Anthropic is changing the data retention framework it imposes on enterprises using its most capable "Mythos-tier" models. Customers will still retain prompts and generated outputs for 30 days, but the storage will shift to clouds they control themselves, with Anthropic no longer holding the data directly. The rollout is planned for fall 2026, and the change has not yet been reflected in product documentation.

The 30-day retention period itself is not changing. What's shifting is the premise underlying enterprise adoption: who holds the data and under whose control it sits. This represents an attempt to reconcile, at the cloud boundary, the interests of enterprises that want to connect top-tier models to sensitive information with those of an AI provider wary of attacks that can only be detected by tracking multiple conversations. However, Anthropic has not disclosed how it will carry out safety monitoring within customer environments.

AD

The 30 Days Remain, But Custody Shifts From Anthropic to Customers

Bloomberg reported on August 20 that Anthropic will roll out a new safety system by year's end that will let enterprise customers store 30 days of data on their own cloud infrastructure. According to people familiar with the matter, the system was developed over several months in coordination with more than 100 customers, including Salesforce. The figure of over 100 customers and Salesforce's involvement have not been officially disclosed by Anthropic.

Boris Cherny, who leads Claude Code at Anthropic, confirmed the plan following Bloomberg's report. Cherny explained that while Mythos-tier models require additional safety measures, enterprises must also meet their own privacy rules and compliance requirements. He stated that the company will introduce a system this fall in which customers own and control the data while Anthropic itself does not retain it.

The previous policy was introduced on June 9, alongside the announcement of Claude Fable 5 and Claude Mythos 5. It applies to both models and to any future models Anthropic designates as having equivalent or greater capability. Anthropic said it would retain all traffic to the covered models for 30 days regardless of access route. The company explained that the data would not be used for training new Claude models or for any purpose beyond safety, and that human access would be logged.

The new approach does not mean a return to Zero Data Retention (ZDR) contracts, under which prompts and responses are not retained after processing. Customers will still be obligated to retain 30 days' worth of data. The difference is that the data will sit in an environment of the customer's choosing rather than being held by Anthropic itself. Where safety monitoring will actually take place, and how much information reaches Anthropic, remains undisclosed.

Which Enterprises Are Affected, and the Cloud Paths Where Data Already Stays Put

The organizations whose terms changed under the June 2026 retention requirement were those that had previously used ZDR. Anthropic's Privacy Center lists as covered: workspaces that configured ZDR through the Claude Console, organizations using Claude Code with ZDR through Claude Enterprise, and organizations connecting to Claude via ZDR through various cloud providers. Free, Pro, and Max consumer plans were excluded from this change, since they already retain inputs and outputs by default.

The data being retained consists of prompts sent to covered models and the outputs generated in response. It is normally deleted automatically after 30 days. Exceptions apply when automated Trust & Safety systems detect suspected danger, or when legal retention obligations exist. By default, humans cannot read conversations; only a small number of approved personnel can access the data through controlled channels, such as when investigating flagged content. Access logs are reportedly kept in a record that personnel cannot erase or alter.

Even under the current explanation, where data is stored depends on the access route. Retained data enabled through Amazon Bedrock stays with AWS, and data from the Google Cloud Agent Platform stays with Google Cloud. By contrast, when using the API directly through Anthropic, retention is enabled on a per-workspace basis and Anthropic itself handles the data. Customers who have already configured ZDR on Azure Foundry need to create a separate Azure Subscription for the covered models.

For this reason, it would not be accurate to characterize the fall rollout as "moving all data to customer clouds for the first time." In some configurations that go through AWS or Google Cloud, retained data already resides in the cloud provider's environment. Anthropic has not yet disclosed how far the new system will extend these existing pathways, or how it will handle direct API access and Claude Enterprise.

AD

Why Anthropic Won't Abandon 30-Day Retention

Anthropic's argument is that examining a single request cannot reveal sophisticated attacks. For example, a Best-of-N jailbreak sends hundreds of slightly varied prompts, betting that one of them will slip past safety measures. State-sponsored espionage and data extortion schemes can also appear harmless when individual interactions are spread across multiple accounts or long stretches of time.

Anthropic's Risk Report, published in August, noted that confidence in detecting attacks that combine multiple requests weakens in ZDR environments. When considering adversaries with advanced capabilities in biological or chemical domains, the report states that the company knows of no mitigation other than withholding sufficiently powerful models from enterprise environments that lack both strict identity verification and account-compromise protections. The report's evaluation cutoff date was July 15, and it does not assess the new system announced now.

Anthropic also acknowledged the business cost of this approach. The Risk Report states that 30-day retention will be unpopular among customers accustomed to ZDR, and that there is a real risk it could hurt the company's commercial success if competitors don't follow suit. Even so, the company judged that historical data is necessary to detect offensive cyber operations, support for bioweapons development, and sustained attacks using compromised API keys. It also notes that there have been actual cases where attacks were only detected by tracking multiple requests chronologically.

The customer-cloud approach is a way to reduce business friction without abandoning the 30-day retention requirement. Anthropic has stated that customers will control the data and that the company itself will not retain it. At the same time, it has not specified what it processes or receives from customer data in order to maintain safety. Based on the reporting and Cherny's remarks alone, it's unclear how Anthropic will achieve the same cross-conversation detection it currently relies on.

Before Counting Retention Days, Verify Processing Authority and Encryption Keys

OpenAI also announced "Private Safety Processing" on August 19, an approach designed to reconcile customer-controlled data with safety monitoring that spans multiple conversations. In ZDR deployments, data stays on infrastructure controlled by the customer, and automated systems extract limited safety signals from related conversations. OpenAI's staff are not designed to access the original prompts or responses. As an alternative, the company is also developing a method to encrypt data placed on OpenAI's own infrastructure using customer-controlled keys.

However, OpenAI's system is also still in preview. Anthropic's approach is slated for fall, but there is still no formal information on which plans, clouds, pricing, or general availability date will apply. Although both companies describe their systems as "customer-controlled," the practical implications hinge on details such as what permissions the safety system holds within the customer's environment, whether detection results can be traced back to original content, and who can decrypt data when legal retention or investigation requires it.

Enterprises need to verify implementation details beyond just the 30-day figure: whether customers can independently manage encryption keys, whether the code and logs behind safety monitoring can be audited, and whether the geographic location of data can be fixed. Once Anthropic publishes product documentation this fall and updates its existing Privacy Center, individual companies will be able to judge whether the system meets their confidentiality and compliance requirements.