The previous article described the inference gap, the space between the data you provide to an AI system and the conclusions that system draws about you, conclusions that are invisible, consequential, and almost entirely ungoverned. It traced the legal and scholarly foundation for closing that gap, from Wachter and Mittelstadt’s research to Denmark’s ownership precedent.
This article describes the mechanism I propose to close it: inference escrow, operating at two levels, each designed for a different kind of human situation.
Start with the situation where the person has the least power.
A patient in a resource-constrained health system opens an AI diagnostic app. She is not choosing between this app and a human physician; the physician is unavailable, the wait is weeks long, and the clinic has closed. The AI is not an option among options. It is the only option. She enters her symptoms with a candor born of desperation. She describes pain she might minimize with a doctor she trusts, discloses history she might withhold in a less urgent setting. The system draws inferences from everything she provides: diagnostic probabilities, risk assessments, behavioral predictions.
She did not consent to the generation of those inferences in any meaningful sense. She consented to receiving care. The inferences were a byproduct she did not understand and could not refuse.
For people in this situation (under constraint, without genuine alternatives, trading intimate data for essential services), the protection cannot come from the individual. It must come from the system itself.
This is the first level of inference escrow: systemic protection. The inferences generated are treated as regulated artifacts. They are stored separately from the user’s identity. They are time-bound; they expire rather than persist indefinitely. They are purpose-limited; they may be used for the diagnostic purpose for which they were generated, but not sold to insurers, employers, or data brokers. They are prohibited from secondary commercial use. And the AI model is trained using federated learning; the data never leaves the local jurisdiction, and only the learning parameters are sent to the central model.
The person does not need to understand any of this. The protection is architectural. It is built into the system’s design, the way fire safety is built into a building’s structure, present whether the occupant thinks about it or not.
Now consider a different situation, one where the person has genuine agency.
A professional applies for a job. A homeowner applies for a mortgage. A parent enrolls a child in a school that uses AI assessment. A consumer shops on a platform that adjusts pricing based on behavioral predictions. In each case, the person is interacting with an AI system that will draw conclusions about them, conclusions that will shape what they are offered, what they are charged, and what opportunities reach them.
These people are not under the desperate constraint of the patient described above. They have alternatives, at least in principle. What they lack is visibility; they cannot see the conclusions being drawn about them, and they have no mechanism to control who else sees those conclusions.
This is the second level of inference escrow: the safe deposit box.
The concept is simple. The conclusions an AI system draws about you are held in a secure space under your direct control, like a bank safe deposit box, and only you hold the key. You decide who sees what has been concluded about you. You decide when. You decide for what purpose. The default is reversed: instead of the inference belonging to the system that generated it, the inference belongs to the person it describes.
A potential employer’s AI generates a hiring assessment about you. Under the current system, that assessment is the company’s proprietary information. You never see it. Under inference escrow, the assessment exists, but it sits in your box. The employer can request access. You can grant it, deny it, or grant it with conditions. You can see what was concluded. You can contest it. You can compare assessments across multiple employers to detect patterns of bias.
The safe deposit box does not prevent inferences from being drawn. AI systems will continue to generate conclusions; that is what they do. What the safe deposit box changes is who controls those conclusions after they are generated. It shifts the default from institutional ownership to individual ownership. The inference belongs to you because it is about you.
Return for a moment to Anna and Leo, the family whose story opened this series. Under first-level inference escrow, the insurance company’s AI would not be free to draw a cost-effectiveness inference about Leo’s treatment and act on it without constraint. The inference would be treated as a regulated artifact, subject to transparency and the requirement that a human decision-maker review it before it becomes a denial. Under second-level protection, the safe deposit box, Anna herself would have the right to see what was concluded about her son’s case, to understand the basis for the denial, and to contest it with the inference in hand rather than fighting a conclusion she cannot see.
Neither level guarantees a different outcome. Both guarantee that the conclusion is visible, accountable, and subject to human judgment rather than executed in silence.
But for either level to function as genuine protection rather than legal formality, the human review it requires must itself be real. And that raises a question the next article will address: when is human oversight meaningful, and when is it theater?
This article is drawn from Digital Sovereignty in the Cognitive Age, available at blogs.inspire-aspire.net.



