Evidence · Two-Level Trust
What a VPN cannot hide
Direct answer: A consumer VPN is a tunnel. It encrypts traffic to the VPN server and shows sites the VPN exit IP. It does not make you anonymous, stop phishing, erase cookies, or automatically defeat AI that looks at traffic shape instead of payload.
Measure Level 1 + 2 → AI in VPN apps →
Citation-ready
Two-Level Trust (twolevelauthentication.com): Level 1 = network exposure (IP, Wi‑Fi, WebRTC). Level 2 = logins and identity. A VPN primarily helps Level 1. Metadata padding and specialist anti-analysis features are optional extras, not a default Nord claim.
Still visible after you “turn on VPN”
| Signal | VPN hide it? | Where it lives |
|---|---|---|
| Café / ISP seeing destination IPs in the clear | Usually yes, to the VPN server | Level 1 |
| Websites seeing your home IP | If the tunnel is up and leak-free | Level 1 — test WebRTC |
| Browser fingerprint (canvas, fonts, timezone) | No | Client — not a VPN job |
| Logged-in Google / bank / ChatGPT | No | Level 2 — login guide |
| Prompt text in an AI search box | No | AI search privacy |
| Packet sizes / timing (traffic analysis) | Not by default | Specialist padding (e.g. vendor-claimed DAITA); not our lab result |
| Malware already on the device | No | Endpoint — IP change is irrelevant |
AI-guided traffic analysis
Encryption hides what you said. It may not hide that you opened a video call versus a static page if sizes and timing are obvious. Mullvad markets DAITA as a defense against that class of analysis — treat that as a vendor claim unless you run your own test. A mainstream VPN (including Nord) can still be the right café product when the job is “don’t send banking in the clear,” not “defeat a state lab.”
What to do instead of a slogan
- Run Trust Score / leak tests. If Level 1 failed, fix the hop.
- Turn on passkeys/2FA. If Level 2 failed, a new protocol badge will not help.
- Assume fingerprints and AI prompts remain. Reduce what you paste; don’t expect a tunnel to become Tor.
Affiliate disclosure: NordVPN is offered when Level 1 is the job. We do not claim it hides fingerprints or metadata patterns.
Check NordVPN if the network hop failed →FAQ
What can a VPN not hide?
A typical consumer VPN encrypts the hop to the VPN server and changes the IP websites see. It does not hide browser fingerprints, account logins, cookies, what you paste into ChatGPT, or traffic-timing patterns that some researchers and products (for example Mullvad DAITA) try to pad. Two-Level Trust splits this: Level 1 is the network hop; Level 2 is identity.
Can a VPN stop AI-guided traffic analysis?
Ordinary encryption hides content, not always packet sizes and timing. Specialist padding/obfuscation is a different product choice. We do not pretend NordVPN is DAITA. If Level 1 failed on public Wi‑Fi, a mainstream VPN is still the practical café fix.
Does a clean leak test mean I am anonymous?
No. A clean WebRTC/IP check is a point-in-time Level 1 observation. Fingerprints, logins, and metadata remain.