Imagine you run a hospital cafeteria and need to know what patients eat most, but you're not allowed to look at any individual tray. The traditional approach: hire a statistician to design a noisy survey for each cafeteria, each menu, each season — slow and lossy. PrivTab's approach: train one system, once, on millions of synthetic cafeterias, so it already knows how to count trays through frosted glass. Hand it your real cafeteria, and it gives you the answer in one look. The committed claim: a single pretrained tabular foundation model can perform differentially private classification on unseen datasets in one forward pass, beating DP-SGD neural networks and private linear models under moderate-to-strong privacy (ε ≤ 4), while reducing fitting time by four orders of magnitude. This is not incremental DP improvement — it is a category shift from 'optimize privately per dataset' to 'learn to be private once, deploy everywhere.' The mechanism is in-context learning with a baked-in privacy layer. PrivTab is a transformer pretrained on synthetic tabular datasets sampled from a prior over data-generating processes. At inference, it receives the sensitive training set as context, passes each row through a local privatization mechanism (label DP via randomized response), and produces predictions for query points. The privacy guarantee follows from the composition of this local mechanism — the model never sees raw sensitive labels. This is architecturally distinct from DP-SGD, which adds noise to gradients during optimization; here, privacy is a fixed structural property of the forward pass, not a training-time constraint. On the ladder: PrivTab is compared against DP-SGD-trained MLPs, private logistic regression, and the non-private TabPFN foundation model. Under ε = 1 (strong privacy), PrivTab outperforms DP-SGD MLPs by substantial margins across multiple OpenML benchmarks. Under ε = 4, the gap narrows but persists. At ε = ∞ (no privacy), PrivTab underperforms standard TabPFN, as expected — you pay for the privacy architecture in raw accuracy. The authors are honest that at very weak privacy budgets, dataset-specific training catches up. The 10,000× speed advantage is real: one forward pass versus thousands of noisy gradient steps per dataset. Integrity is solid but bounded. Benchmarks are drawn from OpenML classification tasks — community-standard, not cherry-picked. Membership inference attacks are run to verify negligible leakage. The differential privacy guarantee is mathematical, not empirical — it follows from the label-DP mechanism, not from measuring attack success. However, the pretraining data is synthetic, meaning the model's generalization to truly adversarial real-world distributions is tested empirically, not proven. No independent replication exists yet. Code availability is not explicitly stated in the abstract but the 74-page supplement suggests thorough documentation. The milestone question is concrete: PrivTab handles classification on tabular data with moderate feature counts. The next unlock is extending this to regression, high-dimensional features, and multi-table relational data — the stuff that actually dominates healthcare and finance pipelines. If the in-context privacy mechanism scales to 100+ features and continuous targets at ε ≤ 1 without collapsing, that would be a deployment-ready tool for regulated industries. The obvious experiment not run: PrivTab on truly large-scale, high-stakes medical or financial datasets where distribution shift between synthetic pretraining and real deployment is maximal. The honest read is (a) — access and compliance barriers to real sensitive data are enormous, and the synthetic-pretraining design deliberately sidesteps this. But it's the exact experiment that would convert skeptics. The authors know this; they built the tool to make that experiment easy for someone with data access to run next.