My point here is that the implementations of AI agents esp in the OS, w the pervasive permissions, insecure MCP architectures, and requirement for data access, undermine Signal’s (and others’) ability to provide privacy via e2ee at the application layer. This is a big problem.