Every AI feature here is off by default, quarantined to a clearly-labelled conversation, and gated behind a consent step the server actually enforces.
The assistant is a real account with an empty public key. Your device therefore cannot derive a key to encrypt to it. Talking to the assistant is not "encryption turned off" — it is a conversation that was never encryptable in the first place, and the client knows it.
The first message any individual sends to the assistant is refused with an explicit consent requirement, and the refusal explains what accepting means. It is per-user, because those are that person's words, not their employer's.
The usual arrangement is that AI features require server-side plaintext across your whole account. Ours is opt-in and confined to one conversation you can point at.