Proton CEO: AI and Privacy Can Coexist, But Not the Big Tech Way
Andy Yen explains why his encrypted email company launched an AI chatbot and how privacy-focused alternatives could reshape the technology's future.

The privacy paradox of AI
Andy Yen, founder and CEO of Proton, has built a company on a simple premise: create encrypted alternatives to Google's suite of products. But his latest move has surprised some of his privacy-conscious users—Proton now offers its own AI chatbot called Lumo.
The decision reflects a pragmatic calculation about technology's trajectory. "AI is surveillance. The internet is surveillance," Yen said in a recent interview with WIRED. "The genie's out of the bottle; we're not gonna put it back in, and we are not gonna be returning to a pre-AI world."
Proton has grown from a few hundred thousand users in 2014 to over 100 million today, offering encrypted versions of email, calendar, file storage, and documents. The company operates on a freemium model with conversion rates between 1 and 3 percent—typical for the category but representing a substantial paying user base.
Why it matters
The tension between AI capabilities and user privacy represents one of technology's defining challenges. Proton's approach—building AI tools that don't follow Big Tech's data-harvesting playbook—could establish whether privacy-preserving alternatives can compete technically while maintaining their core principles. The outcome will help determine whether users must choose between cutting-edge AI features and control over their personal data.
The backlash and the turnaround
When Proton first introduced AI features, user reaction was hostile. "People were sort of like, 'Why are you doing this? It's a waste of resources. It's not what Proton stands for,'" Yen recalled. But sentiment shifted after the company released Lumo. The same critics who initially opposed the feature began demanding improvements instead.
Yen argues the resistance wasn't to AI itself but to what AI represents in Big Tech's implementation—another tool for surveillance capitalism. When Proton demonstrated AI could work differently, users embraced it.
The technical compromise
Lumo doesn't offer the same mathematical guarantee of privacy that Proton Mail provides through end-to-end encryption. Instead, it relies on Proton's promise not to log or access user conversations with the AI.
Yen, a former particle physicist, acknowledges this gap. "As a physicist, I like mathematical guarantees," he said. The technology for fully end-to-end encrypted large language models isn't mature yet, though he expects it within a couple of years.
The company is monitoring developments in trusted execution environments—secure enclaves within servers that use cryptography to isolate AI processing from the rest of the system. While some competitors already use this approach, Yen says the technology remains "a little bit clunky" and would require re-architecting Proton's entire platform, which runs on its own infrastructure rather than cloud services.
The stakes of the AI race
Yen frames Proton's AI push as essential to its mission. If privacy-focused companies don't build AI alternatives, he argues, the future will belong entirely to tech giants with poor track records on data protection. "This is what happened in the late '90s, early 2000s when we let Google, Meta, Yahoo, and these other companies take over the entire [digital economy]," he said.
The company has also introduced tools to make switching from Google easier, capitalizing on growing user frustration with AI features being pushed into products like Gmail.
Yen's position is nuanced: he'd prefer a world without AI but accepts that's not an option. The question now is who will control the technology and under what terms.
These details were first reported by WIRED in an interview conducted by senior writer Andy Greenberg.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call