On Wednesday, a twenty-year-old essay by Moxie Marlinspike — “Scrap,” published in 2006, before Signal, before the encryption protocol now running inside WhatsApp, Google Messages, Facebook Messenger, and Skype — sat at the top of Hacker News with 364 points and 193 comments. The thread is a museum piece: people quoting the essay, debating its foresight, arguing about whether the author was always this sharp or has since lost the thread.

Six weeks earlier, on July 13, Marlinspike published something else. It appeared on his Confer blog under the title “Making end-to-end encrypted AI chat feel like logging in.” Ars Technica covered it the same day: “Signal creator Moxie Marlinspike wants to do for AI what he did for messaging.”

The 2006 essay got more attention in an afternoon than the AI proposal has gotten since. That is not a coincidence. It is a dodge.

The July Paper Nobody Read

What Marlinspike is proposing is not another chatbot. It is a question about who owns the conversation. If AI chat is end-to-end encrypted — if the model provider cannot see the prompts, cannot store the responses, cannot train on the exchange — then the entire data flywheel that frontier AI companies have built their valuations on stops spinning.

This is not a privacy argument. It is a market-structure argument. The moat of every major AI company is not the model weights, which are increasingly commoditized. The moat is the data: every prompt, every correction, every generated document, every conversational quirk. Encrypt the channel and the moat dries up.

One engineer at a frontier AI lab put it plainly in a Slack DM: “If Moxie’s right and encrypted inference takes off, our training-data advantage evaporates. That’s not a privacy problem. That’s a valuation problem.”

He’s right, and that is precisely why the industry would rather talk about a 2006 essay.

Provenance-Checking Is Not Due Diligence

The Hacker News thread on “Scrap” is not really about the essay. It is about the author. Is Marlinspike a visionary or a crank? Was he always right, or has he finally overreached? These are the questions 193 commenters are litigating.

But you cannot evaluate a technical proposal by reading the author’s college-era essays. That is provenance-checking dressed up as due diligence, and it is a category error. The right question about end-to-end encrypted AI chat is not “was Moxie prescient in 2006?” The right question is “does the architecture work, and what would it do to the competitive landscape?”

The reason the discourse prefers the former question is that the latter has an uncomfortable answer: it would do to AI data moats what the Signal Protocol did to messaging interception — make them structurally impossible. Nobody in the AI industry wants to say that out loud, so instead we get a nostalgic re-read of a two-decade-old essay.

Encryption Is a Market-Structure Tool, Not a Privacy Fetish

The right has spent years treating encryption as a wedge issue — a privacy-absolutist indulgence that mainly benefits dissidents, journalists, and, yes, criminals. That framing has always been lazy, but it is actively counterproductive when applied to AI.

Encryption is the most powerful anti-monopoly mechanism ever invented. It does not just hide data from governments; it hides data from the platform itself. A messaging service that cannot read your messages cannot sell your behavioral profile. An AI provider that cannot read your prompts cannot train on them, cannot resell them, cannot build a proprietary dataset from your usage. Encryption breaks the flywheel that makes platform monopolies possible.

The empirical record is already in. The Signal Protocol secures billions of users across WhatsApp, Google Messages, Facebook Messenger, and Skype, and it did not turn those platforms into criminal havens. It turned them into services where your messages are yours. The “criminals will use it” objection has been answered, at scale, for a decade.

The people who should be most interested in encrypted AI are the people worried about AI concentration. If you think a handful of companies owning the entire conversational layer of the internet is a problem — and it is — then encryption is the only mechanism that structurally prevents it. Antitrust regulators who count market share and ignore encryption architecture are missing the one lever that actually breaks the data moat.

Moxie’s 2006 essay is a fine artifact. But the July paper is the one that matters, and it is being ignored by precisely the people who should be arguing about it. The Hacker News thread is a comfortable detour. The uncomfortable question is sitting in plain sight: who owns the conversation, and who has the keys?

Sources