The break is not cheap Claude access. Once a gateway owns the API key and forwards the request, it can read the prompt before it reaches the model and keep the response on the way back. That turns third-party AI access into a standing exposure channel for anything staff paste into it.
Okta says Poison Claude has grown to about 900 paying users. The service uses pooled AWS Bedrock trial credits and fake accounts to route requests through its own servers, which makes the operator the real trust boundary, not Anthropic or AWS.
Any AI proxy or resold model access built this way creates the same problem: the reseller can collect prompts, internal data, and usage over time, and patching the model side does nothing to remove what already passed through the middle.