This is the same old composition problem wearing a model-serving hat: once you let one dataset train a bunch of separate APIs, each extra model is another leak channel, so membership inference can ratchet up even if any single task looks only mildly bad.
People used to think in terms of repeated queries or adaptive composition against a fixed oracle. Here the oracle is just split into a zoo of task heads (face, age, race, medical, text), and the privacy math still bites....