One dimension of this which isn't discussed enough is this opens the road to inference providers silently discriminating against different users who will remain oblivious to what's going on. i.e. if you "fail" ID verification it's actually good that they tell you as opposed to serving you a malicious model instead.