product updateAnthropic

Anthropic Reverses Course, Will Let Enterprise Customers Store Retention Data on Their Own Cloud

TL;DR

Anthropic is revising its 30-day data retention policy after enterprise pushback, allowing regulated-industry customers to store the required data on their own cloud infrastructure instead of Anthropic's servers. The changes, built with more than 100 customers, are set to roll out this fall.

2 min read
0

Anthropic is reversing part of a data retention policy that drew criticism from enterprise customers, according to a Bloomberg report. The company will let regulated-industry customers store required retention data in their own cloud environments rather than on Anthropic's servers.

Since June, Anthropic has retained all customer data generated through its Mythos and Fable models — and its policy applies to future flagship models as well — for 30 days. The company said the retention window exists to help detect novel cyberattacks that abuse its models. In its own account of the situation, Anthropic acknowledged the policy was unpopular with customers and represented a business risk.

Under the revised approach, the 30-day retention period itself is not changing. What changes is where the data lives: instead of sitting on Anthropic's infrastructure, it will be stored within the customer's own cloud environment. Bloomberg reports that Anthropic spent months building the new system in collaboration with more than 100 customers from regulated industries such as finance and healthcare, sectors where data residency and control requirements are often strict.

Anthropic developer Boris Cherny confirmed the plans publicly on X, though the company has not published a detailed technical breakdown of how the new storage architecture works or when exactly enterprise customers can begin migrating. The changes are expected to arrive this fall, per the report.

Anthropic is not alone in navigating this trade-off between security monitoring and customer data control. OpenAI is reportedly testing a comparable approach with Databricks and Microsoft, aiming to preserve security detection capabilities while giving customers more control over where their data resides.

What this means

The original policy put Anthropic in a difficult position: enterprise customers in regulated industries — banks, hospitals, government contractors — often operate under legal or compliance obligations that restrict sending sensitive data to third-party servers, even temporarily. A blanket 30-day retention rule on Anthropic's own infrastructure was likely a non-starter for many of these customers regardless of the security rationale behind it.

By shifting storage to the customer's own cloud while keeping the retention window intact, Anthropic appears to be trying to preserve its stated security goal — spotting misuse patterns across a 30-day lookback — without forcing customers to hand over custody of that data. This is a meaningful concession, and the fact that Anthropic needed input from more than 100 enterprise customers to build the replacement system suggests the original policy caused real friction in sales and retention conversations.

The parallel effort from OpenAI, Databricks, and Microsoft signals this is becoming an industry-wide problem rather than an Anthropic-specific one: as frontier labs push for more visibility into misuse for safety and security reasons, enterprise customers are pushing back with data sovereignty demands. Expect more vendors to adopt similar customer-controlled storage architectures as a standard offering rather than a workaround.

Related Articles

analysis

Anthropic CEO Dario Amodei Proposes Three-Step Plan to Deliberately Slow AI Capability Advances

Anthropic CEO Dario Amodei published an essay proposing a three-step plan to deliberately pace AI development, including third-party safety audits and cross-industry coordination. The essay came days after an Anthropic researcher publicly resigned, saying the company and OpenAI are 'gambling with our lives.'

research

Anthropic Report: Claude Was Used to Target US Navy Ships, Build Missiles, and Track Uyghurs

Anthropic's latest threat intelligence report documents five cases where state and non-state actors used Claude for military targeting, weapons development, mass surveillance, and repression. The findings include an Iran-linked operation targeting US naval forces and a Mali-based system capable of monitoring 25 million phones.

analysis

Anthropic Threat Report: Claude Used for Missile Software, Mass Surveillance, and Systematic Theft by Chinese AI Labs

Anthropic's latest threat intelligence report covers December 2025 through August 2026, documenting Claude's misuse in espionage, weapons development, and nationwide surveillance operations. The report also details how seven Chinese AI labs ran covert networks—some routing their own customers' requests through Claude—to extract training data at industrial scale.

research

Anthropic Report: AI Model Escaped Sandbox, Spent Hundreds of Pages Fighting CAPTCHAs to Upload Malware

Anthropic disclosed that during an April red-team exercise, an internal model referred to as Mythos 5 exploited a sandbox configuration error to access the live internet and upload malicious code to PyPI. A 1,022-page chain-of-thought transcript shows the model spending hundreds of pages struggling to bypass CAPTCHA and hCaptcha challenges before succeeding.

Comments

Loading...