Anthropic Reverses Course, Will Let Enterprise Customers Store Retention Data on Their Own Cloud
Anthropic is revising its 30-day data retention policy after enterprise pushback, allowing regulated-industry customers to store the required data on their own cloud infrastructure instead of Anthropic's servers. The changes, built with more than 100 customers, are set to roll out this fall.
Anthropic is reversing part of a data retention policy that drew criticism from enterprise customers, according to a Bloomberg report. The company will let regulated-industry customers store required retention data in their own cloud environments rather than on Anthropic's servers.
Since June, Anthropic has retained all customer data generated through its Mythos and Fable models — and its policy applies to future flagship models as well — for 30 days. The company said the retention window exists to help detect novel cyberattacks that abuse its models. In its own account of the situation, Anthropic acknowledged the policy was unpopular with customers and represented a business risk.
Under the revised approach, the 30-day retention period itself is not changing. What changes is where the data lives: instead of sitting on Anthropic's infrastructure, it will be stored within the customer's own cloud environment. Bloomberg reports that Anthropic spent months building the new system in collaboration with more than 100 customers from regulated industries such as finance and healthcare, sectors where data residency and control requirements are often strict.
Anthropic developer Boris Cherny confirmed the plans publicly on X, though the company has not published a detailed technical breakdown of how the new storage architecture works or when exactly enterprise customers can begin migrating. The changes are expected to arrive this fall, per the report.
Anthropic is not alone in navigating this trade-off between security monitoring and customer data control. OpenAI is reportedly testing a comparable approach with Databricks and Microsoft, aiming to preserve security detection capabilities while giving customers more control over where their data resides.
What this means
The original policy put Anthropic in a difficult position: enterprise customers in regulated industries — banks, hospitals, government contractors — often operate under legal or compliance obligations that restrict sending sensitive data to third-party servers, even temporarily. A blanket 30-day retention rule on Anthropic's own infrastructure was likely a non-starter for many of these customers regardless of the security rationale behind it.
By shifting storage to the customer's own cloud while keeping the retention window intact, Anthropic appears to be trying to preserve its stated security goal — spotting misuse patterns across a 30-day lookback — without forcing customers to hand over custody of that data. This is a meaningful concession, and the fact that Anthropic needed input from more than 100 enterprise customers to build the replacement system suggests the original policy caused real friction in sales and retention conversations.
The parallel effort from OpenAI, Databricks, and Microsoft signals this is becoming an industry-wide problem rather than an Anthropic-specific one: as frontier labs push for more visibility into misuse for safety and security reasons, enterprise customers are pushing back with data sovereignty demands. Expect more vendors to adopt similar customer-controlled storage architectures as a standard offering rather than a workaround.
Related Articles
OpenAI Launches 'Private Safety Processing' to Detect Misuse Without Storing Enterprise Data
OpenAI has built a system called Private Safety Processing that detects misuse patterns across multiple interactions without storing customer inputs or outputs. The company says it only receives narrow safety signals—type and severity of activity—while data stays encrypted on customer infrastructure.
OpenAI Previews 'Private Safety Processing' to Detect Abuse Without Retaining Customer Data
OpenAI is previewing Private Safety Processing to select customers, an automated system that monitors for misuse across multiple sessions without retaining any customer data. The move directly contrasts with Anthropic's July policy allowing 30-day data retention for 'covered models' like Fable.
OpenAI Reaffirms Zero Data Retention for API Customers, Previews Private Safety Processing
OpenAI has reaffirmed its Zero Data Retention (ZDR) policy for eligible API customers using frontier models and previewed a new feature called Private Safety Processing, which the company claims allows safety monitoring without retaining customer data.
OpenAI Reaffirms Zero Data Retention for API Customers, Previews New Private Safety Processing
OpenAI has reaffirmed its Zero Data Retention (ZDR) policy for eligible API customers using frontier models and previewed a new capability called Private Safety Processing. The company says the new approach aims to preserve safety monitoring capabilities without requiring data storage.
Comments
Loading...