Plain Strata logo

Plain Strata

Archives
Listen
Log in
Subscribe
August 11, 2026

The price of privacy

Plain Strata Plain Strata

Hi,

Somewhere there is a bridge with a toll on it. The toll is not a measurement of what the bridge cost to build. It is a measurement of whether there is another way across the river.

Last week a frontier lab printed a toll on your privacy. The same coding model at two prices, and the only difference between them is one sentence about whether the company may train on what you type. Say yes and it is twelve and a half times cheaper going in.

Everyone already knew that trade existed. It has been sitting in settings pages as a checkbox for three years, and a checkbox has no price. Now it has one, published by the company doing the reading, and the number turns out to be large.

Then you go looking for the other side of the market, the people selling the opposite promise, and you find a price list where privacy does not appear as a line at all. Not discounted. Absent, because there is no version of the product without it.

So the question this week is not what privacy costs. It is what a toll tells you, and what it means when somebody builds a ford downstream.

Listen:

Spotify: https://open.spotify.com/episode/4p93gpw8WV7C9mLFVxxywc

Apple Podcasts: https://podcasts.apple.com/kg/podcast/plain-strata/id6783455764?i=1000782706695

YouTube: https://youtu.be/hVwF8wojjg0


The full piece, no need to click through:

On August 5, Meta put a coding model on sale at two prices.

The model is the same model either way. Same weights, same answers, same servers. The standard price is one dollar twenty-five per million words of input and four dollars twenty-five per million words of output. The other price is ten cents and twenty cents. That is twelve and a half times cheaper going in and twenty-one times cheaper coming out, for the identical thing, and the only difference is one sentence in the terms: on the cheap tier, Meta may train future models on your prompts and on the answers it gave you.

Nobody had ever printed that number before. Everyone knew the trade existed. Every free tier of every assistant has been running some version of it for three years. But it sat in a settings page as a checkbox, and a checkbox has no price. This week it has one, published by the company doing the reading, and the number turns out to be large.

That is this week's story, and the useful half of it is not Meta. It is what happens when you take that number and go looking for the other side of the market, the people selling the opposite promise. Because they are there, they have been there since last winter, and their price for it is nothing at all.

Start with the physical picture, because the abstraction hides the whole problem.

You type a question. Your words get turned into numbers, encrypted, and sent down a wire to a building you will never visit. At the far end they arrive at a computer with a graphics card in it, and to do anything useful with them, that computer has to decrypt them. It has to. A model cannot think about a message it cannot read. So for the second or two that your question is being answered, your words are sitting in the plain, in the working memory of a machine somebody else owns.

Encryption in transit protects your words on the wire. Encryption at rest protects them on the disk. Neither one covers the moment in the middle, when the data is in use. That moment is the entire subject of this episode, and it is the moment every privacy promise in AI is currently a promise about. Not a mechanism. A promise. The provider says: we could look, and we do not.

Meta just told you what that promise is worth to them. Twelve and a half times the input price.

Now the other side. There is a service called Chutes, which runs as subnet 64 on Bittensor, a network where anyone can plug machines in and get paid for doing AI work without asking a company for permission. Their published price list has thirteen models on it. Open weight models, the kind anyone can download: Qwen, DeepSeek, Gemma, Kimi. Prices from about two cents per million words of input up to three dollars for the largest.

Look at the model names and you find something odd. Every single one ends in the same four characters: dash T E E. Gemma dash T E E. DeepSeek dash T E E. Kimi K3 dash T E E. There is no other version. There is no cheaper tier where you drop the suffix and save money.

TEE stands for trusted execution environment, and what it means in the room is this. The graphics card and the processor running your question sit inside a sealed region of the machine whose memory is encrypted with a key that only the processor itself holds. The operating system cannot read it. The person who owns the building cannot read it. Someone who breaks in and takes total control of the machine cannot read it, because the thing that would let them read it, the key, was never handed out. The industry's word for the sealed region is an enclave, from the French enclaver, to lock in, from the Latin clavis, a key. An enclave on a map is a piece of one country's land completely surrounded by another country's. That is exactly the shape here: a small territory inside a machine, sitting in someone else's building, that the building's owner has no jurisdiction over.

Then the second half, which is the half that makes it worth anything. A sealed room you cannot inspect is not obviously better than an unsealed room, because how would you tell the difference? So before your question goes in, the machine hands you a signed statement describing itself: this is the chip I am, this is the exact software I booted, here is the fingerprint of every piece of it. The signature comes from a key burned into the silicon at the factory, which means a machine that is not what it claims cannot produce the signature. The word is attestation, from the Latin testis, a witness, the same root as testify. The machine bears witness about itself, and the witness cannot lie because the pen belongs to the chip.

That is as far as we need to go. The mechanics of how those measurements are taken and checked are a proper subject on their own. What matters here is the shape: the guarantee is not a policy, it is a fact about the hardware, and you can check it yourself before you send anything.

And on that price list, it costs zero. Not zero dollars for the compute, obviously, you pay per word like anywhere else. Zero as a premium. There is no line item for privacy, because there is no product without it.

Here is the turn, and it is the reason this is a story about decentralized AI rather than a story about a discount.

The people running those machines are anonymous. Anyone can join Chutes as a miner. There is no application, no company, no vetting, no legal entity with a reputation to lose. The operators write it plainly in their own documentation: the network is designed for an adversarial world, miners are anonymous and permissionless, so security cannot be trust me, it has to be verify.

Read that again as an economic statement rather than a security one. A centralized provider can sell you privacy as an upgrade because it can also sell you the absence of privacy, and the absence is cheaper to deliver. That is what a two tier price list is: proof that trust me was available, and that they were willing to be paid to stop asking for it.

A permissionless network cannot do that. There is no us. There is a rotating cast of strangers whose names nobody knows, and no promise any of them makes about your data is worth the electricity to transmit it. So the network had two options: build the proof into the floor, or have no product at all. It built the proof into the floor. And once a guarantee is the floor, it stops being sellable. You cannot charge extra for something the customer would otherwise get for free from the physics of your own design.

That is why one company can charge twelve and a half times for privacy and the other charges nothing. Not generosity, and not superior ethics. Structure.

This shape has a name worth carrying, because it shows up whenever a system is built for a world where nobody can be trusted, and it always ends the same way. Call it the hostile default. When you cannot assume a trustworthy operator, the protection stops being a feature and becomes part of the foundation, and a foundation has no price tag.

The oldest version most people have lived through is the little padlock in a web browser. In the nineteen nineties, an encrypted connection was a premium product. Certificates cost real money, you had to prove who you were to buy one, and so encryption was reserved for checkout pages. Everything else travelled in the clear, because the web assumed a mostly friendly network. Then the assumption broke, publicly and repeatedly, and by the mid twenty tens certificates were free and automatic and browsers started marking unencrypted pages as unsafe. The premium became the floor. Nobody sells you the padlock now; they sell you a website, and the padlock comes with it, because the alternative stopped being offerable.

The confidential compute tier in decentralized AI is at the same hinge, arriving from the same direction: not because someone decided privacy was important, but because the network's own design made the friendly assumption unavailable from day one.

Three things cut against the clean version, and the third is the one that matters most.

First, the machine is sealed against its owner, not against itself. The operators of that network say this out loud in their own writeup: a sealed enclave protects you from the host, but it does not protect you from bad code running inside the enclave. If the program in the room is quietly writing your prompts to a file, the walls are working perfectly and you are still being read. Their answer is a stack of other things, signed builds, random spot checks against the running code, blocking the machine's outbound network traffic by default. That is defense in depth, which is real engineering and is not a proof.

Second, the trust did not vanish, it moved. The signature on the attestation comes from a key that Intel or NVIDIA burned into the chip. You are no longer trusting an anonymous operator. You are trusting a chip vendor, and behind it, a supply chain. That is a much smaller and more specific thing to trust, and it is checkable in a way a promise is not. It is also, unmistakably, a central party in a system that exists to remove central parties.

Third, the price comparison is not apples to apples and should not be sold as one. Meta's two prices are for one proprietary frontier model. The confidential list is open weight models on subsidized hardware, and a token network's prices tell you about its token as well as about its costs. The claim that survives all of that is narrow and still worth having: on one list, privacy has a price, and on the other list, privacy does not appear as a line at all.

The implication is a lens you can use on any provider from now on. The price of privacy is a measurement of how much trust a seller can still get away with asking for. When it is high, it means the customer has no alternative but to believe them. When it falls to zero, it usually means somebody made believing unnecessary.

The open question is the one Meta accidentally handed the entire confidential compute field, and nobody has answered it. Is privacy worth twelve and a half times to anybody? The verifiable and confidential side of this industry has been publishing supply numbers for a year: proofs generated, inferences attested, models migrated. Those count how much of the thing exists. None of them counts anybody paying a premium for it, and now there is finally a number to be measured against. If it turns out that almost everyone takes the cheap tier, then the most technically impressive part of this stack is an answer to a question the market was not asking, and that would be worth knowing early rather than late.

Whether any confidential inference provider publishes a demand number rather than a supply number: paid volume on the private tier, not proofs generated.

Whether a second frontier lab follows Meta and prints its own price for training rights. One published number is a pricing experiment. Two is a market forming, and the second one tells you whether twelve and a half was high, low, or about right.


The two voices are AI. The research and writing are mine.

Decentralized AI, layer by layer.

Dastan

Listen on Spotify and Apple. @plainstrata. Decentralized AI, layer by layer.

You just read issue #14 of Plain Strata. You can also browse the full archives of this newsletter.

← Newer The danger is the wiring Older → Nobody checks the answer
Spotify
Powered by Buttondown, the easiest way to start and grow your newsletter.