Most people assume that when a piece of corporate writing is confusing, it is a failure of communication. They imagine a harried legal intern or a marketing manager who was simply too tired to find the right word.
This is a comforting thought because it implies that clarity is the goal and error is the obstacle. But as someone who has spent a decade inspecting the structural integrity of bridges-and the last few years inspecting the structural integrity of AI privacy claims-I have come to a different conclusion.
Clarity is often the enemy. In the world of high-stakes data handling, ambiguity is not a mistake; it is the deliverable.
The “Hyper-bowl” Incident
I spent an embarrassingly long portion of my life pronouncing the word hyperbole as “hyper-bowl.” I said it with confidence in meetings, in classrooms, and to my parents, until the day a colleague gently pointed out that I sounded like I was talking about a particularly intense kitchen appliance.
The symbols on the page had one meaning, but the reality of the usage was entirely different. I had built a bridge in my head that led to a dead end. I realized then that you can stare at a word for a thousand hours and still not know what it is doing to the person listening to it.
The sentences we see at the top of AI product pages-the ones that say “We do not train on your data”-are exactly like my “hyper-bowl.” They are written to be seen, to be repeated in Slack channels, and to be quoted in board meetings. They are not, under any circumstances, written to be read.
Linguistic floating foundations: When the headline survives the meeting while the meaning lives in a glossary.
Inès is a compliance officer I know who recently had to clear a new generative AI tool for her engineering team. She started the morning with three browser tabs and a single PDF. Tab one was the marketing landing page, which featured a bold, sans-serif headline: Your data is your own. We don’t train on it.
This is the sentence that wins the contract. This is the sentence that Inès’s boss wants to see.
However, Inès is paid to be suspicious. She moved to tab two, which was the Privacy Policy. There, she found a qualifier: “Except as provided in the Terms of Service, we do not use Customer Content to improve our models.” She noticed the word improve. Is improve the same as train?
She moved to tab three, the Terms of Service. In section 9.4, she found the definition of “Customer Content,” which excluded “De-identified Metadata and Safety Logs.” Finally, she opened the PDF, the Data Processing Addendum, which stated that the provider reserved the right to “manually review” certain inputs to ensure compliance with safety guidelines.
By , Inès was staring at her screen, paralyzed. The clean, one-sentence promise from tab one had been dissolved by a thousand tiny atmospheric corrosive agents from the other tabs. She ended up writing an internal memo that said the tool was safe to use “as we currently understand it.”
She put that phrase in because she is a professional. She knows that “as we currently understand it” is the legal equivalent of a structural engineer saying a bridge is fine as long as nobody drives a truck over it. It is a hedge against a promise that was designed to fail.
It isn’t for the user. It is for the person who needs to give a “yes” to a superior without having to read the 14 pages of fine print that make that “yes” a lie. These sentences are precision instruments. They are built so the headline survives the initial meeting while the operative meaning lives in a glossary on a different subdomain that nobody in that meeting has ever visited.
This is how we have reached a state where “We don’t train on your data” can coexist with “We manually review your logs for safety improvements” without the marketing department’s head exploding.
The social durability of a short, false statement is significantly higher than that of a long, nuanced truth. If I tell you “The bridge is safe,” you can go home and sleep. If I tell you “The bridge’s secondary support cables show more oxidation than is recommended for a structure of this age, though the primary load-bearing members remain within the 95th percentile of safety margins,” you are going to stay awake all night worrying.
In the AI world, marketing teams are selling the sleep. Legal teams are documenting the oxidation.
The Speed of Oxidation
The problem is that in the digital age, oxidation happens at the speed of light. When you type a proprietary piece of code or a confidential strategy into a standard chat interface, that data isn’t just sitting in a vault. It is being processed, logged, and potentially viewed by a human “safety rater” in a different time zone.
The companies providing these services aren’t necessarily evil; they are just caught in the same linguistic trap I was with my “hyper-bowl.” They want to offer something simple because simplicity scales. But the reality of running a massive LLM requires data, and the reality of modern regulation requires “safety reviews.” They can’t have the simple sentence and the complex reality at the same time, so they use the simple sentence as a mask.
I stopped accepting these masks when I realized that the cost of being wrong is usually $8,420 in legal fees and a complete loss of intellectual property. We are being asked to trade our most valuable assets for a vibe.
We are told that “trust” is the new currency, but in my line of work, trust is what you use when you don’t have a torque wrench. I don’t “trust” that a bolt is tight; I check it.
This is why the architectural approach to privacy is so much more compelling than the linguistic one. If you want to ensure a secret stays a secret, you don’t ask for a promise; you use a vault.
The Vault vs. The Promise
“The tab that promises safety is never the one that defines it.”
True privacy in AI isn’t a sentence in a policy; it’s an infrastructure. It’s the difference between a sign that says “No Trespassing” and a wall made of reinforced concrete. When you use a service like tunnel AI, the protection isn’t coming from a marketing manager’s promise.
It is coming from the fact that the data is encrypted on your device before it ever touches a wire. The provider cannot train on your data because they do not have the keys to see it. It is a physical impossibility, not a legal choice. That is the level of certainty we should be demanding.
Instead, we are currently satisfied with sentences that are “accurate enough” for a pitch deck. We allow “improvement” to be a synonym for “training” when it suits the provider, and a distinct, separate category when it’s time to talk to the regulators.
We have accepted a world where approximately 31% of users realize the privacy policy contradicts the landing page, but 100% of them click “I Agree” anyway because they have work to do.
The Paradox of Consent: Identifying contradiction does not equal stopping usage.
“The most dangerous part of a bridge isn’t the part that’s rusted. It’s the part that looks brand new but was never bolted to the foundation.”
– Helen C.M., senior bridge inspector
Most AI privacy claims are beautiful, shiny, and completely unattached to the underlying technical reality. They are floating sentences. They are designed to be quoted by people who are in a hurry to be reassured.
I don’t blame Inès for her “as we currently understand it” hedge. She is navigating a landscape where the words are shifting under her feet. But I do blame the culture that makes that hedge necessary. We have turned privacy into a linguistic game, a series of nested definitions and “safety” exceptions that serve to protect the vendor more than the client.
If we want to fix this, we have to stop quoting the headlines. We have to start looking at the architecture of the data flow itself. We have to ask where the encryption happens, who holds the keys, and whether the provider has the technical ability-not just the legal intention-to keep our information private.
Until then, we are just like me in that meeting years ago, confidently shouting “hyper-bowl” while everyone else in the room knows the truth. We are using words to hide from the reality of the structures we are building.
And eventually, just like any bridge that was built on a quote instead of a foundation, the weight of the reality will become too much for the words to carry.
