Encrypted AI: The Tool That Does Not Keep You
Evidence-first pattern recognition. Sourced to reputable reporting.
The Pattern
The suspicion of AI is correct. The companies building the most powerful systems are not neutral actors. They have shareholders, lobbying budgets, and a structural interest in framing their product as inevitable. The FTC had to launch Operation AI Comply because companies were lying about what their AI did. One firm was selling “AI” that was resold email lists. The lying is documented. The suspicion is the correct reading of who owns the machinery and what the machinery is for.
The suspicion is also not a strategy.
Suspicion does not write a bill. Suspicion does not organize a workplace. Suspicion does not build the tool a tenant organizer uses to scan a thousand leases in an afternoon for illegal clauses, which a tenant organizer I know is now doing with a model she runs on a laptop. Suspicion does not train the model a public defender’s office uses to draft motions faster so the office can take more cases.
The question is not whether to use AI. The question is on what terms.
The difference
Most AI services keep your prompts. They store them server-side. They log them for analytics. They feed them into training data. The prompt arrives over an encrypted connection — HTTPS, TLS, the padlock in the browser bar — and then sits in plaintext on the operator’s server, where the operator can read it, retain it, and profit from it. The wire was protected. The warehouse was not.
This is the pattern named surveillance dividend. You are not the customer. You are the raw material. Every prompt you send, every hesitation the model can infer from your typing rhythm, every question that reveals what you are working on — all of it becomes the operator’s data. The data becomes the training corpus. The training corpus becomes the next model. The next model is sold back to you. You paid for the service with your behavior. The dividend was the gap between what you thought you were doing and what was being done with the record of you doing it.
Encrypted inference is the different path. The prompt is encrypted before it reaches the model. The model processes it inside a trusted execution environment — a sealed piece of hardware the operator cannot peer into. The output returns to you. The operator retains nothing. No prompt. No log. No training data. No profile. The tool did the work. The operator got nothing.
That is the difference between engaging the infrastructure and feeding it.
The engage-don’t-abstain posture
The purity test says: do not touch it, and if you do touch it you are contaminated. The purity test does not win infrastructure fights. The side that builds the infrastructure writes the rules. The side that refuses to engage spends the next decade filing comments with an agency the other side captured.
The engage-don’t-abstain posture says: use the tool, but use the version that does not make you the raw material. Encrypted AI tools — Lumo and others built on the same principle — let you run the model without feeding the dividend. The inference happens. The retention does not. You get the output. The operator gets ciphertext. The EFF’s position is that encryption is a human rights issue. The inference-layer application of that principle is the demand: you may provide the inference, but you may not keep the record of me using it.
This is the inference-layer equivalent of the tenant organizer’s local model. She runs the model on her laptop. The model never sees the cloud. The leases never leave her machine. The tool did the work. No one got a dossier of every lease she scanned. She engaged the infrastructure rather than abstaining from it, on terms that did not feed extraction.
Encrypted inference is the same logic at the cloud layer. You cannot run a frontier model on a laptop — the compute is too large, the model is too heavy. But you can run it inside a trusted execution environment that the operator cannot read into. The model is in the cloud. Your prompt is not. The output returns. The operator retains nothing. The engagement is real. The extraction is refused.
What the operator cannot do
The tell is what the operator cannot do. An encrypted inference service processes your input but cannot retain it, cannot log it, cannot train on it, and cannot build a profile of you from the interaction. The inference happens. The retention does not.
This is not HTTPS. HTTPS protects the wire. It does not protect the warehouse. A service that receives your prompt over an encrypted connection and then stores it in plaintext on its server is transport-encrypted and server-plaintext. The operator can still read your input, retain it, and profit from it. The padlock in the browser bar protected the transit. It did not protect the destination.
Encrypted inference protects the destination. The operator processes the prompt without seeing it in plaintext. The output returns without the operator retaining the input. The wire was protected. The warehouse was protected. The dividend was refused.
The suspicion that remains
Using encrypted AI does not dissolve the suspicion. The companies building the models are still not neutral actors. The labor threat is still documented — Anthropic’s CEO told Axios AI could wipe out half of entry-level white-collar jobs. The environmental cost is still documented — PBS/AP found AI data centers rival nations in energy and water consumption. The surveillance dimension is still the one the left should be loudest about and is somehow the quietest on.
Encrypted inference does not fix the labor displacement. It does not fix the environmental cost. It does not fix the concentration of compute power in the hands of three or four firms. What it fixes is the extraction layer. It refuses the dividend. It says: you may provide the inference, but you may not keep the record of me using it.
That is not everything. It is not nothing. It is the difference between using a tool and being used by one.
Patterns in this piece
Encrypted inference
You used the model. The model did not get to keep you. That is the difference.
Surveillance dividend
You are not the customer. You are the raw material, and your behavior is the ore.
Affect surveillance
It read your face before you finished speaking. The reading was not for your benefit.