Earlier quoted context omitted.
Because you're silently invoking additional data (the prompt + noise seed), which is not present in the training weights. You have the prompt + noise seed for any given output. An MPEG codec doesn't contain every movie in the world just because it could represent them if given the right file. The white light coming off a blank canvas also doesn't contain a copy of the Mona Lisa which will be revealed once someone obs…
OK so let me encrypt a movie and distribute that. Then you tell people they need to invoke additional data to watch the movie. Also give some hints (try the movie title lol).
The answer is of course not, and the same principle applies if someone uses Stable Diffusion to find a latent space encoding for a copyright image (the 231 byte number - had to go double check what the grid size actually is).