You can structure it so that it becomes accidental.
1. Ensure security barriers are weak or honor based.
2. Put individual researchers under a lot of pressure.
3. If you get caught, blame the weak barriers, or the individual researcher.
Basically setup the incentive structure to incentivize researchers sticking their mittens in the private cookie jar while putting the cookie jar in a dark unmonitored/unsecured room with a sign on the door saying please don't enter.
Yeah, the steps follow exactly what happened at VW with DieselGate. The diesel emissions lies were found out because some enterprising person set up an emissions testing system and drove the car in real world scenarios with it to verify the claimed emissions.
There's no reliable way to verify a foundation model has been trained on a particular piece of proprietary data. If an API key is ingested, hopefully the foundation model is wrapped in enough moderation that the raw API key oberserved during training is not recited verbatim in the output.
Not trying to be rude, but do you work in tech? I can't imagine presenting this as a plan of record in a design review. And the world runs on good faith. If you call a pharmacy, claim to be some doctor, leave a voice mail, and give their (public) NPI number, there is no validation.
Why aren't people calling in prescriptions for themselves? I guess it just kinda runs on trust me bro and the threat of being put in prison.