September 10, 2026
by
AI Expert Team

OpenAI Cracked Navier-Stokes in 88 Hours But The Data Privacy Row Is Potentially Bigger News

what happens to the information we give AI?

On 8 September OpenAI published a proof that the Navier-Stokes equations, which engineers have used for two centuries to design aircraft and forecast weather, can break down in finite time. The question of whether they always behave had stood open for about 90 years but around 10,000 OpenAI agents closed it in 88 hours on their own, apparently.

But a year of another team’s unpublished work on the same problem sat inside OpenAI’s own product while OpenAI raced them to the answer. Any business whose staff paste client work into AI tools should read the rest of this article with that in mind because the AI data privacy question it raises applies to everyone.

What OpenAI say happened

The proof came from an unreleased internal model that OpenAI describe as well ahead of GPT-6 Astra, the model they shipped days earlier. They aimed a system of coordinating agents at every open Millennium Prize Problem at once. The group working on Navier-Stokes ran around 10,000 agents in parallel, exchanged 2.7 million messages and reached an answer on 5 September, three days before publication. The output is a 165-page paper and a formal proof in Lean. OpenAI say they will not claim the $1 million prize and the Clay Mathematics Institute, who set the problem in 2000, have not certified the result.

The capability claim holds up. A Lean proof either compiles or it does not and Quanta Magazine report that mathematicians have checked the formalisation. The detail most coverage skipped is that the model is not for sale. It remains internal, unreleased and still in training, so whatever your team use today is not this frontier tool.

The other team

Tristan Buckmaster of New York University and Levent Alpöge of Anthropic had spent close to a year on the same ground. They used Claude and OpenAI’s Codex and kept their working drafts inside Codex throughout. On 15 August they proved that the Euler equations, the simpler relative of Navier-Stokes, can blow up. They verified that in Lean on 22 August and published nothing until 7 September.

OpenAI’s own announcement says the Millennium effort launched on 1 September after the company heard a rumour, which they later realised concerned Buckmaster and Alpöge. When the two sides spoke on 6 September, Buckmaster learned that OpenAI were claiming a Navier-Stokes result along the line of attack he had been pursuing. He asked whether his Codex sessions had fed the model and received no answer on that point.

OpenAI deny accessing the work. They say no specific user data went into the problem and that neither their researchers nor their agents saw the other team’s drafts before publication. They add that they cannot rule out de-identified data from that use of their products having helped improve their models.

Why both teams took the same road

The shared approach has an innocent explanation, which is probably the real scenario too. Diego Córdoba of the Institute for Mathematical Sciences in Madrid and Luis Martínez-Zoroa of CUNEF University spent years developing the forcing strategy that both results rely on. Buckmaster credits them openly and has said Martínez-Zoroa deserves a Fields Medal. Charles Fefferman of Princeton, who wrote the Clay Institute’s description of the problem, told Quanta the heroes of the story are Córdoba and Martínez-Zoroa. Two teams took the most promising published route and arrived at the same place, which means nobody took anything.

The published method explains the route without explaining the timing and OpenAI concede they started only once word of unpublished work reached them.

The mathematics carries two caveats. OpenAI’s proof covers statements ‘C’ and ‘D’ of the official Millennium formulation, which allow an applied force, and some mathematicians regard forcing as a departure from the problem as written. In both cases the AI also completed a strategy that humans devised rather than originating one.

Why AI data privacy matters even if OpenAI did nothing wrong

Even if OpenAI’s denial is accurate in every particular, the structural problem remains. Buckmaster’s drafts sat inside a product owned by an organisation with the compute to finish in 88 hours and the appetite to race him. Nothing improper has to happen for that to be a daft position. He was in it because the tool was useful and the interface felt private.

Most businesses are in a smaller version of it. The quantity surveyor reformatting a bill of quantities, the practice manager tidying patient letters and the account director sanity-checking a media plan are each handing working material to a company that also serves their competitors. None of them would email the same file to a stranger and a chat box does not feel like emailing a stranger.

Whether a tool trains on what users type depends on the product, the tier and the settings. Most staff have no idea which applies to the one in front of them. The Information Commissioner’s Office have said plainly that no AI exemption to data protection law exists. Customer records pasted into a consumer tool that retains them outside the UK, without a lawful basis, can put a business in breach whatever it sells.

Four categories of exposure

Customer data covers names, contact details and purchase history, shared when somebody asks AI to draft a letter or analyse a list.

Financial information covers margins, forecasts and supplier prices, pasted in for help with a spreadsheet.

Strategic content covers roadmaps, tender responses and acquisition discussions, run through AI for a polish.

Original work is the thing the business sells, whether designs, methods, code or research. It is the category the Navier-Stokes row has pushed to the front and the one most AI policies forget.

What to do

Start by finding out which AI tools the team use. Shadow AI, meaning tools staff adopt without sign-off, is common in smaller businesses because people reach for whatever works.

Read the data terms on each one. Enterprise tiers of the major platforms give stronger controls, data residency and contractual guarantees and moving tier is usually an easy decision once leadership see the exposure.

Write a one-page AI policy covering the four categories above and put the team through AI training so people know where the line sits.

Then ask the provider in writing whether your content trains their models and file the answer. That is the one action this whole story argues for. Buckmaster asked in conversation and got half a reply. A written answer is a contractual position and it tells you quickly whether the licence tier matches the work going through it.

Who owns the next idea?

Terence Tao, reported by Fortune, warned that the ‘strip-mining of open problems’ for answers risks destroying the ecosystem that produces the next generation of techniques and practitioners. Labs publish answers and keep the dead ends, which is where the insight usually lives.

The commercial version of that worry is already public. Satya Nadella of Microsoft and Alex Karp of Palantir have each alleged that frontier AI companies train on customer prompts and use what they learn to build competing products. The allegations are unproven, the incentive behind them is not in doubt.

A handful of companies now hold the tooling, the compute and a view of what everyone else is working on. Who owns the next idea has become a procurement decision and most businesses are making it by default.

Where this leaves an SME

Businesses should use AI. The capability on show is real and the businesses that ignore it will lose to the ones that do not. Using it deliberately means a proper AI roadmap rather than a pile of tools and a clear view of which material can go where. Data privacy is one part of a wider AI compliance job that smaller businesses can no longer put off.

We work with SMEs across the UK through our AI consulting services to find where AI makes money and where it makes risk. Plenty of consultancies will tell a client what to buy. We will tell them when to wait, in writing, before they spend a penny. Jon Rew, Managing Director of Scimitar Sports, said our AI Readiness Assessment ‘highlighted things that were likely costing us money’.

Our free AI Readiness Assessment takes two minutes and shows where your AI data privacy exposure sits.

Frequently asked questions

Has the Navier-Stokes problem been solved?

OpenAI have published a proof with a Lean formalisation covering statements ‘C’ and ‘D’ of the Clay Mathematics Institute formulation. The Institute have not certified it and no peer review has taken place. Some mathematicians question whether the forcing method answers the problem as it was intended.

Did OpenAI use another mathematician’s private work?

OpenAI deny it. Tristan Buckmaster has asked publicly whether his Codex sessions fed the model and says he received no answer on training. Both teams built on the same published strategy, which explains the shared approach. The timing remains in dispute.

Can AI companies train on the work my business puts into their tools?

It depends on the product and the contract. Consumer tiers of many AI products may use conversation data to improve models by default. Enterprise agreements from the major providers typically exclude it. Ask before you upload and get the answer in writing.

What is shadow AI?

AI tools staff adopt without approval from IT or leadership. They may not meet the data protection requirements of the business, which usually finds out only when something goes wrong.

How do I know if an AI tool is safe for business use?

Check the provider’s retention policy, their training policy and whether they offer a Data Processing Agreement under UK GDPR. If there is no DPA, treat the tool as unsuitable for personal or confidential material.

Share this post

Subscribe to our AI newsletter

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.