Privacy-preserving AI research proceeds on the assumption that the model is the threat vector. Trusted execution environments, differential privacy, federated learning — each of these addresses what happens to data once it enters an AI system. The FBI's position this week reframes the question entirely: the threat does not require an AI system. It requires a data market . Anthropic's protest of government surveillance practices is notable not because it was ineffective but because it shows where the company's leverage ends. A lab can restrict what its model does…