De-identification Protects Your Name. It Doesn't Protect Your Idea.

A mathematician spent a year on a Millennium-class problem inside a coding assistant. Then the company that makes the tool called to say it had solved the bigger one. Nobody has shown his data was used. It wouldn't matter: the rarer your idea, the more the idea is the PII.

De-identification Protects Your Name. It Doesn't Protect Your Idea.

Imagine you spend a year on the hardest open problem in your field. You feed every draft, every dead end, every 3 a.m. "wait, what if" into the coding assistant you pay for out of your own research budget. Your proof finally checks in Lean on August 22. You decide, like a decent person, to spend a few weeks turning the machine-generated argument into something a human can read before you announce it.

Then, on a Sunday, the company that makes the tool calls you. They have solved the bigger problem. Via your route. They started last week. Would you like to write it up for them?

That is Tristan Buckmaster's account of the last ten days, and even if every single thing OpenAI has said in response is true, that is still what it felt like from his chair. WHICH, for better or worse, is the point of this post.

What actually happened

Quick version.

The Navier-Stokes existence and smoothness problem asks whether the equations describing fluid flow can spontaneously produce infinite velocities in finite time. It is one of the seven Millennium Prize Problems, and, it's really really hard. For years, Diego Córdoba and Luis Martínez-Zoroa have been building a program to force a blowup with an external forcing term, first with rough forcing, aiming toward the smooth-forcing version that Fefferman's official problem statement allows as options (c) and (d).

Buckmaster (NYU) and Levent Alpöge (a mathematician who works at Anthropic, collaborating with Buckmaster on a personal basis with no institutional involvement) took that program and pushed it, with a great deal of LLM help, to smooth forcing and to the 3D incompressible Euler equations. Their Euler proof verified in Lean on August 22 but instead of publishing right away, they held it back to write a readable paper. Among the tools they used was Codex, in which sessions held every draft of the project.

But then the rumors started leaking. A colleague at Courant emailed Buckmaster that "Anthropic had solved a Millennium problem." The colleague heard it from an analyst in the UK, who heard it from somewhere upstream. The rumor was wrong on the problem, wrong on the institution, and right on the direction.

On the Sunday call, Buckmaster asked whether the model had been trained on, or had access to, their sessions. He was told the model did not look up user data. He asked about training. He says he got no answer. Publicly, OpenAI's position is that no person or agent searched user data, that the two teams' approaches look different now that both are visible, and that both grew from the same Córdoba and Martínez-Zoroa roots.

Nobody has shown that Buckmaster's data was used. I want to be clear about that. I am not accusing anyone of anything either. I am pointing at something that is true regardless.

By Altman's own account, OpenAI heard the same rumor, and started seeing if they could solve it on September 1 because they were curious whether their model could do it too. They pointed an unreleased model at all six remaining Millennium problems, saw traction on Navier-Stokes, and threw roughly 10,000 agents at it for about 88 hours worth millions of dollars of compute.

They solved it, and that gets you up to speed.

The thing de-identification cannot remove

Every AI lab, every SaaS vendor, every enterprise data team has followed the privacy checklist. "We strip names and emails and session identifiers and aggregate and and and." Sometimes we get to call the result "synthetic data" and feed it back into the system with a clean conscience.

Now the problem is that when you have something really unique, like the solution to a Millenium problem over months in your logs, all that doesn't really help.

What is left after you remove "Tristan Buckmaster" and "levent@"? A pile of text in which someone is attacking Navier-Stokes through smooth forcing, options (c) and (d), via a specific chain of prior results, with a specific set of estimates that keep failing in a specific way. Buckmaster himself said almost nobody in the world was on that route. He also said the model does not land on it in a few days from the bare problem statement.

There are maybe four people on Earth who would write that particular sequence of prompts, so while it's not EXACTLY personally identifiable information (PII) it's not hard to figure out who it is. And even if you don't know or care, you STILL get a ton of information.

De-identification is a name-removal technique, and works when your data sits in a crowded region, when you are one of ten million people asking how to center a div. It fails when your data sits in a sparse region where just the way you ask the question is both unique, and valuable. Basically, the rarer your idea, the more the idea is the PII.

And while the leak in this story appears to have traveled entirely through humans, it was enough to trigger a bunch of people to start looking at the problem in a new way. A single rumor with one word in it, "forced," was enough to point ten thousand agents at the right door. If that can happen through gossip, imagine what a gradient can do.

The same mechanism is the whole point

Why is the model good at this problem at all? Because it is a compression of billions of humans interacting over a million arXiv preprints, and every seminar note somebody typed up, and every Stack Exchange thread where a grad student got yelled at for a sign error. So you take every half-finished idea somebody abandoned in 2011 because the estimate didn't close and you form it into a new ball, and, magically, our tool can pull out threads no individual could hold in their head at once. Including, apparently, a two-person research program from Madrid that most of the field was not paying attention to.

This is really kind of insane, and it should be as inspirational as it is scary.

For all of human history, collaboration has been bandwidth-limited by the number of people you could physically talk to. Newton had Halley who had Ramanujan, and only because a letter made it across an ocean. The rest of us have a lab, a Slack channel, and whoever answers our email. Every important idea that ever died did so because the one person who needed it never met the one person who had it. That is the default outcome for most ideas.

What Buckmaster actually did this year is the first version of something different. He did not just use a tool; he collaborated with a compressed record of everyone who ever wrote down a thought about fluid dynamics, including two people in Madrid he took as his starting point, including thousands of people whose names he will never know and whose partial results the model absorbed and recombined. He and Alpöge took Córdoba and Martínez-Zoroa's ideas and used LLMs to push them to completion in about a month. He called it a Deep Blue moment and even with that grand pronouncement, I think he is still underselling it. Deep Blue beat one man at one game. This is every mathematician who ever lived showing up to your office hours at once, badly organized, occasionally wrong, and available at 3 a.m.

The first LLM-generated proof he was sent was, in his words, the most horrendous he had ever read. But it was also correct. That is what collaborating with all of humanity looks like. Not clean. It is a room with eight billion people in it, and somewhere in the noise is the one sentence you needed.

You cannot have that capability without the risk in the previous section. The ability to tease apart a rare, high-value thread from the mass is the same ability that makes rare, high-value threads unhideable inside the mass. The room that lets you hear everyone also lets everyone hear you. There is no privacy setting that keeps the second thing and drops the first. It's a trade off, but one that could unlock a new version of humanity, at the cost of the way we think about privacy.

Two big takeaways

There are two really big things this teases out.

First: the only de-identification that works is not sending it. If your work lives in a sparse region, and you are a startup, a lab, or a lone mathematician with a real idea, the only protection that survives contact with a sufficiently capable model is keeping the data where it lives and bringing the model to it. Buckmaster used the frontier tools and got a Millennium-class result out of them. The question is which room you think out loud in, and who holds the lease.

Second: we need provenance for ideas, not just data. The community will spend months trying to work out whether two proofs that share a root, a route, and a week share anything else and it cannot, because nothing was logged. We have spent years building lineage for datasets and software bills of materials for code. When a proof is produced by 2.7 million messages between agents, "we did not use their prompts" is not evidence. A machine-readable record of what went into a result, what it was seeded with, and when, is the missing artifact here. Not a better privacy policy. A receipt.

Keep using the tools!

The lesson is not "don't use the tools." Buckmaster used them and got a result that would have been science fiction two years ago because thousands of people he never met helped him do it. That is the biggest expansion of who you get to think with since the printing press, and I do not think anyone should give it up.

But the room where all of humanity can help you is also the room where all of humanity can see your notebook. Right now one company holds the lease on that room and gets to decide, after the fact, what "we didn't look" means. The fix is not to leave the room; it is to bring the room to you, and to keep receipts for who said what inside it.

De-identification is a promise about your name. But your name was never the valuable part. The idea was, and the idea is exactly what the whole thing is built to find.

Sources: Buckmaster's public statement; OpenAI's announcement and press call as reported by Scientific American and Axios, September 8, 2026.


Want to bring the model to your data instead of shipping your notebook to somebody else's room? Check out Expanso. Or don't. Who am I to tell you what to do.

NOTE: I'm currently writing a book based on what I have seen about the real-world challenges of data preparation for machine learning, focusing on operational, compliance, and cost. I'd love to hear your thoughts!