The future of Siri, or: why private inference isn’t private enough
Summary
Matthew Green argues that private inference in Siri-like agents is not truly private once the agent needs internet access and can interact with external services. The piece warns about data leakage via prompts and external queries, introduces the lethal trifecta concept, and concludes that cryptography alone cannot fully protect privacy in agentic systems; governance and policy incentives matter.