Apple's Evidence Is a List of Copies. Your AI Workflow Makes Them Too.
The Apple filing against a former employee, accused of taking company data with him on the way to OpenAI, got passed around my feeds all week, and the part that stuck with me wasn’t the accusation. It was the shape of the evidence.
Not testimony. Not a smoking-gun email. A log of moments where information moved from one container to another.
The proof is made of export events
Cases like this almost always come down to the same categories of artifact, because those are the categories a corporate machine actually records. Files copied to a personal drive. Documents synced to storage that isn’t the company’s. Screenshots taken of screens the employee had every right to look at. Text lifted out of an internal tool and dropped somewhere with a different owner.
Notice that none of those are accusations about reading. This person, by all accounts, had legitimate access to everything in question. Reading internal documents was the job. What turns access into a case is the moment a copy comes into existence outside the perimeter, because a copy is a discrete event with a timestamp, a source, a destination, and a size, and that combination is exactly what a forensic report is built to reconstruct months later when somebody’s lawyers go looking.
So the interesting question for the rest of us isn’t whether Apple’s evidence holds up. It’s how many export events an ordinary Tuesday generates.
Because I think the number is much higher than people assume, and almost all of it is voluntary.
Legitimized copy-out
Every mainstream AI workflow right now is built on the same primitive that shows up in the exhibit list.
You’re in Salesforce, or your admin console, or a customer’s support thread. You want the model’s help. So you select the page, copy it, switch tabs, paste it into a chat window, and hit enter. That’s a file leaving a system of record and landing in a different company’s infrastructure. Nobody logs it as an incident because you did it with your own hands, in a browser, for a legitimate reason. But structurally it’s indistinguishable from the thing that gets you deposed.
We wrote about the copy-paste tax mostly as a time problem. The time is real. The bigger cost is that you’re manufacturing a duplicate of internal data every few minutes and losing track of where the duplicates live.
Screenshots are worse, honestly. A screenshot of a dashboard pasted into a chat is a permanent, un-redactable, un-revocable image of whatever happened to be on screen, including the six rows of customer names you weren’t thinking about at all.
Reading in place
The alternative isn’t complicated. An agent that runs inside the tab you already have open reads what’s rendered, does the thing, and never produces a second copy that outlives the task.
What Dassi does instead of a paste
Dassi is a Chrome extension that lives in the side panel, so when you ask it to summarize the ticket queue or draft the reply or pull the numbers off the page, it works against the DOM of the tab you’re on. Your login is already there. You didn’t grant OAuth to a third party, you didn’t download an export, and there’s no intermediate file sitting in ~/Downloads with a customer list in it. (Chrome Web Store, free.)
I’m not going to pretend this makes data movement disappear. The relevant text still goes to a model somewhere, and if you’re pointed at a hosted API, that’s a network request like any other. What changes is that the movement is scoped to the task and it doesn’t leave a durable artifact behind. Nothing gets copied to a personal account. Nothing gets screenshotted into an image you’ll forget about. The page stays the page.
And that scoping is the whole argument. We went through the routing details in what actually gets sent where, and the short version is that most AI browser products send your page to their servers first, then to a model, which means there are now two organizations holding a copy of your internal document instead of zero.
The key you own
This is where BYOK stops being a pricing preference and becomes a compliance answer.
With your own API key, the request goes from your browser to Anthropic or OpenAI or Google under your account, governed by your provider’s zero-retention terms, billed to your card. No vendor in the middle building a corpus of everything their users looked at. If you’d rather not deal with keys at all, logging in with an existing ChatGPT subscription works too, and the same principle applies: one hop, one counterparty, no accumulating pile of your company’s documents on some startup’s S3 bucket.
The question I’d ask about any AI tool your team uses: if someone reconstructed the export log for the last ninety days, how much of it would be your employees helpfully feeding internal data into a chat box because that was the only interface on offer?
Nobody at Apple is going to sue you over a paste. Your security team might have opinions, though, and they’ll be reading the same kind of log.