The company that said "no exceptions" two months ago is now building an exception
Here's the deal: Bloomberg reported on August 20 that Anthropic will give business customers more control over how their data is retained on its most capable models.
The specifics matter. A new safety system is expected to ship later this year, and under it enterprise customers still have to retain data for 30 days. What changes is where. They'll be able to keep those logs in their own cloud infrastructure rather than Anthropic's.
Same window, different custody. On paper that reads like a minor adjustment. To anyone who has run an enterprise security review, it isn't minor at all. Whether data lives in your VPC or a vendor's account rewrites half a compliance package — jurisdiction, access logging, key ownership, incident response responsibility all fork at that line.
The interesting part is why this adjustment exists. Two months ago Anthropic made exactly the opposite call, and it cost the company in the market.
Who's involved — Mythos-class models, ZDR, and June 9
Start with ZDR (Zero Data Retention). It's a standard contract term for enterprises buying AI APIs: don't keep our requests or your responses. In regulated industries — finance, healthcare, legal — it was effectively mandatory, and for years it was a core selling point for every frontier lab.
Mythos-class models is Anthropic's label for its top tier. It covers Claude Fable 5 and Claude Mythos 5, plus future frontier releases. The classification matters because the policy attaches to model tier, not to account. Lower-tier models keep the old contract terms; the moment you call the top tier, different rules apply.
June 9 is the pivot. Shipping Fable 5 and Mythos 5, Anthropic announced that every prompt sent to and every output generated by those models would be logged for 30 days. The justification was cybersecurity: to detect and prevent novel attacks carried out with its own models, the company argued, it needs the logs.
The problem was how it applied. Anthropic extended the policy retroactively to commercial customers who already held ZDR agreements. In the company's own words: "we are requiring limited data retention and review as part of our safety work. Prompts submitted to, and outputs generated by, covered models are retained for 30 days to support our safety work, on every platform where these models are offered."
No exceptions. No opt-out. No grandfathering. And when automated systems flag content as potentially harmful, a human can look at it.
What actually happened — in order
| Date | Event |
|---|---|
| 2026-06-09 | 30-day retention announced with Fable 5 / Mythos 5, applied to existing ZDR customers |
| June–July | Enterprise pushback. Microsoft reportedly restricted Fable 5 in some internal deployments |
| Recently | Anthropic concedes in its own report that the policy will be "unpopular" |
| 2026-08-19 | OpenAI unveils Private Safety Processing — safety checks without retention |
| 2026-08-20 | Bloomberg reports Anthropic is preparing a customer-cloud retention option |
The Microsoft item is the loudest signal. Microsoft has its own zero-retention commitments baked into products like GitHub Copilot. Routing developer code through a model that logs everything for 30 days collides with that head-on, and it reportedly restricted Fable 5 in certain internal deployments as a result. From Anthropic's seat, one of its largest distribution partners was using less of the product because of a policy choice.
Anthropic saw it coming. The company wrote in a recent report that the policy would "be unpopular with customers who have come to expect zero retention, and pose real risks to our business success (especially if competitors do not follow)." That's a declaration that it would accept commercial damage for safety reasons — and also a remarkably accurate forecast of the size of that damage.
Worth being fair about the original decision, though. June's policy looks reckless because we know how it landed, not because the reasoning was thin. As frontier models get better at cyber tasks, the argument that a vendor needs to see attack patterns first is one the whole industry has been making — OpenAI itself paused a training run in August because it couldn't rule out that a model had reached the top cyber tier of its internal framework. The dispute was never really about whether to look at logs. It was about who got to decide where those logs live.
What each side gets
Anthropic gets back to the negotiating table. To clear procurement in a regulated industry you need a sentence that says data never leaves your control. A customer-cloud option restores that sentence. The design tries to have both: the safety telemetry stays available, the jurisdiction goes to the customer.
There's also a pre-IPO calculation. On the same day, August 20, Bloomberg reported Anthropic is preparing to file publicly for its IPO as soon as the end of this month. Filings disclose customer concentration and revenue risk. "Major partner reduced usage over a policy dispute" is not a line any company wants in that document.
Enterprises get half a win. With data in their own account, jurisdiction and access control come back. But the 30-day retention itself doesn't go away. You still can't tell an auditor you store nothing. Storage cost and deletion hygiene also shift onto the customer.
Legal and compliance teams gain something real too. If the 30-day logs sit inside the customer's account, they fall under a data-handling regime that's already been approved. It stops being a new-vendor review and becomes an extension of existing controls. In regulated sectors that difference shows up as weeks or months of calendar time — which is precisely the sales cycle Anthropic is trying to shorten.
OpenAI gets an opening. On August 19 it unveiled Private Safety Processing, which claims automated systems can flag potential misuse and return limited safety signals without exposing the underlying prompts or responses to OpenAI personnel. Human review is narrowed to child sexual abuse material. It's in testing with companies including Databricks and Microsoft, with wider release planned for September.
The timing is not subtle. A competitor is losing accounts over a policy, and OpenAI ships a product aimed exactly at that seam.
The privacy infrastructure category gains status. Apple's Private Cloud Compute, Google's Private AI Compute, Meta's Private Processing — every major platform is now pushing an architecture that promises to process data without reading it. A new axis of competition in AI infrastructure is forming around it.
Precedents — how policy reversals played out
AWS and data sovereignty from 2015 onward is the useful template. When European customers balked at putting data on US clouds, AWS expanded regional infrastructure and eventually let customers hold their own encryption keys. The vendor that let customers decide where data lives won the regulated-industry market. Anthropic's adjustment is following that playbook.
Apple's 2021 on-device CSAM scanning plan cuts the other way. Apple proposed hashing photos on the device to detect abuse material, hit fierce privacy opposition, and shelved it. The lesson: a safety purpose does not automatically justify a privacy cost. However good the rationale, a policy dies when users feel control was taken from them.
Slack's and Adobe's AI training terms in 2023–2024 rhyme too. Both quietly inserted language allowing customer data to be used for AI, both got caught by their communities, and both were walking it back within days. The common thread was retroactivity. Apply a new rule automatically to customers who signed under old terms and trust breaks faster than the policy itself.
The DPA cleanup around GDPR in 2018 is the constructive case. Vendors then also tried unilateral changes under a "regulation made us do it" banner. What actually became market standard was contract structure that let the customer choose processing location and retention period — which is exactly what Anthropic is now building.
The Schrems II fallout in 2020 overlaps most directly. When the EU's top court invalidated Privacy Shield, every US SaaS with European customers had to rewrite contracts overnight. Two approaches survived: keep the data inside Europe, or hold the keys yourself so the vendor only ever touches ciphertext. Five years on, AI vendors are standing at the same fork. Anthropic is choosing the first, OpenAI the second, and which becomes the standard depends on how regulators come to view safety logging.
How competitors counter
OpenAI has already played. Private Safety Processing is slated for wider release in September, with Databricks and Microsoft as reference accounts. Against Anthropic's looser "later this year," that's a few months of head start. OpenAI's approach has its own burden of proof, though: a claim that you extract only safety signals and never see the text is verifiable only if you publish what the signals are and how they're derived.
Google is pushing the same axis with Private AI Compute, plus a distribution advantage in Gemini's integration across Workspace and Cloud. If your data already lives in Google Cloud, keeping it inside that boundary is architecturally easier.
The open-weight camp — Meta, Mistral, Alibaba — gets a tailwind. Download the weights, run them on your own infrastructure, and the retention debate never starts. In a period when capability gaps are narrowing, "nothing ever leaves" is a strong commercial argument.
Security researchers are skeptical of both. Cryptographer Matthew Green has argued that "private inference isn't private enough" — that AI agents reaching into sensitive data create exposure that technical protections alone don't close. That critique applies equally to Anthropic's customer-cloud retention and OpenAI's no-exposure processing.
What actually changes for you
If you run security in a regulated industry, this is renegotiation season. Plenty of organizations either stopped using the top tier or dropped to lower models when ZDR broke in June. A customer-cloud option puts the procurement case back on the table. Your question list just got longer, though: exactly which account and region holds the 30-day data, who controls the encryption keys, under what conditions Anthropic personnel can query it, and who attests to deletion at day 31.
If you're a developer, check whether the model you're calling is Mythos-class. The policy binds to model tier, so the same API key can produce different data handling depending on the model string. If you have workloads that legally cannot be logged, model selection has become a compliance decision.
If you sell an AI product, this is a textbook vendor-risk case. When your upstream model provider changes terms, it breaks the promises in your own contract. Microsoft couldn't dodge that collision. Now is a good time to check whether your agreements address downstream policy changes, and whether you have an abstraction layer that lets you swap models without rewriting the product.
If you're in Korea or another jurisdiction with data-localization rules, there's an extra axis. Personal information law and financial-sector network separation rules trigger separate procedures the moment data leaves the country. Until now, using a frontier model meant accepting that burden or walking away. If the customer-cloud option supports domestic regions, the math changes — but which clouds and which regions are supported hasn't been disclosed, so it's too early to conclude.
If you invest, read this as competition in AI infrastructure widening from raw capability to data governance. As frontier performance converges, contract terms become the deciding factor. Given how much of Anthropic's revenue comes from enterprise APIs, a single policy of this shape is large enough to move a growth rate.
If you just use Claude, this story is about enterprise contracts. Consumer plans follow separate data policies and aren't part of this change.
🥄 Three Things You're Probably Wondering
— Does this mean zero retention is back? No. The 30-day window stays. Only the location changes. You still can't tell an auditor that nothing is stored. What does change substantially is the jurisdiction and access-control conversation once the data sits in your own account.
— When can I use it? "Later this year" is the only timeline on record. No release date, no list of supported clouds, no pricing. Compared with OpenAI's stated September expansion, Anthropic's schedule is the looser of the two.
— Are the safety logs genuinely necessary, or is it cover? Possibly both. Anthropic's stated reason — that detecting novel cyberattacks run through its models requires logs — sits on top of a real, industry-wide observation that frontier cyber capability is rising. But now that OpenAI has shipped an approach that claims to work without retention, the claim that logging is the only way has become a testable one. Which side is right won't be clear until the two systems' detection performance can actually be compared.
Sources
- Bloomberg — Anthropic Plans to Change Data Retention Policy for Advanced AI (2026-08-20)
- Anthropic Privacy Center — Data retention practices for Mythos-class models
- Anthropic — Frontier Safety Roadmap Updates
- The Register — OpenAI chases Anthropic's biz customers with zero data retention pledge (2026-08-20)
- Axios — OpenAI says it doesn't need to store customer's business data to keep models safe (2026-08-19)
- PYMNTS — Anthropic Plans to Tweak Data Retention Rules After Enterprise Concerns (2026-08-20)
- Yahoo Finance — Anthropic plans to change enterprise data retention policy, source says (2026-08-20)
Numbers and criteria are as of announcement and may change.



