Ethereum co-founder Vitalik Buterin has detailed an experimental privacy-preserving AI workflow designed to generate personalized diet and exercise recommendations from health and travel data without exposing sensitive personal information. The setup combined three separate privacy layers: a local AI model to prepare queries, zkAPI to shield payment identity, and Tor to obscure network and IP information.
According to Buterin’s posts on X, the local model—identified as Qwen 3.8 Flash Next—coordinated requests to more powerful remote models through tool calls. A skill file instructed the local system when to seek external assistance and how to construct requests revealing minimal data, while the local model wrote the queries itself to avoid exposing identifying patterns in Buterin’s writing. For payments, Buterin used zkAPI, which accepts deposits in ETH or USDC to cover remote model access, routed through Tor as a command-line tool.
Buterin reported that the experiment worked and that frontier models improved the recommendations he received. However, he also highlighted unresolved trade-offs. Privacy restrictions left remote models with less context, reducing the quality of tailored advice. He noted local processing speeds of roughly 20–30 tokens per second—well below his target of more than 100 tokens per second—and described Tor latency as potentially 10–100 times higher than direct connections. Request strategies also remained far from optimal, and he questioned whether Tor’s privacy protections were sufficient for separating individual requests.
Overall, the test demonstrated a working approach to privacy-aware AI assistance, but Buterin emphasized that the privacy-and-utility trade-off remains an open constraint.