One email each morning — yesterday's AI, sortedGet it in your inbox

METAL LAB

Anthropic Revises Enterprise Data Retention Policy, Moves Storage to Customer Cloud

The 30-day retention requirement stays, but storage location shifts from Anthropic's servers to customers' own cloud

이미지: The Decoder

Summary

  • Anthropic will revise this fall the 30-day data retention policy it implemented in June, moving the storage location from its own servers to customers' own cloud infrastructure
  • The policy had stored data from customers using powerful Claude models such as Mythos and Fable for cyberattack detection purposes, but drew strong backlash
  • Rival OpenAI is reportedly also testing a similar compromise with Databricks and Microsoft
기존 정책 시행 시점
2026년 6월부터
기존 보관 방식
Mythos·Fable 등 모델 데이터를 앤스로픽 서버에 30일 보관
새 정책 저장 위치
앤스로픽 서버 대신 고객사 자체 클라우드
보관 기간
30일 유지
도입 예정 시점
2026년 가을
공동 개발 참여
규제 산업 고객 100곳 이상과 수개월간 개발
경쟁사 동향
오픈AI, 데이터브릭스·마이크로소프트와 다른 방식 시험 중
공개 경로
앤스로픽 소속 보리스 체르니가 X에서 확인

Retention Policy Revised After Two Months Amid Enterprise Backlash

Anthropic will revise this fall the data retention policy it has run since June. The change would let enterprise customers using its most powerful Claude models store their data on their own cloud rather than on Anthropic's servers. According to Bloomberg, the new safety system keeps the 30-day retention requirement in place but lets customers choose where that data is stored.

What the June Policy Involved

Since June, Anthropic has stored all data for 30 days from customers using its Mythos and Fable models, as well as future flagship models, on its own servers. The stated goal was to use this data to detect new types of cyberattacks. The problem was the approach: data was collected and held by Anthropic regardless of whether customers wanted that, a condition that was hard to accept for customers in regulated industries who prioritize data sovereignty. Anthropic itself reportedly acknowledged in a report that the policy was unpopular and posed a business risk.

Storage Location Now Left to Customers

Under the new system, the 30-day retention requirement doesn't go away. What changes is where the data physically sits. Instead of Anthropic's servers, the data would reportedly stay on the cloud infrastructure customers already use, with Anthropic running its attack-detection logic against that location instead. The system was reportedly built over several months in collaboration with more than 100 customers in regulated industries, and the new policy is set to launch this fall. Anthropic developer Boris Cherny confirmed the plan publicly on X.

CategoryPrevious Policy (June–)New Policy (Fall, planned)
Retention period30 days30 days (unchanged)
Storage locationAnthropic's serversCustomer's own cloud
Applicable modelsMythos, Fable, and future flagshipsSame
PurposeDetecting novel cyberattacksSame

OpenAI Facing a Similar Dilemma

Rival OpenAI is grappling with the same issue. It's reportedly testing a different approach with Databricks and Microsoft that aims to satisfy both security needs and data control demands. Whether it's Claude or GPT, both companies are confronting the same reality: for enterprise customers, "where is my data" matters as much as model performance.

A Move Tied to Claude Security's Expansion

This policy change fits into the broader security product lineup Anthropic has been expanding recently.

On August 21, Anthropic released a public beta feature for Claude Enterprise Premium Seat users that lets the Mythos 5 model scan GitHub repositories for vulnerabilities. The feature requires admin activation and prerequisites including Claude Code web, Extra Usage, and installation of Anthropic's GitHub app. The data retention policy now being revised also targets the same Mythos family of models. Anthropic is simultaneously expanding its security features while addressing the backlash over the data collection methods those features require.

Editor's Take

This decision illustrates how safety and control don't always point in the same direction. Anthropic chose to collect data to catch novel attacks, only to reverse course within two months in the face of regulated-industry customers reluctant to hand that data over. It had to craft a compromise that preserves cyberattack detection capability while returning data ownership to customers.

For organizations that have deployed enterprise AI, this pattern is familiar. After reviewing a model's performance sheet, what often trips up adoption is the contract language governing where data is stored and who can access it. In sectors like finance and healthcare, where data export itself is regulated, deployment can fall through over a single storage-location clause no matter how good the model is. Korean companies looking to deploy Claude- or GPT-based models in regulated industries should first check, as in this case, whether an option exists to keep data on their own cloud.

The fact that OpenAI is preparing a similar compromise with Databricks and Microsoft shows this isn't a problem unique to Anthropic. Once both companies roll out their new systems this fall, enterprise customers may increasingly choose model providers based on where they want their data to live.

Comments