‘No company is going to go to jail for you’: Proton’s CTO on balancing privacy, policy, and trust

· Source: The Verge · Field: Technology & Digital — Cybersecurity & Data Privacy, Artificial Intelligence & Machine Learning, Software Development & Engineering · Depth: Advanced, quick

Summary

Proton CTO Bart Butler discusses the company's strategy for balancing privacy, policy, and trust in its suite of encrypted productivity software, including Proton Mail, VPN, Drive, and the new AI assistant Lumo. Proton, a Swiss-based company with approximately 650 employees, operates under a foundation structure designed to protect its mission of providing privacy-by-default products funded directly by users, not advertising. Butler emphasizes that Proton sells trust, backed by end-to-end encryption and a business model aligning company growth with user protection. The company faces significant pressure from governments, including Swiss authorities and EU surveillance laws like Chat Control, which have led to compliance with metadata requests and threats to relocate operations from Switzerland or the EU if privacy is compromised. Proton's Lumo AI assistant uses open-source models to offer a private alternative, reinforcing the principle that privacy is about user control over data sharing, not absolute non-sharing.

Key takeaway

For policy makers drafting digital surveillance or age verification laws, recognize that demands for backdoors or client-side scanning are technically infeasible to implement securely. Such mandates create universal vulnerabilities, threatening user privacy and the operational viability of companies like Proton. Instead, focus on regulations that encourage privacy-preserving technologies, like zero-knowledge proofs. This allows for necessary controls without compromising fundamental freedoms or forcing companies to abandon jurisdictions. Your decisions directly impact the future of secure digital services.

Key insights

Trust in privacy-centric software hinges on interlocking technical, business, and corporate structures that align incentives with user data control.

Principles

Method

Proton engineers products for maximum privacy, operates on a user-paid model, leverages Swiss jurisdiction, and uses a foundation to protect its mission, even threatening relocation from hostile legal environments. For AI, it uses in-house open-source models.

In practice

Topics

Best for: CTO, Executive, AI Product Manager, Director of AI/ML, AI Security Engineer, Policy Maker

Related on AIssential

Open in AIssential →

Editorial summary, takeaway, and curation by AIssential. Original article published by The Verge.