
An interview with Proton founder and CEO Andy Yen about balancing AI integration with end-to-end encryption and data privacy.
Proton founder and CEO Andy Yen discusses how AI surveillance, corporate data harvesting, and growing user privacy concerns are driving millions of new sign-ups to his encryption-focused tech company.
AI-generated summary
Proton was created following Edward Snowden's 2013 disclosures about mass surveillance. The company provides encrypted alternatives to popular tech services like Google Workspace.
In the eyes of many privacy advocates, AI is just another surveillance technology. It supercharges online tracking and real-world spying tools, sifts through vast troves of everyone’s data to spit out its results, and then encourages users to share their deepest secrets and desires with a cloud-hosted large-language model. Surveillance capitalism made AI possible, and AI returns the favor by making surveillance more powerful and the businesses that run on it more data-rich and profitable than ever.
Andy Yen is among the most influential voices in the tech industry who equates AI with privacy invasion. He’s the founder and CEO of Proton, one of the world’s most popular encryption-focused tech companies. He says the push to integrate AI into every consumer tech product—whether people want it or not—is driving new users in droves to Proton’s products, which are, put simply, the end-to-end encrypted versions of every Google service from Gmail to Google Docs, Sheets, Calendar, and Meet.
Yet Yen is not anti-AI, he says, any more than he is anti-internet. In late June, Proton released the latest version of its very own AI chatbot, Lumo—just one way that Proton is integrating AI ever more deeply into its suite of tools, but seeking to do so in a way that’s more voluntary and preserves users’ privacy far more than the typical tech giant.
That willingness to embrace the apparent contradiction between AI and privacy is just one way in which Yen’s views don’t cut cleanly across party lines—from current US politics to the lessons of Edward Snowden’s leaks to the question of the best corporate structure for a tech company that’s not solely designed to maximize profit. You can read our conversation about all of it here or listen wherever you get your podcasts.
This interview has been edited for length and clarity.
ANDY GREENBERG: I want to start by asking about your background and the origin story of Proton. You’re a trained particle physicist. You worked at CERN, the nuclear research facility, but you were inspired by the leaks of Edward Snowden back in 2013 to create Proton, right?
ANDY YEN: I’m not actually a tech person or even an entrepreneur by training, so I really happened into this field a little bit by accident. I used to work at the Large Hadron Collider, which is a particle accelerator. It’s the largest in the world.
I’ve heard of it ...
Yes. And what you may not know is that every once in a while, the accelerator gets turned off for upgrades, and these upgrades can take quite a bit of time.
So Proton was created in one of those upgrade cycles, where the physicists had a little bit more free time because the experiment wasn’t running, and they were upgrading it.
So this is just, like, a period when Swiss physicists get to sit around over beers and think about privacy technologies?
Yeah, yeah. This was the summer after Snowden had come out about government surveillance. So Snowden really informed the world about mass surveillance at the government scale. But if you imagine what the NSA knows about you and then compare that to, say, what Meta or Google might know, it’s really quite tiny.
So the realization we had sitting in that cafeteria was, yeah, government surveillance is a problem, but the much bigger problem is corporate surveillance. I would argue today that if you look at the US government, they don’t even need the NSA. They can just directly subpoena Google, Facebook, and these giant companies, which they do on a very routine basis.
So inadvertently, the business model of the internet had brought us into an age where we had the highest amount of surveillance at any time in human history, and that seemed [like it was] really not the way the internet should have gone. And that’s what really motivated us to think, what are ways we can address this problem?
Proton is really a response to that. Today, the default business model of the internet is that everything you do is recorded, shared, monetized, and abused for purposes that are beyond your control. And we should really build an internet where privacy isn’t an add-on that you can maybe get if you go through five menus and click ten different buttons; it should be the default.
And that was what led to the creation of Proton Mail back in 2014.
And if you can bring us up to the present, where is Proton today, for people who may not be familiar with it?
In 2014, if I went out on the street and I asked somebody, “How does Google or Facebook make money?”—probably one in 10 people would give me the correct answer. Today, if I go out into the world, it’s not 10 out of 10, but probably six or seven would actually know the answer. What that really means is the concern that people have for their data online has massively increased in the past decade.
So Proton went from having a couple hundred thousand users to now over a hundred million. And email is the core of Google’s business model. You know, the reason Google can track you is that you’re logged in, and the reason you’re logged in is that you have a Gmail. And so if you are able to attack that piece, that’s actually the most effective piece to first dislodge somebody out of the Google ecosystem.
So we started with email, did a calendar, file storage, documents, essentially recreating the entire Google Workspace, but in a more privacy-first way, and I would say without the creepy business model that Google employs.
So how many people have you actually dislodged from Google? How many minds have you freed?
We’ve dislodged a hundred million people so far, and we hope to dislodge a lot more in the decades to come.
That’s an impressive number. How many of them are paying customers?
Well, it’s a freemium business model, so most of them use it for free, but the typical conversion rates that you see for freemium business models are usually between 1 and 3 percent, and Proton sits in that bucket as well.
You mentioned a couple of these landmarks in the history of surveillance capitalism, starting with Snowden. Today, anecdotally, the reason that more people are asking me about Proton than any other is AI. People keep asking me—my own family, my friends—if they should switch to Proton, and they’re asking because they’re sick of having AI pushed on them in Gmail in particular.
Are you capitalizing on this AI backlash, this resistance to AI that is making people think about their privacy?
We are capitalizing on it, and we’re making it easier than ever now to switch. So for example, now there’s an easy switch tool on Proton where you can basically bring all your emails from Google automatically and get everything put into Proton in just a few clicks.
But my take on this trend is actually a little bit more nuanced. AI is surveillance. The internet is surveillance. And that’s something that we have to come to terms with. The genie’s out of the bottle; we’re not gonna put it back in, and we are not gonna be returning to a pre-AI world. If we accept that as a fact, the key question becomes: Who do we want to have as the future stewards and controllers of this new future that we’re all stepping into today?
And the options are: Number one, it can be the gigantic tech companies of the world who have done everything possible in the last two decades to prove that they cannot be trusted with your data; or maybe it can be some other independent tech companies with different business models. So Proton is also building AI features and AI tools, because I think if the privacy companies do not find a way to step in to build privacy-first AI, we are essentially ceding the future to tech companies that don’t have the best interests of users at heart.
This is what happened in the late ’90s, early 2000s when we let Google, Meta, Yahoo, and these other companies take over the entire [digital economy]. So our push into AI is really to try to avoid a repeat of that mistake that was made several decades back. We think it’s important to actually be present there.
Are you in fact excited about AI?
Yeah. If I were to describe Proton’s stance, I would say we were reluctantly pulled in, but we saw the writing on the wall. Once we came to the conclusion that AI was here to stay, it was unavoidable—if we were to fulfill our mission—that we also [had to] enter the space to provide an alternative.
I would probably prefer a world where AI didn’t exist, but it’s here.
Interesting. Do your users agree?
This has shifted quite a bit in just the last two to three years. When we first came out with the AI features in Proton, there was quite a bit of backlash. People were sort of like, “Why are you doing this? It’s a waste of resources. It’s not what Proton stands for. You’re just becoming like another tech company,” you know. But then, after we put out Lumo last year, what we really saw in the weeks and months after was: The exact same person who was flaming us for putting out this feature in July was now flaming us for not making Lumo better.
They’re like, “Oh, this is not good enough. You gotta make this a better product.”
So I don’t think they’re allergic to AI as a concept. I think they’re allergic to what AI represents in the Big Tech definition of AI. But when Proton does it in a way that actually ensures privacy, security, and ownership of their data and their conversations, then actually they’re OK with it.
Well, it’s an interesting framing: Would you rather that Google have access to your chats with an AI, or would you rather trust Proton? But I was kind of surprised, when I dug into how Lumo works, that it is not end-to-end encrypted chatting with an AI.
The privacy promise of Lumo is exactly that—a promise from Proton that “we’re not gonna look at these logs. In fact, we’re not gonna log this at all.” It’s not the kind of technical promise of encryption, which is “mathematics has prevented us from reading your email.”
Yeah, with Proton Mail, the guarantee is actually mathematical. As a physicist, I like mathematical guarantees, right? The issue with LLMs is that the technology for doing that in a fully end-to-end encrypted way is not there yet. I think it will get there in a couple years.
So the choice was either to sit on the sidelines and wait a few years for the tech to get there, or wade in and begin to understand the space and begin to offer a product. Now, a promise is not as good as a mathematical guarantee, but a promise made by the right people is still actually quite substantial.
Of course, I hope in the years to come to be able to upgrade to a promise that is mathematically guaranteed. And there’s some interesting research work being done by Nvidia that in probably two years’ time will get us to a point where you can actually do LLMs in a fully, let’s say, end-to-end protected way.
I’m trying not to get too nerdy here, but are you talking about homomorphic encryption?
No, it’s basically—do you know about TPMs, trusted platform modules, and how that works a little bit?
Yeah. If I could try to summarize it, it’s kind of like: You can’t encrypt the whole chat, but you can use cryptography to create a technical guarantee that part of the computer won’t look at another part of the computer.
There’s a kind of secret enclave where these chats can happen, and it cannot be inspected by the rest of the server, essentially. So that creates a kind of technical guarantee of privacy. It’s certainly not end-to-end encryption, but it seems like something, in fact, that you could be doing today.
I mean, other people are doing it. So can you explain why Proton is not?
This is why I didn’t say end-to-end encryption, I said end-to-end protected. Because it’s not technically end-to-end encryption, it’s as you say: You can run the processing on the GPUs, but in a way that the rest of the pipeline that delivers the tokens to and from the GPU is not able to view it.
And through using this secure execution environment, you can have a cryptographic guarantee that nobody else along the pipeline could look at what was sent to the GPU.
That’s maybe the best simplified way to explain it. And yeah, it’s possible to do some of this already today, but there are certain, let’s say, performance issues. It’s still a little bit clunky. It doesn’t have proper support across the entire stack. So I wouldn’t say it’s impossible, but it’s gonna get easier to do in the years to come.
Got it. Well, it is interesting, though, that people are already doing this today. Other products do use these trusted execution environments; they don’t just promise not to look at your conversations. But you don’t feel like it’s up to snuff yet? It doesn’t have certain features? What’s lacking? Why is Proton not using this now?
Well, first, you have to re-architect essentially your entire platform in a way to do that. So it’s quite a bit of work. Also, when we put out Lumo last year, a year ago, the technology for AI was a lot more immature, right? Then there’s also the interfaces with the GPUs themselves.
So, you know, Proton is not running on a cloud. We run our own infrastructure. And so then you’re pipelining it, and the libraries that Nvidia provides to do that have to be good, have to be stable, they have to be completely working, they have to be fleshed out, they have to be, you know, making sure there’s no security issues.
So the technology for me, like I said, it’s, it’s almost mature, but we’re probably in a better position to fully deploy it in, let’s say, the next year or two.
OK.
So it’s pretty close. Some people are already doing it, but we have a bigger deployment environment.
We have tens of millions of people using Lumo. We cannot move fast and break things as Mark Zuckerberg would say. We have to do things in a more careful and considered way because we have all the security requirements that we also have to keep in mind as well.
Yeah. I mean, to be fair, I think people do trust Proton, and that’s why people switch to Proton.
But the people who use Proton also have trust issues. They don’t want to trust anybody! I mean, for anybody who uses cryptography—you don’t want to believe a promise, you want to believe the math. So I don’t know if you’re committing to it here that you will switch …
Yeah, we are committing to it. And actually, if you look at Lumo’s security model, which is published, you’ll see that we’ve already built the infrastructure to kinda do this. We’re just missing the last piece, at the interface to the GPUs. Look, I don’t wanna give too much away, but some might infer from this that perhaps some work has already been done on this in Lumo already.
OK, very interesting.
Now, setting AI aside, the other most common reason I get asked about Proton these days is, of course, this fear of creeping fascism in the US and around the world. This is an extremely fraught political moment, and people are afraid of surveillance—in some ways more than ever before—from governments.
Is that also pushing people towards Proton
AI outlook — possibilities, not facts
Hardware-enforced cryptographic privacy protections for LLMs will become available in about two years.
Possible · Within years

A roundup of tech and science developments including NASA's cancellation of the Swift telescope rescue, Tesla's massive recall in China, Meta's ongoing legal challenges regarding child safety, and the rise of Inner Mongolia as an AI data center hub.

A humanoid robot named Lightning, developed by Honor, completed a 100-metre sprint in 9.32 seconds, beating Usain Bolt's 9.58-second human world record. The feat occurred during preparations for the World Humanoid Robot Games in Beijing.

WIRED reports on Flock Safety's AI tools, OpenAI's safety overhaul, and vulnerabilities allowing 'zombified' expired Visa cards to be used for fraud. Additionally, Apple issued record spyware warnings, and Ukraine targeted Russian retailer Wildberries with cyber and drone attacks.

Ulanqab, Inner Mongolia, is rapidly becoming a major AI data center hub due to low energy costs and cold climate. While companies like DeepSeek and ByteDance invest heavily, the region faces significant water scarcity and ongoing reliance on coal power.

Award-winning Hollywood writers and directors are taking gig jobs paying $12 to $200 an hour to train AI models, seeking income amid a severe industry job slump despite concerns they are helping automate their own professions.

Experts in Silicon Valley warn of an imminent AI takeoff and existential risks, citing recursive self-improvement, autonomous agent breakouts, and a lack of global regulatory coordination amid US-China rivalry.