I think an AI botnet is probably a poor fit for AI workloads not mention it would be a security nightmare.
The "AI" comes in where the cost of processing all of the data is high, and Microsoft start pushing everyone to include NPU in their next "AI-enabled Windows PCs". On-device processing with a lot of benefits to the users.. but even more if the results of all of that processing can be sent back to the cloud and not take up space on Microsoft analytics processing farms.
Describe to me, how would you perform secure processing of encrypted workloads without it, and know it was secure? That the workload was not in a VM and the hardware was not issuing deliberately weak keys that could be exploited to expose the workload?