Anthropic is backing away from its data retention requirement for enterprise customers with the launch of Claude Fable 5.1 and Claude Mythos 5.1, after pushback from enterprises that the policy made it difficult to use the company’s most capable models with sensitive information.
The company said its new Enterprise Frontier Safeguards (EFS) system will eventually give customers the privacy protections of Zero Data Retention (ZDR) while allowing Anthropic to maintain sophisticated safeguards against misuse.
The move is significant for enterprises operating under strict data protection, regulatory and sovereignty requirements. It follows OpenAI’s decision last month to announce a Private Safety Processing system to support ZDR for its frontier models, as a way to conduct safety monitoring without retaining customers’ prompts and outputs. OpenAI is preparing to launch its own new frontier model with “critical” cybersecurity capabilities, Astra.
Anthropic Changes Course on Retention
The reversal comes less than three months after Anthropic launched its Mythos-class models, including Fable 5, with a policy requiring 30-day retention of data, effectively eliminating Zero Data Retention (ZDR) options and prompting companies like Microsoft to restrict internal use.
The company had argued the retention was necessary to identify sophisticated misuse by analyzing activity across multiple requests. But enterprises operating in regulated industries, including financial institutions, healthcare providers and legal firms have been unable to adopt the models, as storing proprietary data violates privacy frameworks and General Data Protection Regulation (GDPR) requirements.
Anthropic has acknowledged that, taking “steps towards addressing the feedback we’ve received from customers on price, data retention, and safeguards.”
“Our new system of Enterprise Frontier Safeguards (EFS) gives customers complete privacy (the same as a zero data retention policy) while still being state-of-the-art at preventing adversarial use,” according to the announcement.
“EFS works by storing data in cloud infrastructure controlled entirely by the customer, not Anthropic. It will be made available to enterprise customers in phases, beginning later this fall. Until EFS is available, eligible customers will be able to use Fable 5.1 with zero data retention.”
Anthropic said that it introduced the 30-day data retention policy starting with Fable 5 for security reasons, as it has “seen substantial evidence of attempted misuse of AI models. These range from typical forms of abuse, such as fraud, to sophisticated cyberattacks, which can include agents autonomously engaging in destructive behavior.”
Some of these instances involved theft or misappropriation of enterprise customers’ credentials, the company added, which it said were difficult to detect without the ability to monitor traffic.
“This policy was not motivated by a desire to train on enterprise data: Anthropic has never trained on enterprise data without explicit permission, and never will,” the statement claimed.
The company argued that monitoring sophisticated misuse requires retaining information across multiple interactions, sessions and accounts, particularly when agents are involved in potentially destructive activity.
However, discussions with more than 100 enterprise customers exposed a conflict between those security requirements and corporate data governance.
“The enterprises we worked with generally understood the safety and security value of data retention, but many–especially in regulated industries–found it difficult to use models with data retention.”
EFS will be supported on Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google’s Agent Platform, and Microsoft Foundry.
The Data Sovereignty Question
The move towards ZDR by both OpenAI and Anthropic points to a growing contest between frontier AI providers over one of the biggest barriers to enterprise adoption, which goes beyond whether an AI provider technically retains prompts for 30 days. The bigger question is where enterprise data resides, who controls it, who can access it and which organization is responsible for monitoring it.
Both companies are trying to manage the tension between two requirements that pull in opposite directions. Frontier models need increasingly sophisticated monitoring because their capabilities create new opportunities for misuse, but enterprise customers want assurances that sensitive information used by those models remains under their control.
Like OpenAI’s PSP, Anthropic’s EFS architecture is designed around customer-controlled infrastructure. Activity data used for monitoring can be stored in the customer’s own cloud environment, including Amazon S3, Azure Blob Storage or Google Cloud Storage.
Customers can also use their own encryption keys, access policies and audit logging. The controls are designed to work whether Claude is accessed directly or through its cloud partners, Anthropic said.
Enterprises increasingly need to demonstrate that they retain meaningful control over the location of data and access to it, in addition to robust protection. Keeping monitoring data inside an organization’s cloud account can simplify that governance model and reduce the number of third parties that need to be treated as trusted data processors.
Anthropic said its approach allows enterprises to determine who reviews flagged activity, which is an important consideration where regulations or internal policies restrict access to non-public information or sensitive customer records.
While Zero Data Retention can remove one of the barriers to putting frontier models in front of highly sensitive workloads, it does not resolve every data protection or sovereignty requirement.
Enterprise buyers will need to establish exactly what “zero retention” covers.
Questions should include whether prompts, responses, logs, metadata, telemetry and safety signals are retained; whether any human can access customer content; where monitoring data is stored; who controls the encryption keys; and which jurisdictions can access the underlying infrastructure.
The distinction between data retention and data location is particularly important, because a provider can promise not to retain prompts while other operational data remains subject to its infrastructure, legal jurisdiction or access controls.
Frontier AI Raises the Stakes
Anthropic describes Fable 5.1 as its general-access model available to enterprise customers, Mythos 5.1 is restricted to vetted organizations through Anthropic’s trusted-access programs because of its capabilities in cybersecurity and biology.
Fable 5.1 is designed for long-running, autonomous workloads that can span applications, browse the web, work through Slack requests, operate browsers and function as managed agents. Anthropic says it can undertake multi-day coding projects and complex knowledge-work tasks with minimal oversight, capabilities that increase the amount and sensitivity of information it could potentially encounter.
A model processing a customer service transcript presents one set of data protection concerns, whereas an agent capable of navigating systems, writing code, conducting research or interacting with enterprise tools can potentially access a much broader range of corporate information.
Enterprises increasingly need to consider data protection alongside agent permissions, identity, monitoring and auditability.
The security implications are becoming more pressing for financial institutions in particular. Scott Dawson, CEO at payment processing firm DECTA UK, warned that frontier AI could intensify an existing fraud arms race as the technology makes attacks faster, cheaper and more convincing.
“That arms race was always coming, but the pace it is now arriving and at which financial institutions will need to be able to respond should concentrate minds in every fraud and compliance team in the country.”
But Dawson cautioned that speed cannot come at the expense of testing and control. Changes to fraud and compliance systems “will need to be properly tested and controlled before deployment, with appropriate safety nets in place.”
The warning indicates why data protection, monitoring and governance need to develop alongside frontier AI capabilities, particularly in sectors where a compromised model or AI-enabled attack could have systemic consequences.
An enterprise deploying an agent across customer service systems, financial applications, internal documents or software repositories may be exposing considerably more information than it would through a conventional chatbot interaction.
For CIOs, CISOs and data protection teams, ZDR is likely to become one part of a broader procurement checklist: where does the data go, who controls it, who can see it, how long does it exist and can the enterprise prove all of that to its customers and regulators?
Zero data retention also needs to be separated from data sovereignty. A provider can promise that prompts and outputs will disappear after processing while other information generated during an AI interaction remains subject to its infrastructure and jurisdiction. For multinational and regulated organizations, the location and legal control of data can be as important as retention.
Those questions could become as important to frontier-model selection as benchmark performance and price.
Anthropic’s reversal indicates that enterprise customers are beginning to exert influence over how frontier AI providers design their safety architectures.