, then I don't have to be nice.
Buckmaster has been careful about the limits of his own claim. He has not seen OpenAI's proof, does not know whether his data was used, and says he is reporting what he was told rather than accusing anyone of misconduct.
OpenAI says it did not "see" Buckmaster's work and then admitted it may have ingested the data from users like Buckmaster
On 8 September 2026, OpenAI stated that we (the researchers and the agents) did not see any of their work through any means until they released it publicly, in particular, no specific user data was accessed in order to solve this problem. The company added that it cannot rule out that de-identified usage data improved its models in general, and noted that the two proofs differ.
We have no reason to doubt that denial. It still changes nothing about the exposure.
Buckmaster could not verify the answer either way. He had no access to the training set and no standing to compel disclosure. He could not point at a clause and say what he was owed if the answer went the other way. He asked a question that mattered to a year of his life, and the only thing behind the response was the goodwill of the party with the most to lose from answering it wrong.
That exposure exists whether or not anyone did anything wrong. A dispute you cannot adjudicate is a dispute you lose by default. If you run compliance for a hospital or an agency, the fluid dynamics are irrelevant and the structure is familiar: it describes your clinician pasting a discharge summary into a general-purpose chatbot this afternoon.
Does my AI vendor train on my data?
Most commercial AI vendors will tell you they do not train on business-tier customer data, but that doesn't include using human and machine review to identify and reuse information on the platform. A narrower question decides your risk: what happens when that changes, and what do you hold when it does?
A privacy policy is a unilateral statement of current practice. The vendor writes it, the vendor amends it, and the vendor's own terms reserve the right to amend it on notice you will not read. It describes intent. It creates almost no obligation that survives the vendor changing its mind.
A contract binds both sides. It names the parties, the obligations, the timeline, and the consequence of breach. Under HIPAA that instrument has a specific form, the Business Associate Agreement, and no vendor may handle protected health information without one.
Buckmaster and Alpöge worked as a personal collaboration with no institutional agreement in place. That is the default condition for most people using these tools, including the hospital department that adopted a general-purpose assistant last quarter because it summarized charts well.
What a real data contract commits to
We can be specific here because we signed one. Hathr.AI works with Healthcare Data, Proprietary Information, Government Data, etc. every day - not just a vendor theorizing about Business Associate Agreements. Our BAA, DPA, and User Agreement (See our Terms and Conditions) is accepted electronically at signup, and using the service constitutes a binding electronic signature. It carries these terms:
- Breach and security incident notice within 20 business days of discovery. A date you can hold us to, not a promise to hurry.
- Return or destruction of Protected Health Information within 30 business days of termination, or extension of the same protections where return is infeasible.
- Support for individual rights: access, amendment, restriction, and accounting of disclosures under 45 CFR § 164.528, 42 CFR Part II, 38 CFR, and other compliance regimes required for responsible, secure, compliant, AI tools in healthcare.
- Downstream flow-down. The same obligations bind any subcontractor we use.
- Coverage of the HIPAA Privacy and Security Standards and the HITECH Act, with Hathr as Business Associate and the customer as Covered Entity.
That is what separates a compliance page from a compliance control.
How a vendor prices the instrument tells you what the vendor thinks it is for. If a vendor charges more for the BAA, the BAA is a product line rather than a safeguard. Hathr.AI includes a signed BAA on every web application account at $47 per user per month, with no seat minimums. We work with solo practitioners and multi-state health systems.
Four questions to ask your AI vendor before your next upload
We built this list from the questions our own prospects raise during security review, and from what Buckmaster could not get answered. Ask them in writing. A vendor who answers three and dodges the fourth has told you something.
- Will you sign a data agreement naming your obligations, or will you point me at a policy page? A link back to a policy page means you hold a description of intent and nothing else.
- At what layer do you retain my data, and for how long? Retention at the model layer and storage at the platform layer are different questions with different answers, and a vendor who collapses them is either confused or counting on you to be. For Hathr.AI: the models operate under zero data retention, so they retain no prompts or outputs and reuse nothing. Your files and chats sit in your own account in a segmented environment for as long as the account is active, and you delete them whenever you want.
- Who and what can read my prompts, responses, queries, or anything I upload or create with your tool, and under what circumstances? Ask about human review for quality, safety, and abuse monitoring. Vendors carve those out of the no-training promise.
- What do I hold if you are wrong? The most useful question on the list, and the one buyers skip. Notice deadlines, deletion clocks, and subcontractor terms are the answer. Silence answers it too.
Where this exposure bites
A contested proof makes a visible version of an ordinary problem. The organizations we work with are not racing anyone to a Millennium Prize. They handle material where losing control costs them a penalty rather than a citation:
- Healthcare and behavioral health. A discharge summary pasted into a general-purpose tool is a disclosure to a party with no BAA. The policy memo telling staff to stop doing it does not work. Giving them something that does the same job and is permitted does.
- Federal and state agencies. Data carrying a handling requirement keeps carrying it when a model turns out to be convenient. Hathr.AI's FedRAMP High infrastructure supports processing of federally regulated data, including CMS data that commercial AI tools are not authorized to handle.
- Medical-legal and expert-witness work. Opposing counsel will ask where you processed the record and who could see it. Hathr.AI can attest that it does not monitor or use customer information, which supports use of its outputs in legal and expert-witness settings.
- Payers, RCM, and utilization review. Claims and appeal material is commercially sensitive on top of being regulated.
Buyers already ask this question at volume, and someone else already answers it. Our own search data shows the shape of it. Over the last six months, 278 distinct queries reaching hathr.ai concerned AI privacy, training, retention, or data ownership. Those queries produced 44,493 impressions at an average position of 6.06, and 79 clicks. Buyers ask whether AI vendors train on their data, read the answer inside the search result, and never reach a page where they can act on it. If you have been meaning to check your vendor's terms and have not, you have a lot of company.
How Hathr.AI is built for this
Hathr.AI is a HIPAA-compliant AI platform for regulated industries. It runs Anthropic's Claude models on AWS GovCloud (US) inside a FedRAMP High authorization boundary, the class of government-approved infrastructure used for sensitive federal workloads and not available on the commercial market. The models are unmodified Claude, so you get identical capability. The environment differs.
- Never used for training. Hathr.AI never uses customer data for model training or product development, and customer data never touches the commercial internet.
- Zero retention at the model layer, your documents yours at the platform layer. The models retain no prompts or outputs. Files and chats live in your account in a segmented environment, never commingled with another customer's data, and you delete them on your schedule. Enterprise customers set a custom retention schedule.
- A signed BAA on every web application account, accepted electronically at signup, carrying the terms above.
- Government-approved models and control frameworks. Hathr.AI's controls conform to NIST 800-53 and NIST 800-171, and map to HIPAA, 42 CFR Part 2, and 38 CFR.
- Reliability we tested in public. During the commercial Claude outage, Hathr.AI stayed up on GovCloud while commercial-cloud tools went down. We wrote up what that boundary looked like from inside it.
Discount any page claiming to win on every axis. Ours loses on one: if your work involves no regulated, privileged, or contractually sensitive material, a commercial tool with a business-tier no-training commitment will serve you and cost you less thought. Hathr.AI is built for the case where a policy statement fails you, where you need an instrument with your name on it because someone will ask you to produce one.
Hathr.AI costs $47 per user per month with a 7-day free trial for unilimited use, unlimited uploads and downloads, no seat minimums, no setup fee, and a signed BAA on every account. See pricing or start the trial.
Frequently asked questions
Does my AI vendor train on my data?
It depends on the tier and the contract. Consumer tiers of most commercial AI tools may use conversations to improve models unless you opt out, and business tiers exclude customer content by policy in most cases. Hathr.AI never uses customer data for model training or product development, and that commitment sits inside a signed Business Associate Agreement instead of a policy page.
What is zero data retention in AI?
Zero data retention means the model stores no prompts or outputs after a request completes. It is a claim about the model, not about the whole product. Hathr.AI's models operate under zero data retention, while documents and chats you upload sit in your own segmented account until you delete them or close the account.
Is a privacy policy enough to protect confidential research or patient data?
No. A vendor can amend a privacy policy alone, and most policies specify no notice deadline, no deletion clock, and no remedy. A signed data agreement names those things. Under HIPAA, a Business Associate Agreement is required before a vendor may handle protected health information at all.
What is a BAA and who needs one?
A Business Associate Agreement is a contract binding a vendor who handles protected health information to HIPAA's Privacy and Security Standards and the HITECH Act. Any covered entity, including a solo practitioner, needs one with every vendor touching PHI. Hathr.AI includes a signed BAA on every web application account, accepted electronically at signup.
What private AI platforms work for government agencies with sensitive data?
Agencies handling federally regulated data need infrastructure inside a recognized authorization boundary instead of a commercial cloud tenancy. Hathr.AI runs on AWS GovCloud (US) inside a FedRAMP High boundary, with controls conforming to NIST 800-53 and NIST 800-171, which supports processing of federally regulated data including CMS data.
Can AI outputs be used in legal or expert-witness work?
They can support it, provided you can describe where you processed the record and who had access. Hathr.AI can attest that it does not monitor or use customer information, which supports use of its outputs in legal and expert-witness settings. Hathr.AI surfaces evidence, and a qualified human signs off on any clinical or legal conclusion.
Did OpenAI use Buckmaster's data to solve Navier–Stokes?
OpenAI stated on 8 September 2026 that neither its researchers nor its agents saw the mathematicians' work before public release, and that no specific user data was accessed to solve the problem. Buckmaster says he does not know whether his data was used. Neither party signed a contract that would let either of them prove it.
Our Youtube Videos
Hathr.AI is the fastest, safest way to handle sensitive medical records with HIPAA-compliant artificial intelligence. In this demo, watch how you can:✅ Summarize a patient’s medical record ✅ Generate an AI-assisted treatment plan ✅ Write a letter to the patient in plain English ✅ Suggest CPT billing codes ✅ Draft an insurance appeal for a denied claim ✅ Evaluate the case for potential malpractice — all in under 5 minutes.The only AI tool hosted in AWS GovCloud and Powered by Claude 4.0 Sonnet, Hathr.AI is trusted by hundreds of practices that need speed, security, and compliance.Learn more: hathr.ai For healthcare teams: hathr.ai/healthcare Reach out to learn more: contact@hathr.ai
#HIPAACompliantAI#ArtificialIntelligenceInMedicine#HealthcareAI#MedicalBillingAI#AIForDoctors#HIPAAAI#MedicalRecords#AIInHealthcare
Description
As Hathr.AI, we are dedicated to providing a private, secure, and HIPAA-compliant AI solution that prioritizes your data privacy while delivering cutting-edge technology for enterprises and healthcare professionals alike.
In this video, we’ll dive deep into the growing concerns around data privacy with AI tools—especially in light of recent revelations about Microsoft’s Word and Excel AI features. These new features have raised alarm over data scraping practices, where user data could be used without clear consent, leaving individuals and organizations exposed to potential privacy breaches. What makes this especially concerning is the "opt-in by default" design, which could lead to unintended data sharing.
In contrast, Hathr.AI ensures that your data stays yours. With a firm commitment to HIPAA compliance, we take the protection of sensitive healthcare data to the highest level. Our platform is built with the understanding that privacy is not an afterthought but a fundamental pillar of our design. We don’t collect, store, or sell user data, and we employ state-of-the-art encryption, secure access protocols, and clear user consent processes to keep you in full control.
We’ll also touch on why Hathr.AI, powered by advanced LLM (Large Language Models) like Claude AI, offers a secure and private alternative for businesses looking to leverage AI technology without compromising sensitive information. While some AI tools may collect or expose data through ambiguous or hard-to-find opt-out settings, Hathr.AI puts transparency and security at the forefront, offering peace of mind in an era of increasing digital vulnerability.
If you’re concerned about your privacy or looking for a HIPAA-compliant AI solution that respects your data, Hathr.AI provides the robust security, transparency, and ethical design that you need.
Key Points:
- HIPAA Compliant AI: Built for healthcare professionals, ensuring compliance with privacy regulations.
- Privacy-first: No data scraping, no data selling, full user control over information.
- Claude AI: Secure, powerful LLM tools for advanced capabilities without compromising security.
- Data Transparency: Say goodbye to hidden opt-in/opt-out toggles—Hathr.AI gives you clear, easy-to-understand privacy settings.
Tune in to learn how Hathr.AI ensures your AI tools remain private, secure, and trustworthy, while still delivering the performance and accuracy you need to thrive in a fast-evolving digital landscape.
Don't forget to like, comment, and subscribe for more insights on secure AI solutions and how to protect your organization from emerging privacy risks!
Description
Discover how Hathr AI's advanced AI tools transform federal acquisition processes with unparalleled security and efficiency. Designed for government professionals, this video showcases Hathr AI’s capabilities, including secure AI data analysis, HIPAA-compliant tools, and AWS GovCloud integration, to help streamline decision-making and document management. Perfect for agencies seeking private, compliant, and powerful AI solutions, Hathr.AI delivers tools tailored for healthcare and government needs.
Key Topics Covered:
AI-driven data analysis for governmentHIPAA-compliant, secure AI tools for federal agencies
Private deployment options with AWS GovCloud
Learn more about Hathr AI’s secure, high-performance solutions at hathr.ai and transform your agency’s acquisition process with cutting-edge AI.
Description
Discover how Hathr.AI simplifies NSF grant evaluations with advanced AI-driven compliance and proposal review tools. This video showcases Hathr.AI’s capability to streamline grant compliance checks, enhance accuracy, and save time for evaluators and applicants alike. Ideal for research institutions, government agencies, and proposal writers, Hathr.AI offers secure, HIPAA-compliant AI solutions tailored to meet the complex requirements of NSF and other grant processes.Highlights:AI-powered compliance checks for NSF grant proposalsFast, accurate, and secure evaluations with Hathr.AITailored solutions for research, government, and healthcareOptimize your grant proposal process with Hathr.AI's private, secure AI tools. Learn more at hathr.ai and transform how you handle grant evaluations and compliance.
Description
Join Hathr.AI at the Defense Information Systems Agency (DISA) Technical Exchange Meeting to explore innovative AI solutions tailored for federal and defense applications. In this session, we highlight Hathr.AI's secure, private AI tools designed for efficient data handling, HIPAA compliance, and seamless integration within government systems, including AWS GovCloud. Perfect for agencies seeking reliable AI for data analysis, document summarization, and secure decision-making, Hathr.AI provides cutting-edge technology for defense and healthcare needs.Highlights:AI tools for federal and defense data managementSecure, HIPAA-compliant AI solutions with AWS GovCloudEnhancing operational efficiency with private AI deploymentsDiscover how Hathr.AI's solutions empower government and defense agencies to stay at the forefront of innovation. Visit https://hathr.ai to learn more about our services.


.png)

