\n\n\n\n Your Unpublished Proof and Somebody Else's Server - Agent 101 \n

Your Unpublished Proof and Somebody Else’s Server

📖 5 min read•850 words•Updated Sep 10, 2026

It’s 11pm. A mathematician has a proof sketch that isn’t finished, isn’t published, and isn’t shared with anyone yet. Three lemmas work. One doesn’t. She opens a chat window, pastes in the messy part, and asks for help finding the gap. Twenty minutes later she has a useful answer and a new, quieter thought: that text now lives on a company’s servers, and she has no real idea what happens to it next.

That moment is the whole story. Not a scandal, not a leak, just a small hesitation that a lot of researchers are feeling at once.

Why this keeps coming up now

The tools got good. That’s the honest starting point. OpenAI has described how its own researchers’ daily work has changed over the past year, with coding agents running throughout the day, often in several concurrent sessions, and total usage climbing quickly. Outside OpenAI, scientists are using these systems to move faster on coding and experiments, and Nature has run pieces asking directly whether tools like “deep research” are actually useful for scientific work.

When something is merely interesting, you can afford to be picky about it. When it genuinely speeds up your work, the calculation changes. You start feeding it the real stuff — the half-finished argument, the unpublished dataset, the idea you haven’t told your collaborators about yet. And that’s exactly the material that has no protection at all until you publish.

What an agent actually does with your text

If you’re not technical, here’s the mental model that matters. An AI agent isn’t a calculator sitting on your desk. It’s more like a very fast assistant who works in someone else’s office. You hand over the work, it comes back with something useful, and the handoff itself involves a trip you can’t see.

Greg Brockman of OpenAI has described the current experience as micromanaging an agent — you have to hand it tasks and supply the context, because it doesn’t have that context on its own. That’s an accurate description of how these tools work, and it’s also the crux of the trust problem. Context is the valuable part. Context is your unpublished result.

So the question researchers are asking isn’t “will the AI steal my theorem.” It’s narrower and more reasonable:

  • Where does my input go, and for how long does it stay there?
  • Could it influence a future version of the model?
  • Who inside the company can see it?
  • If policies change, do my old submissions get treated under the new rules?

These are ordinary questions. In academia, priority is currency. Being second to publish the same result is close to being nowhere.

The trust gap isn’t really about math

Two things are true at the same time, and holding both is the grown-up position.

The tools deliver. Researchers keep using them because the acceleration is real, not because they’ve been talked into it.

And the concerns haven’t gone away. Worries about leadership and ethical risk continue to follow OpenAI around. At least one AI researcher has warned publicly that companies in this space are ignoring catastrophic risks. Regulators are still working out their approach — a joint privacy investigation into OpenAI produced findings in 2026 that, by its own framing, addressed privacy risks around building and deploying large language models while acknowledging the technology raises many other unresolved questions.

That last line is the tell. Even the regulators looking at this are saying, in careful language, that they’ve covered one slice of a much larger problem.

There’s also a money dimension. Researchers have been reckoning with what’s been called a $1.5 million “academia tax” — the gap between what frontier AI work costs and what university budgets can carry. When the good tools are expensive and centralized, individual scientists have less bargaining power over the terms they accept. You can’t negotiate hard with an infrastructure you can’t replicate.

What I’d tell a nervous researcher

Not “stop using it.” That advice ages badly and nobody follows it. Instead:

  • Sort your work into tiers. Published or public material is low stakes. Unfinished, unpublished, priority-sensitive work is high stakes. Treat them differently.
  • Abstract before you ask. You can often get help on a structural problem without handing over the specific case that makes your result yours.
  • Read your account’s data settings, not the marketing page. Enterprise, API, and consumer tiers frequently differ.
  • Ask your institution what it has actually agreed to. Many have negotiated terms nobody bothered to explain to the researchers covered by them.
  • Notice that scientists are already spreading their bets — the enthusiasm for DeepSeek among researchers shows how quickly people move when a second option appears.

The uncomfortable truth is that trust here isn’t a feeling you can reason your way into. It’s a set of commitments a company makes, in writing, that outside parties can check. Right now researchers are extending trust faster than those commitments are being written down, because the tools are too useful to wait for. That’s a normal human trade. It’s just worth making it deliberately, with your eyes open, rather than at 11pm with a half-finished proof in the paste buffer.

🕒 Published:

🎓
Written by Jake Chen

AI educator passionate about making complex agent technology accessible. Created online courses reaching 10,000+ students.

Learn more →
Browse Topics: Beginner Guides | Explainers | Guides | Opinion | Safety & Ethics
Scroll to Top