This has been the quiet sore spot of the past few months. When Fable 5 and Mythos 5 launched in June, Anthropic introduced mandatory 30-day retention for all traffic on those models. The reasoning: misuse and sophisticated cyberattacks only show up when you can correlate patterns over time and across accounts. If you check each request in isolation and delete it right away, you miss the attacks that spread across weeks and dozens of sessions.
Anthropic kept insisting it would never train on that data. It didn’t help much. In regulated industries especially, the answer was blunt: we simply can’t use a model that retains data. Every additional data processor has to be disclosed to your own customers, contracts need updating, and who is allowed to look at logs is tightly governed at banks and law firms.
On September 1 came the reversal. Anthropic announced Enterprise Frontier Safeguards (EFS), citing “a lot of feedback” and several hundred hours of customer conversations, according to CNBC. The idea: zero data retention on Anthropic’s side, but monitoring still happens. Activity data lives in the customer’s own cloud, meaning their own S3 bucket, Azure Blob Storage, or Google Cloud Storage, under their own keys, access policies, and audit logs. Anthropic runs automated systems on top that scan a rolling window of traffic for serious misuse: attempts to build offensive cyber or biological capabilities, or signs of stolen credentials.
Here’s the key bit. When the system flags something, the alert goes straight to the customer. Their own people decide whether something is actually wrong. No Anthropic employee ever needs to see the data. EFS will be free, and it works whether you call the Claude API directly or go through Bedrock, Google Cloud, or Microsoft Foundry. Claude Code and Claude Enterprise are covered too.
It was built with more than a hundred customers, including the CISOs of the largest US banks via the Analysis and Resilience Center, plus companies like Comcast, KPMG, Mastercard, Salesforce, and Visa. The rollout starts in phases this fall. Until then, eligible customers get zero data retention on Fable 5 and Fable 5.1 as a bridge. For consumer subscribers on Mythos-class models, by the way, the 30-day rule stays in place.
What strikes me here: Anthropic didn’t just scrap the retention rule, it flipped the problem around. The monitoring stays, only the data moves to the customer. That’s technically harder than a simple policy change, and it’s a direct answer to OpenAI, which unveiled its own zero data retention offering just two weeks ago. Heading into an IPO, Anthropic can’t afford nervous enterprise customers. And let’s be honest: given the choice between “trust us” and “keep your own data,” most people won’t need long to decide.
Sources: Anthropic: Developing Enterprise Frontier Safeguards with our customers · CNBC: Anthropic changes data retention policy after pushback from customers