Attesting the virtual machines running the AI models in this way is a really trust inspiring move, especially if it really is possible to verify the software running in detail, ie if the VM images are provided for download to compare with what is attested.
But nothing of this is end-to-end encryption. It is still classic client-server encryption as is used by any website, the server is still capable of decrypting all your communication. All you did was verify what hardware, software and configuration said server is running. In fact, they need the data in decrypted state to be able to run it in AI models.
This is abuse of terminology, and false marketing, claiming properties of their solutions they do not have.
In the meantime, local AI is actually private.