The Pew Research Center and AP published a poll last week that should bother every AI company more than it apparently does. Adoption is climbing — more Americans used AI tools in the past year than ever before — but trust in the results is actually declining. Roughly six in ten respondents said they do not trust AI systems to handle personal information responsibly, up from the year before, even as usage numbers moved in the opposite direction.

That’s a divergence worth staring at for a minute, because the standard tech industry response to distrust is “the product just needs to get better.” But this gap is not about capability. GPT-5.2 is unambiguously better than GPT-4 was. Claude is sharper than it was twelve months ago. And people are still less confident, not more, that their data is safe.

The trust problem has plumbing, not a model problem

So what’s actually driving the discomfort? I keep coming back to something Lea Kissner, who ran security engineering at Google and later became Twitter’s CISO, wrote about data trust models: users don’t distrust algorithms, they distrust data flows they cannot see. And with most AI tools, the data flow is essentially a black hole. You type something into ChatGPT, it goes to OpenAI’s servers, gets processed alongside hundreds of millions of other conversations, and comes back as a response you have no way to verify didn’t also get logged, used for training, or retained under policies that have already changed multiple times since you signed up.

The Pew numbers reflect people catching on to this even if they cannot articulate it in technical terms. They use the tool because it is useful, and they distrust it because they have no visibility into what happens between hitting “send” and seeing a response. Both things are true simultaneously, which is exactly why the gap keeps widening.

Where the data actually goes

Most people I talk to about this assume their AI conversation is sort of like a phone call — it happens, and then it’s gone. But the architecture of every major hosted AI tool works more like email forwarded through an unknown number of servers, each of which keeps a copy according to its own rules that you agreed to in a terms of service document nobody has ever finished reading, including me, and I say that as someone who should probably know better.

OpenAI retains conversations for 30 days by default, with an option to opt out that most users do not know exists. Anthropic’s retention policies differ between their consumer product and API. Google’s Gemini conversations feed into a data ecosystem so sprawling that even Google employees have described it as difficult to fully map. And every third-party AI productivity tool that sits between you and these models adds another retention layer, another server, another potential breach surface.

The Pew poll did not ask people to diagram their data flow. It did not have to. People can feel when they have lost control of something, even when they lack the vocabulary to describe what specifically they lost control of.

Browser-native execution as a trust architecture

A browser-native AI agent reverses the data direction entirely. Instead of your data going out to be processed, the AI comes to where your data already lives — your browser.

Dassi runs in Chrome’s side panel, reads the page you’re currently looking at, and when it needs the LLM, sends a request directly from your browser to whatever model provider you’ve configured with your own API key. The browsing context, the email you’re drafting a reply to, the financial dashboard you’re analyzing, the HR form you’re filling out — none of it ever touches a dassi server because there is no dassi server in the request path. Your bank page stays on your machine. Your medical portal stays on your machine. The LLM sees only what you explicitly send it, through a connection you control, to a provider you chose.

This is not a feature. It is an architectural decision that makes the entire category of risk that Pew is measuring structurally impossible.

BYOK and the single trust decision

The BYOK model collapses what would normally be a chain of trust decisions into one. When you use a typical AI productivity tool, you’re trusting the tool company, their infrastructure provider, their data retention practices, their security posture, their future acquirer, AND the underlying LLM provider. That is five or six trust decisions masquerading as one checkbox during signup.

With bring-your-own-key, you trust the LLM provider whose API key you hold. That’s it. You already made that trust decision when you created the account and entered your credit card. There is no additional company inserting itself into your data path, no aggregation layer accumulating your work product into a target worth breaching, no terms of service that might change next quarter because some startup got acquired by a company with different privacy values.

The gap won’t close with better PR

Pew will run this poll again next year. Adoption will be higher. And unless something structural changes about how AI tools handle data, trust will be lower still. Because the problem is not perception — it is architecture. People are correct to be uncomfortable with data flows they cannot see, and telling them the AI is “more accurate now” does absolutely nothing to address that discomfort.

The tools that close this gap will be the ones that never opened it in the first place. An AI that runs in your browser, sees what you see, and routes requests through your own key to your own provider does not need to earn your trust about data handling because your data never left your damn machine to begin with.