Files
docs/open-questions.md
T

101 lines
5.8 KiB
Markdown

# Open Questions for Member Discussion
A living list of decisions the cooperative needs to make. Each question is framed for discussion on [Loomio](https://forum.inference.coop). As questions are resolved, they move to a "Decisions" log (to be created) rather than being deleted.
---
## Privacy & Infrastructure
### Search: self-managed or Tinfoil's encrypted search?
We currently run our own [SearXNG](https://searxng.github.io/searxng/) instance (`search.inference.coop`) to power web search in the chat. Tinfoil also offers a `websearch` model — a private, encrypted search that runs inside their enclave.
- **Self-managed (SearXNG):** full control, no external dependency, but search queries are visible to our own infrastructure (and to the search engines SearXNG queries).
- **Tinfoil's encrypted search:** queries are encrypted end-to-end, but it's a third-party dependency and may cost per-query.
**Question:** Do we prioritize self-hosting (control, no external deps) or encrypted search (stronger privacy, but a dependency on Tinfoil)?
### Green energy vs. privacy — when we can't have both?
Our inference runs through Tinfoil (TEE-protected, verifiable privacy), but Tinfoil's energy mix is not disclosed. Self-hosting on renewable-powered hardware (e.g. Hetzner hydropower, Scaleway wind+hydro) would be greener but would lose the TEE privacy guarantee at our current scale.
- **Privacy-first (current):** TEE inference, energy mix unknown.
- **Green-first:** renewable hosting, but policy-based privacy (we *promise* not to read data, but can't *prove* it architecturally).
**Question:** When the two conflict, which value wins? Is there a threshold (e.g. member count, cost) at which we'd switch?
### Should we adopt Tinfoil's other models (embeddings, private search, audio)?
Tinfoil's catalog includes `nomic-embed-text` (embeddings), `websearch` (private search), and audio models (Whisper, TTS). We currently use Open WebUI's bundled local embedding model for file uploads.
**Question:** Do we standardize on Tinfoil for all model needs (consistency, privacy), or keep the local embedding model (no per-token cost, no dependency)?
### Which models should we offer?
We currently expose three chat models: DeepSeek V4 Flash (default), GPT-OSS 120B, and GLM-5.3 Flash. Tinfoil's full catalog also includes GLM-5.3 (full), Kimi K3, Llama 3.3 70B, Gemma 4 31B, and others.
**Question:** Which models should members have access to? Should we offer a curated few (simpler, cheaper, easier to govern) or the full catalog (more choice, but more cost and governance overhead)? Who decides when to add or remove a model — the General Manager, or members via Loomio?
### Should personal data be collectively or individually managed?
Currently chat history is stored on co-op servers. We could potentially switch to storing it in browser cache, which would be more private but less convenient. How do we balance privacy and convenience?
### Should we prioritize running and owning our own infrastructure, or are we comfortable collectively buying tokens from others?
---
## Pricing & Fairness
### How should pricing account for unequal usage?
Members currently pay a flat $15/month for a $15/month credit budget. But usage is unequal — some members use far more tokens than others.
- **Flat (current):** simple, predictable, but heavy users subsidize light users (or vice versa).
- **Usage-based:** pay for what you use, but unpredictable and may discourage experimentation.
- **Tiered:** a few usage bands, balancing simplicity and fairness.
- **Sliding-scale + usage cap:** pay what you can afford, with a shared usage ceiling.
**Question:** What pricing model best balances fairness, simplicity, and the cooperative's solidarity values? How do we handle a member who consistently exceeds their budget?
### What happens when a member's budget runs out mid-month?
Currently LiteLLM enforces the $15 budget cap — requests stop when it's exhausted.
**Question:** Should members be able to top up? Should there be a grace period? Should the co-op pool surplus to cover light users?
---
## Governance & Membership
### What does "member-governed" mean in practice before 50 members?
The charter says the General Manager (Nathan) has full governance until 50 members, then transitions to member governance. But members can already deliberate on Loomio.
**Question:** Which decisions should be opened to member input *now* (even if non-binding), versus reserved for the General Manager during the pilot?
### How do we handle institutional members?
AI Potluck's "government-as-contributor" framing suggests a path for institutions (universities, municipalities) to contribute compute or data without owning the whole.
**Question:** Should we create an institutional membership tier? What would institutions contribute, and what would they get?
---
## Values & Product
### Should we adopt "provenance transparency" as a product feature?
AI Potluck commits to "every response shows its provenance: the model, the organization, the compute, the country." We could surface which model served each response (already possible via LiteLLM).
**Question:** Is this worth building? What's the right level of transparency without cluttering the chat?
### Should we articulate an "anti-engagement" stance?
AI Potluck explicitly rejects the extractive engagement model ("AI that wants you to turn it off," "doesn't sell you sycophancy"). A cooperative has no engagement-maximization incentive — a structural advantage.
**Question:** Should we name this explicitly in our charter and product copy? What does "AI for human flourishing, not engagement" mean concretely for our chat?
---
*This list is maintained in the [docs repository](https://git.inference.coop/co-op/docs). Add questions via pull request or raise them on [Loomio](https://forum.inference.coop).*