[ai-control] Re: Proposed "AI System Inference" and "AI User Input" categories

Tyler Martin <tyler@copyright.sh> Thu, 20 August 2026 06:30 UTC

Return-Path: <tyler@copyright.sh>
X-Original-To: ai-control@mail2.ietf.org
Delivered-To: ai-control@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 82E5212CB1CD5 for <ai-control@mail2.ietf.org>; Wed, 19 Aug 2026 23:30:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1787207402; bh=g3DEXuUC64IMqSFs4tQh3kpGMe4OcJenYt18T/PxH+w=; h=Subject:From:In-Reply-To:Date:Cc:References:To; b=U8Bc+YJ2GTHLEGp/RRH2ELTSg7txFdTBLHfLnFD9gFi8Kpb8iFW508lmUJ96t6Msl AwlLaB305nRS2BaNs+u+pnCEF2KX5qpznQao3ZV7ilayYxuj/stbxw1kXohRPR6dWr cs52KU3xgfr/G39xuA1DJIBC44V8iMjXfMRsl0J0=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.101
X-Spam-Level:
X-Spam-Status: No, score=-2.101 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=copyright.sh
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RuA_JOkPoOW4 for <ai-control@mail2.ietf.org>; Wed, 19 Aug 2026 23:30:01 -0700 (PDT)
Received: from mta1.migadu.com (out-206.mta1.migadu.com [IPv6:2001:41d0:203:375::ce]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 22B4312CB1CCE for <ai-control@ietf.org>; Wed, 19 Aug 2026 23:30:00 -0700 (PDT)
X-Envelope-To: ai-control@ietf.org
DKIM-Signature: a=rsa-sha256; bh=g3DEXuUC64IMqSFs4tQh3kpGMe4OcJenYt18T/PxH+w=; c=simple/simple; d=copyright.sh; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1787207393; v=1; x=1787812193; b=WUl30mqrVLvC7FbZp4kpiQA3bPNptXioo3U+PoqLDubXP6b2yiyHEGZ3C2osWFuzk+kdL36/ uszpJEGF94UIZcUhlAmSex4yW4kFMkUBmMjdmyHd1zssSMXPczQ7R+CnMWmrp4X6mt7BNfx72Fw +mBu5vw1OGghi/koY7V6ZsaPkhsTSKq459KqaJNFvlBOtV4cZJF5FG8m/OTid/UUUJ+oLt+lbie 5qj31m5Er370eOAtEie9uEfCbCN6Z4g2kT90BcZUWRR/nVEi6ahzvqN5IawKMD4fTORfeFWgFNz T5KYIkuqpGvdtyJLOPrlrf2EnOwShbX3AYrp5IUGM9+zQ==
X-Envelope-To: ai-control@ietf.org
Received: from smtpclient.apple (136.25.154.160) by smtp.migadu.com with ESMTPS id 3c3d349f6fbd3697; Thu, 20 Aug 2026 06:29:53 +0000
X-Mizu-Trace-ID: 3c3d349f6fbd3697
X-Migadu-Flow: FLOW_OUT
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3864.600.51.1.1\))
From: Tyler Martin <tyler@copyright.sh>
In-Reply-To: <b75d7072-e0b0-49c4-ac59-e04ef4f96f5c@app.beta.fastmail.com>
Date: Wed, 19 Aug 2026 23:29:36 -0700
Content-Transfer-Encoding: quoted-printable
Message-Id: <DEC6BB32-C63B-4FC8-9B46-E019B18E4C30@copyright.sh>
References: <CA++fB=qZVce-mDjYHPziW2W7dGyvcGDmqNdcS559Q6TfvshjCQ@mail.gmail.com> <CAHAi=4x=o=qA5+fkOo=RfcArT9BJE4xPBisiBpXvNGkt+6=1wA@mail.gmail.com> <CA++fB=o0x5smnht+sRBnD+0N5Pzc229SbWVT-ui=2c=nNWwrYA@mail.gmail.com> <CAE+sOj=C7zKcSBLP0RsE3nGU7H90O2S0QWsL5XA=Fjft1=YQcQ@mail.gmail.com> <7027F6ED-0B24-40CC-B066-12BDB7B0457C@edrlab.org> <CABQM+Ay4REiQ_6wK9jsM=OSYUXQQsMnQ_dW+JjVCiBnehNcNfQ@mail.gmail.com> <46AA463D-607F-4531-BA28-1313B24BCF17@cooperw.in> <CA++fB=qFTjAo=cb+-cTdL2Cz3K2Cr53aV6hO_Pjhee8+7tRwdQ@mail.gmail.com> <E64AFF37-AD44-4FEA-9F0C-E2B3678E91F0@kuehlewind.net> <CA++fB=pM=eGnXwVvXNgAKeJ+ToGqDkAxcSCvubLtcLURgW1upg@mail.gmail.com> <CH8PR02MB1097029104D91FA84D374BA9FCDD12@CH8PR02MB10970.namprd02.prod.outlook.com> <CAE+sOjkz1MjXvyn=mgV9J0iqgJLWERgsqJpmuvrOMjjkT2m3aQ@mail.gmail.com> <CH8PR02MB10970CDF4523400C76D81052ACDD12@CH8PR02MB10970.namprd02.prod.outlook.com> <CAE+sOjk8XCdiaBdQXHMRKa61Z0yArz_B__xXik0auu17+gWtjw@mail.gmail.com> <CH8PR02MB10970CD9C54377F5C7CCF84DDCDDE2@CH8PR02MB10970.namprd02.prod.outlook.com> <CA++fB=qSnS8y9VmY+vrYmW2q_ihG4egbLVCD1DA_JWAQZVRWLQ@mail.gmail.com> <PH0PR01MB7521DC2BBA9CE9A426908BA2BADC2@PH0PR01MB7521.prod.exchangelabs.com> <CA++fB=qp0YbL3kDScULKpbMwiYpOGbbCCv+pUBbDRWfdRVfFmQ@mail.gmail.com> <82A42F74-19B2-4C47-8CC0-80CD1C1B941D@kuehlewind.net> <CA++fB=qJGBKDpeOheLfaek8XvAfheLD1D0pNB-G-85=mWhohEg@mail.gmail.com> <2DBC3698-49AF-4F14-96BA-F903B4438936@kuehlewind.net> <CA++fB=pjkBBOVDVd3S3RU5QZzatN0pTN_2ck8ngz5Etp5ryd+A@mail.gmail.com> <8157EEB7-9A48-4CD1-8A0A-39611DD6B0C5@kuehlewind.net> <CA++fB=pTJceAgs3jUB3C5LgCZpUCZUd7bmKhv7nuQSiBHSX07Q@mail.gmail.com> <DD8E56F3-7F3F-4957-88ED-34152C92F4FA@kuehlewind.net> <4BFE4B81-BA68-41E5-8093-34BC3D4C179B@openfuture.eu> <4B6C5C56-28D4-4FA3-95FD-ACCD67A87C78@kuehlewind.net> <CH8PR02MB109702454859619D9A02DDCEBCDA62@CH8PR02MB10970.namprd02.prod.outlook.com> <7471B930-0FA5-4C13-98DF-303793422F3E@kuehlewind.net> <IA1PR02MB10983B3FE5159DD77F2784DC9CDA52@IA1PR02MB10983.namprd02.prod.outlook.com> <40895F1C-453D-481C-905A-BDA9CD5B86C6@kuehlewind.net> <IA1PR02MB1098306D1CA492C76B61E19B1CDA52@IA1PR02MB10983.namprd02.prod.outlook.com> <487E489A-6C37-43DD-9D57-8584EDF399AC@kuehlewind.net> <CA++fB=p01rQ0-immNR-jzxQ5x3f72xDzDNFpPveJ=3L1pFxfVA@mail.gmail.com> <8614497a-8105-433c-9ea9-6dc1053db13b@app.beta.fastmail.com> <289B1A10-BBEF-49B7-890F-A76A70282952@copyright.sh> <CALtcm6THhR5+wx2jJ4+hpS5==peJYpU48u_jr4BQogQpy7bseA@mail.gmail.com> <62A8F670-97D3-47B6-A841-3D34A11E2D0B@copyright.sh> <b75d7072-e0b0-49c4-ac59-e04ef4f96f5c@app.beta.fastmail.com>
To: Martin Thomson <mt@lowentropy.net>
X-Mailer: Apple Mail (2.3864.600.51.1.1)
Message-ID-Hash: HLA5PHN326AOIS2XEJROZTQPI4HZIYHP
X-Message-ID-Hash: HLA5PHN326AOIS2XEJROZTQPI4HZIYHP
X-MailFrom: tyler@copyright.sh
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Eric Rescorla <ekr.ietf@gmail.com>, Nate Hake <nate@travellemming.com>, "ai-control@ietf.org" <ai-control@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [ai-control] Re: Proposed "AI System Inference" and "AI User Input" categories
List-Id: AI Control <ai-control.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ai-control/5rvm7R1Ry1D8gUcGyRLPhvDIQzY>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ai-control>
List-Help: <mailto:ai-control-request@ietf.org?subject=help>
List-Owner: <mailto:ai-control-owner@ietf.org>
List-Post: <mailto:ai-control@ietf.org>
List-Subscribe: <mailto:ai-control-join@ietf.org>
List-Unsubscribe: <mailto:ai-control-leave@ietf.org>

Right, from the outside the two systems look similar. But I don't think the vocabulary can assume anything about what's observable from outside a system. Policy and infrastructure get built on these definitions, so they should attach to what is possible, not known. Let the individual players make decisions around use and transparency as they may, then let the courts decide. 

> 1. infer(train(X + other_training_data), inference_inputs)
> 2. infer(train(training_data), X + other_inference_inputs)


On your two cases: in case 1, X is used once and its value persists in the weights, reaching every future answer with no further event. In case 2, X is used every time, and each use is an event that can be counted and revoked. A publisher who changes their preference tomorrow reaches tomorrow's context window and never yesterday's weights. That's the difference in kind, and it's why they deserve separate declared preferences even when the outputs look alike.

The wasteful part is the interesting part for publishers. The per-use cost of case 2 is what makes a per-use market possible and arguably necessary for fair compensation models.

Tyler

> On Aug 19, 2026, at 10:17 PM, Martin Thomson <mt@lowentropy.net> wrote:
> 
> It seems like you are missing the thrust of Ekr's queries here, which are to highlight that the distinction between training and inference is not strictly treating the system as opaque.
> 
> If you can excuse something that looks like code, the effect is that the following two things are hard to distinguish from the outside:
> 
> 1. infer(train(X + other_training_data), inference_inputs)
> 2. infer(train(training_data), X + other_inference_inputs)
> 
> Your point about where the intermediate outputs end up is perhaps why the two aren't identical, just similar.  That the model is then used for many things is perhaps where the concern comes from, whereas putting X into the context window every time is sufficiently wasteful that there is a difference in degree.
> 
> On Thu, Aug 20, 2026, at 12:43, Tyler Martin wrote:
>> One sentence we can/should add to the training 
>> definition to close it:
>> 
>> "Using outputs generated from an asset during inference in the 
>> production or refinement of a model is use of that asset under this 
>> category."
>> 
>> The alternative, documenting that train-ai=n doesn't reach synthetic 
>> data, would just be publishing the workaround.
> 
> I'm not sure that this is necessary.  Though it can get complicated. If your concern is that distillation is not considered train-ai usage, then that depends on selectively looking at scopes.  
> 
> In the example, the teacher is running inference and the student is training.  The overall process is training AI and it takes the asset as an input.
> 
> Inference excludes training already, so it would not apply in this scenario if your scope is the overall training process.  Unless you change the scope over which you look to only include the teacher model and its use of the asset for inference.
> 
> Of course, we hear that some labs are concerned that their inference is being used in distillation to train other models.  If they are ignorant of this possibility, that leads to a problem: do they have to consider train-ai when it comes to their inference?  (Most have terms of use that prohibit distillation, so maybe they can make this a responsibility of their customers.)
> 
> Some language to clarify this would seem to be helpful if we pursue one or more inference definitions.  My guess is that it need not be directly normative, but more explanatory in nature.