A federal judge approved Anthropic’s $1.5 billion copyright settlement this week, and I keep snagging on one detail underneath that gigantic number. The case was about books. Around 500,000 of them, pulled from pirate libraries like LibGen and fed into early versions of Claude. Authors get roughly $3,000 per work. Anthropic gets to move on.

But strip away the dollar figure and the actual problem was simpler than “copyright infringement.” It was about data ending up somewhere it was never supposed to be, doing something nobody consented to.

Nobody signed off on this

The authors never handed their books over. Anthropic downloaded them, ran them through training, and the writers found out when a lawsuit dragged it into daylight. So this settlement isn’t payment for a fair deal that went a little sideways. It’s the price of taking data that happened to be sitting somewhere grabbable.

And that shape should feel uncomfortably familiar. Because it’s more or less what happens every time you drop something into a cloud AI tool and hit enter without thinking about the route it takes.

The route your data actually travels

Most AI tools you touch at work follow one path. You type a prompt or upload a file, it leaves your machine and lands on some company’s servers, sits there long enough to be logged and possibly cached, maybe gets folded into a future training run depending on which checkbox you did or didn’t find, and eventually an answer comes back. You saw the input box. You never saw the half-dozen hops behind it.

Anthropic’s own case is the tell. If a company that builds frontier models can end up on the wrong side of a $1.5 billion provenance fight over training material, the idea that your quarterly numbers or your client’s contract are being handled with perfect discipline once they leave your laptop starts to feel like wishful thinking. I wrote before about how AI companies don’t even trust each other with data, and this settlement is that argument with a court order attached.

A browser reads the page. It doesn’t mail it anywhere.

A browser agent runs where the page already sits. It reads what’s on your screen, locally, and skips the upload entirely because nothing has to leave to be understood.

BYOK means one hop, not three

So the interesting question stops being “is this AI tool trustworthy” and becomes “how many parties am I routing my data through.” With most setups, it’s three. There’s you, there’s the app in the middle that wraps the model and logs your traffic on the way past, and there’s the actual LLM provider at the end doing the thinking. That middle layer is the one you learn nothing about until it leaks, and proxy layers do leak, which is roughly the whole story of the LiteLLM breach.

Bring-your-own-key collapses that. You plug your own Claude or GPT or Gemini key straight in, and your prompt goes from your browser to the provider you already have a contract with. No middleman caching your inputs. No mystery vendor holding a copy of your Gmail thread on a server you can’t name. Dassi runs this way on purpose: it lives in your browser side panel, reads the tab you’re already looking at, and when it needs a model it talks to your provider directly using your key. Your data stays between you and the company you actually chose.

That’s a small design decision with an outsized consequence. The thing that got Anthropic into a courtroom was data moving to a place its owners didn’t sanction, and every extra hop in your own stack is one more place that can happen to you, quietly, until a headline tells you it already did. Cut the hops and most of the risk cuts with it. Not because the middleman was evil, but because a copy that was never made can’t be leaked, subpoenaed, or scraped into somebody’s next model.

What I’d actually take from a $1.5 billion number

The books will get most of the coverage. The precedent, the payout per author, whether this changes how anyone trains models next year. All fair.

But the durable lesson is duller and more useful: know where your data physically goes, and shorten the trip. A tool that reads the page locally and hands your key straight to the model you picked has almost nothing to lose on your behalf, because it’s barely holding anything. If you want to see what that feels like, dassi is free on the Chrome Web Store, and it’ll never ask you to trust a server you can’t see. Anthropic just paid a billion and a half to relearn that data has a location. Cheaper to remember it going in.