Imagine you're building a house with six different contractors, each working on a different floor. Every contractor locks their own toolbox, but nobody has agreed on a master key policy — and worse, nobody has even agreed on what counts as a 'locked door' versus a 'window left open.' That's the state of privacy in multi-institutional scientific AI. Each layer (federated learning, differential privacy, secure enclaves, provenance tracking) protects its own floor, but guarantees don't compose across floors. This paper proposes the shared vocabulary for writing the building code. The committed claim: privacy in scientific AI should be recast as a structured assurance problem defined by six elements — protected asset, observer, channel, permitted disclosure, guarantee, and evidence — and existing tools (DP, FL, MPC, TEEs) fail to compose their guarantees across mixed-trust institutions. This is a framing contribution, not an algorithmic one. The authors are not building a new lock; they're proposing the form you fill out to describe what your lock actually protects. The paper's most interesting move is identifying two attack surfaces specific to leadership-class computing facilities (think Oak Ridge, Argonne). First: scheduler, allocation, and telemetry metadata from HPC job queues can reveal an institution's resource posture — essentially, what a lab is prioritizing and how hard it's pushing. Second: instrument-attached control loops on shared accelerators leak research strategy through timing and contention patterns. These aren't theoretical hand-waves; anyone who has used shared HPC clusters knows that job queue visibility is a real information channel. The paper doesn't quantify the leakage, but naming these channels concretely is valuable. The 'claim register' concept — a structured table mapping each privacy claim to its six elements — is the paper's operational deliverable. They walk through a composite cross-institutional scenario (national labs, universities, hospitals, industry partners collaborating on a foundation model) and show how different lifecycle stages (data ingestion, training, inference, reproducibility) create different claim profiles. This is useful bookkeeping, but it's bookkeeping. No proofs, no experiments, no implementations. Six research priorities emerge: institution-level DP guarantees (not just record-level), agent-communication privacy (for autonomous AI agents negotiating across institutions), cross-tier information flow control, privacy-compatible reproducibility (a genuine tension — you can't fully reproduce if you can't see the data), leadership-scale accounting, and instrument side channels. These are reasonable priorities. None are solved here. The honest assessment: this is a perspective paper from a strong author team spanning DOE labs and universities. It fills a gap in vocabulary, not in capability. The six-element framing is clean and could become a useful lingua franca if adopted — but adoption is the hard part. The paper has no benchmarks, no code, no empirical validation that the framing catches real composition failures that ad hoc approaches miss. It's a call to arms, not a weapon. For practitioners running multi-site federated learning or managing HPC allocations across institutional boundaries, the two novel attack surfaces (scheduler metadata, instrument contention) are worth knowing about today. For everyone else, this is a paper to file under 'will matter if it gets adopted' and revisit when someone builds tooling around the claim-register format.