No need to make up hypotheticals. The server isn't the final destination for your LLM requests. The reply needs to come back to you.
Similarly with AI. The AI is one of the ends of the conversation.
The difference here is that the web server receiving a request for Confer receives an encrypted blob that only gets decrypted when running in memory in the TEE where the data will be used, which IS an end in the system.