From 94f6fded13c08d4826331ad67821c9758199dfbb Mon Sep 17 00:00:00 2001 From: inference-bot Date: Wed, 9 Sep 2026 14:10:04 -0600 Subject: [PATCH] Add open-questions.md: living list of governance decisions for member discussion --- README.md | 2 +- open-questions.md | 94 +++++++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 95 insertions(+), 1 deletion(-) create mode 100644 open-questions.md diff --git a/README.md b/README.md index 99df3de..87cf875 100644 --- a/README.md +++ b/README.md @@ -60,7 +60,7 @@ Because Tinfoil requires EHBP-encrypted request bodies (it rejects plaintext wit ## Governance -Members govern the project through [Loomio](https://www.loomio.com) and the Open Collective. See the [Charter](charter.md) for the cooperative's values, membership terms, and governance structure. +Members govern the project through [Loomio](https://www.loomio.com) and the Open Collective. See the [Charter](charter.md) for the cooperative's values, membership terms, and governance structure, and [Open Questions](open-questions.md) for the decisions currently open for member discussion. During the pilot phase, Nathan Schneider serves as Managing Director and has sole final discretion on decisions. diff --git a/open-questions.md b/open-questions.md new file mode 100644 index 0000000..423400f --- /dev/null +++ b/open-questions.md @@ -0,0 +1,94 @@ +# Open Questions for Member Discussion + +A living list of decisions the cooperative needs to make. Each question is framed for discussion on [Loomio](https://forum.inference.coop). As questions are resolved, they move to a "Decisions" log (to be created) rather than being deleted. + +--- + +## Privacy & Infrastructure + +### 1. Search: self-managed or Tinfoil's encrypted search? + +We currently run our own [SearXNG](https://searxng.github.io/searxng/) instance (`search.inference.coop`) to power web search in the chat. Tinfoil also offers a `websearch` model — a private, encrypted search that runs inside their enclave. + +- **Self-managed (SearXNG):** full control, no external dependency, but search queries are visible to our own infrastructure (and to the search engines SearXNG queries). +- **Tinfoil's encrypted search:** queries are encrypted end-to-end, but it's a third-party dependency and may cost per-query. + +**Question:** Do we prioritize self-hosting (control, no external deps) or encrypted search (stronger privacy, but a dependency on Tinfoil)? + +### 2. Green energy vs. privacy — when we can't have both? + +Our inference runs through Tinfoil (TEE-protected, verifiable privacy), but Tinfoil's energy mix is not disclosed. Self-hosting on renewable-powered hardware (e.g. Hetzner hydropower, Scaleway wind+hydro) would be greener but would lose the TEE privacy guarantee at our current scale. + +- **Privacy-first (current):** TEE inference, energy mix unknown. +- **Green-first:** renewable hosting, but policy-based privacy (we *promise* not to read data, but can't *prove* it architecturally). + +**Question:** When the two conflict, which value wins? Is there a threshold (e.g. member count, cost) at which we'd switch? + +### 3. Should we adopt Tinfoil's other models (embeddings, private search, audio)? + +Tinfoil's catalog includes `nomic-embed-text` (embeddings), `websearch` (private search), and audio models (Whisper, TTS). We currently use Open WebUI's bundled local embedding model for file uploads. + +**Question:** Do we standardize on Tinfoil for all model needs (consistency, privacy), or keep the local embedding model (no per-token cost, no dependency)? + +--- + +## Pricing & Fairness + +### 4. How should pricing account for unequal usage? + +Members currently pay a flat $15/month for a $15/month credit budget. But usage is unequal — some members use far more tokens than others. + +- **Flat (current):** simple, predictable, but heavy users subsidize light users (or vice versa). +- **Usage-based:** pay for what you use, but unpredictable and may discourage experimentation. +- **Tiered:** a few usage bands, balancing simplicity and fairness. +- **Sliding-scale + usage cap:** pay what you can afford, with a shared usage ceiling. + +**Question:** What pricing model best balances fairness, simplicity, and the cooperative's solidarity values? How do we handle a member who consistently exceeds their budget? + +### 5. What happens when a member's budget runs out mid-month? + +Currently LiteLLM enforces the $15 budget cap — requests stop when it's exhausted. + +**Question:** Should members be able to top up? Should there be a grace period? Should the co-op pool surplus to cover light users? + +--- + +## Governance & Membership + +### 6. What does "member-governed" mean in practice before 50 members? + +The charter says the General Manager (Nathan) has full governance until 50 members, then transitions to member governance. But members can already deliberate on Loomio. + +**Question:** Which decisions should be opened to member input *now* (even if non-binding), versus reserved for the General Manager during the pilot? + +### 7. How do we handle institutional members? + +AI Potluck's "government-as-contributor" framing suggests a path for institutions (universities, municipalities) to contribute compute or data without owning the whole. + +**Question:** Should we create an institutional membership tier? What would institutions contribute, and what would they get? + +### 8. What's our stance on the "coalition vs. cooperative" question? + +We're a cooperative (member-owned, formal bylaws, accountable). AI Potluck is a coalition (no single owner, maximally resilient, but no one to hold accountable). + +**Question:** Is the cooperative model the right long-term structure, or should we explore hybrid forms (e.g. a cooperative that federates with other co-ops)? + +--- + +## Values & Product + +### 9. Should we adopt "provenance transparency" as a product feature? + +AI Potluck commits to "every response shows its provenance: the model, the organization, the compute, the country." We could surface which model served each response (already possible via LiteLLM). + +**Question:** Is this worth building? What's the right level of transparency without cluttering the chat? + +### 10. Should we articulate an "anti-engagement" stance? + +AI Potluck explicitly rejects the extractive engagement model ("AI that wants you to turn it off," "doesn't sell you sycophancy"). A cooperative has no engagement-maximization incentive — a structural advantage. + +**Question:** Should we name this explicitly in our charter and product copy? What does "AI for human flourishing, not engagement" mean concretely for our chat? + +--- + +*This list is maintained in the [docs repository](https://git.inference.coop/co-op/docs). Add questions via pull request or raise them on [Loomio](https://forum.inference.coop).*