You used the model. The model did not get to keep you. That is the difference.
Running an AI model on terms that prevent the model's operator from retaining, logging, or training on your inputs and outputs. The inference happens, the response returns, but the operator cannot fold your prompt, your hesitation, your emotional state, or your data into its training corpus or its surveillance dividend. The engage-don't-abstain posture: you use the tool, but you use the version that does not make you the raw material. This is the inference-layer equivalent of running a local model on a laptop — not purity, not surrender, just using the best available tool on terms that do not feed extraction. The demand is not 'do not touch the machinery.' The demand is 'touch it on terms that do not feed the surveillance dividend.'
Truth-adjacency
Truth-independent: the pattern works regardless of whether the claim is true
Where it shows up
Platforms and algorithms
The phrases and tells that mark this pattern in the wild:
an AI tool that processes your input without retaining it for trainingencrypted prompts that the operator cannot read in plaintexta model usage policy that prohibits logging of inputs and outputsinference that happens in a TEE or under encryption the operator cannot breakthe tool works, but the operator cannot build a profile of you from using itThe tell is what the operator cannot do. Encrypted inference reveals itself when the AI service processes your input but cannot retain it, cannot log it, cannot train on it, and cannot build a profile of you from the interaction. The inference happens. The retention does not. The distinction is between transport encryption (the wire is protected, the server is not) and inference encryption (the server cannot read what it is processing).
Watch for the retention policy. A service that encrypts your prompt in transit but stores it in plaintext server-side for analytics, debugging, or model improvement is not encrypted inference. The protection must extend to the server, not just the network. The strongest forms use trusted execution environments (TEEs) or fully homomorphic encryption, so the operator processes the input without ever seeing it in plaintext. Weaker but still meaningful forms have enforceable no-retention policies with independent audit.
Also watch the training pipeline. If the service’s terms allow training on your inputs, it is not encrypted inference regardless of what happens in transit. The surveillance dividend is collected at training time. The protection must close that pipe.
You call “encrypted inference” on a cloud AI service because it uses HTTPS. Transport encryption protects the wire. It does not protect the warehouse. If the service receives your prompt over an encrypted connection and then stores it in plaintext on its servers, logs it for analytics, or feeds it into training data, the inference was transport-encrypted and server-plaintext. The operator can still read your input, retain it, and profit from it. The pattern requires the operator to be unable to read or retain the inference inputs, not just unable to intercept them on the network. If the server can see your prompt, you are looking at HTTPS, not encrypted inference.
How this pattern gets misused
Someone treats any cloud AI service as encrypted inference because it uses HTTPS in transit. The term becomes a blanket reassurance that covers services that encrypt the network layer but retain plaintext prompts server-side for training, logging, or analytics. Indiscriminate use makes the genuine protection — the operator cannot read or retain the inference inputs — harder to distinguish from ordinary transport encryption, which protects the wire but not the warehouse.
What it looks like when you're wrong about it
A cloud AI service that uses TLS for transit but stores prompts in plaintext on its servers, logs them for analytics, or retains them for model improvement, is not encrypted inference. It is transport-encrypted inference with server-side plaintext retention. The pattern requires the operator to be unable to read or retain the inference inputs, not just unable to intercept them on the network. If the operator can read your prompts after they arrive, you are looking at HTTPS, not encrypted inference.
Not sure? Describe the situation to someone outside it. If they do not see the pattern, pause before you name it.
Surveillance dividend
You are not the customer. You are the raw material, and your behavior is the ore.
Affect surveillance
It read your face before you finished speaking. The reading was not for your benefit.
Training data extraction
The model remembered what it was fed. What it was fed was you.
Retroactive encryption
The archive was built in plaintext because no one expected you to read it. Encrypt it anyway. The lever is not delete. They won't.
The name is designed to spread. The hook is designed to stick. If you recognized something, share the name.