The AI Economy Has a Proof Problem
We built the AI economy without an evidence layer. Litigation is building one for us.In June I wrot 2026-10-3 08:37:31 Author: hackernoon.com(查看原文) 阅读量:5 收藏

We built the AI economy without an evidence layer. Litigation is building one for us.

In June I wrote that you cannot de-risk a breakthrough. I meant it as a complaint about venture capital and game studios: a financial discipline built to protect assets that already exist had been pointed at the creation of things that do not yet exist, and the result was a menu of predictable, insipid options.

I was too polite. De-risking is not only a taste problem, it is a structural one, and this summer produced two specimens of it inside the same industry. I am going to open on capital, take a detour through hiring and music to show the mechanism, and come back to capital at the end, because that is where the mechanism has now been written down by the people running it, and where the writing down turns out to prove less than I first thought, because the only thing that pried it loose was a lawsuit.

The first loop: the money

In July, Nvidia was reported to be weighing a guarantee of up to $250 billion on an OpenAI data centre campus in Pike County, Ohio. Nvidia shares tumbled 4.5% in late morning trading, and the price of credit default swaps on Nvidia bonds recorded their highest intraday increase since they began trading actively. Axios put the worry in one line: you buy from me, I invest in you, and everything is fine unless one of us has a problem, in which case both of us have a problem.

By mid-August the number had come down to $105 billion and been disclosed in an SEC filing, alongside a separate $1.5 billion investment in SoftBank’s SB Energy, the developer of a campus ultimately planned for as much as eight gigawatts.

The number came down. The shape did not. But the shape deserves to be stated precisely, because the loose version of this story is easy to shoot down, and the precise version is worse.

Nvidia did not finance OpenAI’s chip purchases, and it did not guarantee OpenAI’s rent. It guaranteed the residual value of the buildings. The obligation is capped at $105 billion. It is triggered only if OpenAI defaults on a lease or becomes insolvent. Before Nvidia pays anything, SB Energy has to try to relet the site at the same price, and if that fails, to sell it. And OpenAI has agreed to reimburse and indemnify Nvidia for any amount Nvidia actually pays out. On paper this is a conservative instrument: several layers of protection stand in front of it, and the party being insured has promised to make the insurer whole.

Now ask what the instrument is worth in the state of the world where it fires.

Nvidia is underwriting the resale value of buildings whose resale value consists almost entirely of their suitability for running Nvidia chips. The guarantee is cheap if, and only if, demand for AI compute holds long enough for somebody else to take the lease. The party that must fail for the guarantee to trigger is the party whose spending sustains the demand that makes the guarantee cheap. And the indemnity standing behind it is worth precisely what an insolvent OpenAI is worth, in the one scenario where anyone would need to collect on it.

Every protection in that structure is real. Every protection is conditioned on the same thing continuing. That is not fraud, and it is not even unusual. It is de-risking, performed competently, at every node.

Circular risk has a name in financial history: the doom loop. In the euro crisis, banks held their sovereign’s debt while the sovereign backstopped the banks, so neither could fail alone and both would fail together. The elegance of a doom loop is that at every individual node, the books look de-risked. That is the whole point. That is also the danger.

The mechanism, borrowed from two industries that got there first

I am not an economist and I will not pretend to price this. I build protocols, and what I recognise in the Ohio structure is not a valuation. It is a move I have watched two other industries make, in slow motion, from the inside.

The move: when evidence becomes expensive, institutions stop producing evidence and start issuing labels.

Hiring did it first. An applicant tracking system cannot observe whether you can do the work, so it observes the shape of a CV, and the shape becomes the thing. I wrote about the proxy trap and about the employable lie before I had a protocol to propose, and in Journal du Net I described how the machine asks you to lie so that the label it needs will exist. The degree, the prior title, the reference class: none of them is evidence about you. Each is a bet that the population you resemble behaves the way the population you resemble behaved. That is not knowledge. It is portfolio theory applied to a single human being, which is a category error with a person inside it.

I did not find that argument in a hiring system. I found it in dogs. Barkley AI, the first thing I built at the lab, started from breed averages and was wrong in a specific, repeatable way: the signal that matters is an individual animal drifting from its own baseline, not the distance between that animal and the population mean. A dog can be normal for its breed and abnormal for itself. Change the species and you have the hiring problem, and then the provenance problem, and then this entire article. Reference classes describe populations. Every claim worth checking is about one particular subject.

Music is making the same move now, faster and more visibly. At peak in June 2026, fully AI-generated tracks passed half of all daily uploads to Deezer, around 90,000 a day. Platforms, societies and charts answered with disclosure flags and eligibility rules. I argued in Journal du Net that the industry built the labels before it built the proof, and nothing since has changed my mind. A declaration field is not a verification.

The verification layer everyone assumes sits underneath is thinner than the announcements suggest. In August, David Buchanan showed that C2PA cameras do not survive contact with reality: Android implementations lean on Key Attestation and Play Integrity, and one-click root exploits exist in the wild for fully patched Pixel devices, via CVE-2026-43499. That is on the very app that achieved Assurance Level 2, the highest security rating the C2PA Conformance Program currently defines.

Meanwhile the Munich Regional Court was busy doing the thing a label never does. In GEMA v Suno, filed on 21 January 2025 and decided on 31 July 2026, the court took six well-known works, examined outputs generated from simple prompts naming their title, lyrics and style, found them recognisable reproductions, and held the provider responsible rather than the user. Notice how the fact got established: not by a tag and not by a disclosure, but by comparing outputs to originals. Disclosure appeared in that case as a remedy, ordered so that revenue could be quantified once infringement had been shown. That is evidence before classification. The industry has largely built the classification layer first. Eighteen months, one court, six songs, and the judgment is not final.

And the gap has now reached a creator, in real time. On 26 September, "Movin' To The Sun", a Beatport number one built from a Suno-generated sketch and rebuilt in Ableton Live by HUGEL and his co-producers, was removed from Grammy consideration over AI concerns. HUGEL has asked the Recording Academy which elements of the master led to the decision, and his team says it has preserved the session files, the working versions and the source material. Read that carefully. The evidence exists. It sat in a DAW the whole time. There is no standardised, verifiable format in which to hand it to the institution, and no way for the institution to evaluate it without taking his word. The Academy's own rule asks whether human authorship meets the category's requirements, which is the right question. Nobody built the layer that answers it.

A month earlier, South Korea's rights society KOMCA had withdrawn a rule that asked members for their session files, because there was no format in which to request them. Same gap, seen from both sides.

Three industries, one gesture. The label is a de-risking instrument. It does not transfer knowledge, it transfers responsibility.

Why the label wins, and then stops working

Labels win because they are cheap, immediate, and legible to the layer that decides. Evidence is expensive, slow, and legible only to someone willing to check.

So the label spreads, and then it decays, for the reason Goodhart gave us and everyone quotes and nobody funds around: once the proxy is the thing being bought, the proxy is the thing being produced. CVs are written for the filter. Uploads are tagged for the flag. Demand for the buildings is underwritten by the company that sells what goes inside them.

And because every actor de-risks toward whatever is currently the safest label, they all converge on the same one. Nobody was ever fired for buying IBM, and nobody is being fired this year for buying the frontier model. The individual decision is defensible in every meeting room. The aggregate of those defensible decisions is a single trade. Epoch AI estimates that AI-related data centre construction, compute hardware and networking equipment accounted for about 0.8% of US GDP in the first quarter of 2026, bringing computing infrastructure as a whole to about 1.5%, and it describes AI infrastructure as the leading driver of growth in US private investment. Every participant is de-risked. The system is a concentration.

That is de-risking’s actual output: risk removed at the level of the node, manufactured at the level of the network, and made invisible by the label until it is the only thing anyone can see.

The second loop: the documents

Here the word I have been using stops being mine.

On 17 September, unredacted filings in the New York Times copyright case against OpenAI and Microsoft were made public. As reported by TechCrunch, a January 2023 memo by Brent Hecht, Microsoft’s director of applied science, calls AI scraping “the largest theft of labor in human history”. A presentation by the same author from January 2024 describes the decline it produces as a “doom loop” that would “hurt the performance of our models and the entire web at the same time”. The filings also cite Microsoft’s own data showing that its Copilot answer engine caused click-through rates for the Times’ domain to drop by as much as 93% compared with traditional Bing search, and quote OpenAI’s head of ChatGPT describing an “existential threat” to publishers from products that are “largely substitutive”.

Read that against Ohio. The two structures are the same machine.

In the financial loop, a supplier insures the residual value of infrastructure whose value depends on continued demand for the supplier’s own product. In the documentary loop, a product substitutes for the content supply that trains it, and the substitution pays only while the supply lasts. In both cases the firm takes risk off its own node by leaning harder on a counterparty it depends on. In both cases every individual step is defensible. In both cases the failure mode is not that one side collapses, it is that there is no longer a side that can collapse separately from the other.

Ninety-three per cent fewer clicks is not a publisher’s problem. It is the training set’s problem. Somebody inside Microsoft understood that and wrote it down in January 2024, and the rest of us were allowed to read it in September 2026.

What proof would have looked like

This is the part I owe the reader, because four conditions in the abstract are worth nothing if they cannot be applied to the case that opened the article.

I have spent this year writing down what evidence has to satisfy, because I needed the specification for ACTA, and the same four conditions kept surviving every attempt to simplify them. Evidence is produced at the moment of the act, not reconstructed afterwards from its output. Evidence is a trajectory, not a point, which is the lesson of the camera failures: a signature proves that a key signed something, it does not prove where the something came from. Evidence survives an adversary, because a system whose only threat model is an honest user with default settings is a courtesy, not a proof. And evidence is verifiable by someone who does not trust the issuer, because a label you have to take my word for is my word in a nicer font.

Now apply them to the money. In this entire cycle, what has satisfied all four? Not the earnings call. Not the disclosure. Not the analyst note, not the tag, not the attestation, not the conformance badge.

One thing came close. Documents written inside the firm at the time of the act, kept as records, and pulled into the open by an adversary who did not trust the issuer.

Came close, and stopped there, and this is where I have to argue against the ending I wanted. Much of what is now public comes from the Times' own brief rather than from the underlying exhibits, which remain sealed. What we are reading is a plaintiff's characterisation of documents we cannot see, in fragments, selected by the party they benefit. That fails the fourth condition, the one I care about most. I can verify that the Times says Hecht wrote this. I cannot verify Hecht.

So the honest conclusion is harder than the one I was reaching for. Three years after the case was filed, the best evidence mechanism this economy has gives us a partial, contested, adversary-filtered view of what two companies knew about their own effect on the web. That is the state of the art. A proof layer made of subpoenas is slow, it costs millions, it fires only after the damage, it exists only where somebody had standing to sue, and even then it hands the public a curated version chosen by a litigant.

We are using it because it is the only one we built.

The uncomfortable part

Evidence infrastructure is always built after the loss. Double-entry bookkeeping, audited accounts, the chain of custody, the flight recorder: every one of them arrived after somebody’s catastrophe, and every one of them was an unnecessary expense the day before. Proof is a cost centre in the boom and the only surviving asset in the bust.

Which means the people arguing for it now look like pedants, and will keep looking like pedants for exactly as long as the label holds. I have made my peace with that. The same four conditions are the design brief for IREP and for ACTA, because hiring and provenance turn out to be one engineering problem in two costumes: an individual record, produced during the act, resistant to the incentive to inflate it, checkable by a third party who owes nobody a favour. Build that and you do not need the reference class. Build that and you do not need to ask an artist to swear. Build that and the fact does not have to wait three years for a judge.

So here is the sentence I would add to what I wrote in June. You cannot de-risk a breakthrough. You cannot de-risk a claim either. You can prove it, or you can repeat it louder and hope nobody has standing to ask.



文章来源: https://hackernoon.com/the-ai-economy-has-a-proof-problem?source=rss
如有侵权请联系:admin#unsafe.sh