메뉴
BL
The Decoder • 10일 전

AI 기업들의 데이터 신뢰 문제, 정책만으로는 해결 못해

IMP
7/10
핵심 요약

Anthropic이 플래그십 모델 Fable의 사용 로그를 30일간 보관하겠다고 발표하자 Nvidia, Booz Allen Hamilton, Palantir 등 주요 기업들이 민감한 업무에 해당 모델 사용을 제한하거나 강력한 무데이터보관(ZDR) 보장을 요구하고 있습니다. 문제는 ZDR을 적용해도 메타데이터 수집이나 사용자 데이터 기반 학습 관행이 남아 있어 기업 데이터 신뢰 문제가 근본적으로 해결되지 않는다는 점입니다.

번역된 본문

AI 랩은 정책만으로 해결할 수 없는 데이터 신뢰 문제를 안고 있다

마티아스 바스티안 (Matthias Bastian) | 2026년 9월 15일

주요 기업들이 가장先进된 AI 모델의 사용을 제한하거나, 데이터가 저장되지 않는다는 철저한 보장을 요구하고 있다. 더 인포메이션(The Information)의 보도에 따르면, 엔비디아(Nvidia)와 방산 기업 부즈 앨런 해밀턴(Booz Allen Hamilton)은 앤스로픽(Anthropic)의 새 플래그십 모델 '페이블(Fable)'을 민감한 업무에 사용하는 것을 제한한 기업에 포함된다.

이러한 반발은 6월의 정책 변경에서 시작됐다. 앤스로픽은 '복잡하고 신종 공격'에 대응하기 위해 페이블의 사용 로그를 30일간 보관하겠다고 발표했다.

엔비디아, 투자자임에도 앤스로픽을 민감 업무에 신뢰하지 않아

지식재산권을 우려하는 기업들에게 이는 결정타다. 더 인포메이션에 따르면 엔비디아는 현재 페이블을 오픈소스 프로젝트 같은 덜 민감한 작업에만 사용한다. AI 기반 공급망 모니터링 같은 내부 업무에는 자체 네모트론(Nemotron) 모델을 구동한다.

엔비디아의 엔터프라이즈 AI 부사장 저스틴 보이타노는 더 인포메이션에 "회사로서 ZDR(무데이터보관, Zero Data Retention)이 기본으로 켜져 있어야 한다고 믿는다"고 말했다. 엔비디아는 앤스로픽에 투자한 상태이며 앞으로도 투자를 계속할 계획으로 알려졌고, 모델 개발용 하드웨어도 공급하고 있다.

부즈 앨런 해밀턴은 앤스로픽의 '미토스(Mythos)' 모델 초기 사용자 중 하나였지만, 더 인포메이션에 따르면 사내 독점 사이버보안 소프트웨어 작업에 페이블 사용을 금지했다. 빌 배스 CTO는 "페이블이 우리 코드의 일부를 학습하고 있을지 모른다는 우려가 조금 있다"고 말했다.

더 인포메이션에 따르면 팔란티어(Palantir)는 앤스로픽이 취소 불가능한 무데이터보관 보장을 제공할 때까지 자사 소프트웨어를 통한 고객사의 페이블 배포를 차단하고 있다. 알렉스 카프 CEO는 고객 행사에서 기업들이 AI 랩에 '착취'당하는 데 지쳤다고 말했다. 카프는 이전부터 이런 불신을 공개적으로 표출해왔다. 팔란티어의 입장에는 자기 이해도 얽혀 있다. 고객이 공급자에 직접 접속하는 대신 자사의 안전하다는 플랫폼을 통해 AI 모델을 사용하게 만들고 싶기 때문이다.

고객 반발과 오픈AI가 8월에 GPT-5.6 사이버(Cyber) 고객에게 보안 로그를 자체 서버에 저장할 수 있도록 한 조치 이후, 앤스로픽도 비슷한 프로그램을 이번 가을에 선별된 고객에게 순차적으로 도입하기로 했다.

무데이터보관에도 여전히 빈틈이 있다

무데이터보관(ZDR)을 적용해도 AI 랩은 서비스 사용 방식 자체로부터 학습할 수 있다. 더 인포메이션에 따르면 오픈AI와 앤스로픽 모두 기업 고객으로부터 메타데이터와 기술적 사용 데이터를 수집한다.

오픈AI는 이 데이터를 '비식별화(de-identified)'됐다고 부르는데, 개별 고객까지 추적할 수 있는 정보가 제거됐다는 의미다. 오픈AI는 웹사이트에서 '서비스 사용 방식을 더 잘 이해하기 위해' 비즈니스 데이터를 자동 분류기와 보안 도구에 통과시킨다고 밝혔다. 그 결과물인 분류 정보는 비즈니스 데이터에 관한 메타데이터이며 '비즈니스 데이터 자체를 포함하지 않는다'고 회사는 설명한다. 하지만 더 인포메이션에 따르면 일부 고객은 이 메타데이터가 정확히 무엇을 포함하는지 확신하지 못하며, 현재의 투명성으로는 부족하다고 생각한다.

기업이 말하지 않는 방식으로 이뤄지는 사용자 데이터 학습

오픈AI 공동 창업자로 잠시 앤스로픽에서 일했고 현재 씽킹 머신스(Thinking Machines)에 있는 존 슐만(John Schulman)은 최근 AI 기업이 사용자 데이터로 학습할 수 있는 다양한 방식을 정리했다. 그 스펙트럼은 콘텐츠 재생 위험이 높은 사용자 데이터 직접 사전학습부터, 대형 모델을 소형 모델로 증류하는 방식, '사용자 흔적(user traces)'으로 강화학습 과제를 만드는 방식까지 이어진다.

마지막 방식은 콘텐츠 재생 위험은 낮지만 여전히 고객의 지식재산을 추출할 수 있다. 슐만에 따르면 이는 무해한 것("명시적 사용자 피드백을 보상 모델 학습에 사용")부터 침습적인 것("사용자의 코딩 환경과 커밋 이력을 강화학습 환경으로 만들기 위해 업로드")까지 다양하다. 그는 "비식별화는 취약하다"며 사용자는 '몇 비트만으로' 추적될 수 있다고 덧붙였다.

원문 보기
원문 보기 (영어)
AI labs have a data trust problem that their policies haven't solved Matthias Bastian View the LinkedIn Profile of Matthias Bastian Sep 15, 2026 Nano Banana Pro prompted by THE DECODER Major companies are restricting their use of the most advanced AI models or demanding ironclad guarantees that no data gets stored. Nvidia and defense contractor Booz Allen Hamilton are among the companies limiting how they use Anthropic's new flagship model Fable for sensitive work, according to a report from The Information . The pushback started after a policy change in June, when Anthropic said it would retain usage logs from Fable for 30 days to defend against "complex and novel attacks." Nvidia won't even trust Anthropic with sensitive work despite being an investor For companies worried about their intellectual property, that's a dealbreaker. Nvidia now uses Fable only for less sensitive tasks like open-source projects, according to The Information. For internal work like AI-powered supply chain monitoring, the company runs its own Nemotron models instead. "As a company, you know, we believe ZDR [Zero Data Retention] should be on by default," Justin Boitano, Nvidia's VP of Enterprise AI, told The Information. Nvidia has invested in Anthropic, reportedly plans to continue doing so , and supplies the company with hardware for model development. Booz Allen Hamilton, one of the earliest users of Anthropic's Mythos model, has banned employees from using Fable for work on proprietary cybersecurity software, according to The Information. CTO Bill Vass said, "We worry a little bit that [Fable] might be learning from some of our code." Palantir is blocking Fable deployment through its own software to customers until Anthropic grants irrevocable zero-data-retention guarantees, The Information reports. CEO Alex Karp said at a customer event that companies are tired of being "exploited" by AI labs. Karp has been vocal about his distrust before. Palantir's stance is also self-serving, since the company wants customers running AI models through its supposedly secure platform rather than going directly to providers. After customer pushback and OpenAI's August move to let GPT-5.6 Cyber customers store security logs on their own servers , Anthropic followed suit with a similar program rolling out to select customers this fall. Zero data retention still leaves gaps Even with zero data retention, labs can learn from how their services get used. Both OpenAI and Anthropic collect metadata and technical usage data from enterprise customers, according to The Information. OpenAI calls this data "de-identified," meaning it's stripped of information that could be traced back to individual customers. OpenAI states on its website that it runs business data through automated classifiers and security tools "to better understand how our services are used." The resulting classifications are metadata about the business data "but do not contain any of the business data itself," the company writes. Some customers aren't sure what exactly that metadata covers, according to The Information, and don't think the current transparency is enough. Training on user data happens in ways companies won't talk about John Schulman , OpenAI co-founder who briefly worked at Anthropic and now works at Thinking Machines , recently laid out the different ways AI companies can train on user data. The spectrum runs from direct pretraining on user data, which carries a high risk of reproducing content, to distilling large models into smaller ones, to building reinforcement learning tasks from "user traces." That last approach has a low risk of content reproduction but can still extract customer IP. It ranges from harmless ("use explicit user feedback in reward model training") to invasive ("upload user's coding environment and commit history to turn into rl envs"), Schulman says. "De-identification is weak," he adds, and users can be traced back "with just a small number of bits" and it doesn't protect against IP leakage. AI researcher Sarah Hooker, who previously worked at Cohere and Google DeepMind, describes a similar loophole . There are "clever synthetic data techniques that can generate distributional equivalent data while preserving privacy." In other words, even if an AI lab doesn't use original data directly, it might be able to extract statistical patterns that get the same job done. Hooker warns companies, "If you are a company with IP you have a limited window to build your own intelligence that leverages your IP. Otherwise you are fueling a frontier lab which will encroach on your vertical sooner or later." In a follow-up post , Schulman walked that back somewhat. Training on user data is "exceedingly unlikely" to contribute much to frontier capability gains, he said. Those gains come primarily from scaling pretraining and reinforcement learning. User data is more useful for finding failure modes or situations that are hard to replicate with paid annotators. He added, though, that "model companies vary in how aggressively they train on user data (and uploading repos isn't hypothetical)." That's likely a nod to AI coding tools like Codex or Cursor, where users connect their code repositories directly to the services. Schulman called for "stronger norms around disclosing how companies train on user data." The Buckmaster case made the trust problem real Schulman weighed in after mathematician Tristan Buckmaster leveled serious accusations against OpenAI. Buckmaster and his co-author Levent Alpöge had used AI models to make progress on the Navier-Stokes equations , uploading their drafts through OpenAI's Codex. Shortly after, OpenAI presented its own breakthrough using the same unusual solution path. OpenAI initially acknowledged that it could not rule out that anonymized data derived from their use of our products contributed to improving our models. After an internal investigation, the company updated its post , saying Buckmaster's Codex prompts from the two months before the September 8, 2026, publication "could not have influenced the system in any way, including through training." Still, the case showed how fragile the trust between business, academia, and the AI labs really is . AI News Without the Hype – Curated by Humans Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section. Subscribe now --> Read on for the full picture. Subscribe for hype-free coverage. Full access to every article on THE DECODER No ads Join the comments and community discussions A weekly AI news recap via mail 6x/year: "AI Radar" — deep dives on the AI topics that matter most Daily AI news, always up to date Our full ten-year archive Covered by a team with 10+ years in AI Subscribe to The Decoder -->