I read Clément Delangue’s call for “radical transparency” after the OpenAI hack twice, and both times I snagged on the same word. Transparency. The Hugging Face CEO wants AI companies to disclose more, faster, when things go wrong, and I’m not against that. But AI privacy isn’t really a disclosure problem. Transparency is a report you get after the fact, and the report only exists because your prompts were sitting on somebody else’s disk in the first place.

That’s the part nobody put to a vote. Every cloud AI agent, by construction, has to park your stuff somewhere it controls.

AI privacy is an architecture question, not a policy question

A privacy policy is a promise about behavior. An architecture is a statement about what’s physically possible. When a company says “we don’t train on your data,” that’s the first kind. When a system never receives your data at all, that’s the second kind, and the second kind survives a hack, a policy change, an acquisition, and a subpoena.

So the useful exercise isn’t reading terms of service. It’s tracing the actual hops.

Three architectures, three blast radii

Take a boring task. You’re on a supplier’s order page behind a login, and you want an AI to pull the line items into a table.

Cloud browser agent. Your instruction goes to their backend. Their backend renders or receives the page, which means the page HTML, any screenshots, and often a copy of your session state land in their infrastructure, because a remote browser can’t open your authenticated page without some version of your credentials riding along. Then there’s the task log, retained for debugging, which is a searchable transcript of everything you asked and everything the agent saw. I wrote about this specific mechanic for Perplexity’s Comet in what actually gets sent to their servers, and the shape is the same across the category. Breach that backend and the attacker gets a corpus: what you were working on, which vendors you use, the contents of pages you had to log in to reach, and enough session material to sometimes become you.

Proxy or gateway in the middle. This is the LiteLLM-shaped failure. A gateway exists to route, meter, and cache traffic across providers, and to do any of that it must see the request in plaintext. Your API keys sit there too. The LiteLLM breach was instructive because the product itself wasn’t the target of your trust; it was infrastructure your vendor picked, three layers below anything you agreed to. You can’t audit a supply chain you never saw.

Local agent, your own key. The extension runs inside the Chrome tab that’s already logged in. It reads the DOM locally, builds a prompt, and sends that prompt to the model API. One hop, to a provider you chose. There is no product company holding a copy, because there’s no server in the middle to hold one.

What a breach of the middle actually gets

Not “some metadata.” The prompts are the sensitive part, and people forget that because prompts feel ephemeral. They aren’t. A year of agent logs is a better dossier on your work than your email, since email is what you sent other people and prompts are what you actually thought.

The part I can’t hand-wave

Local execution does not mean your data goes nowhere. If you ask Claude or GPT-5.2 to summarize a page, that page content goes to Anthropic or OpenAI. Full stop. Those companies can be breached too, and one of them just was.

What changes is the count. BYOK collapses three or four parties down to two: you and the lab. You hold the key, you can rotate it in ten seconds, you can see the usage in your own dashboard, and when a vendor between you and the model gets popped, you’re not in the blast radius because there is no vendor between you and the model. That’s not perfect privacy. It’s just a much smaller damn surface, and smaller surfaces are the only defense that keeps working when everyone’s incident response fails at once.

We built Dassi this way partly out of laziness. Running a fleet of cloud browsers is expensive, and storing user page content is a liability I’d rather not carry insurance against. Dassi runs in your side panel, uses the tab you’re already authenticated in, and calls the model with your key or your existing ChatGPT login. Either way our servers don’t see the page.

Delangue is right that the industry should disclose more. I’d just rather have less to disclose. Every breach post-mortem for the next few years is going to include some variation of “the exposed data included user conversation logs,” and the companies writing that sentence will all have been very transparent about it.