P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

AI Security

Anthropic will let enterprises keep their AI data on their own cloud. The 30-day retention it fought pushback over does not go away, it moves

In one week OpenAI promised zero retention and Anthropic conceded on location, and the two moves reveal the same buried fact: serious safety monitoring on a frontier model reads your content across interactions, whoever holds it.

By Parminder Kumar Sharma · · 7 min read

A heavy dark metal storage drawer pulled open in near darkness, its interior an empty black space, a warm brass rail catching the light along its runner. In the dark lower right, the line: your data, your cloud, still read either way.

What changed this week

Anthropic told several outlets on 20 August that it will let enterprise customers satisfy its data-retention requirement on their own cloud infrastructure rather than on Anthropic's, a bring-your-own-cloud option developed with more than a hundred customers including Salesforce. The coverage framed it as Anthropic "letting companies keep their own data" after enterprise pushback.

Read the detail and the headline softens. The 30-day retention requirement does not go away. It moves.

Anthropic announced in June that it would retain all customer data for its most capable models, Mythos 5 and Fable 5, for 30 days, to detect and prevent attacks that span multiple requests. Customers disliked it. This week's change lets them hold those 30 days of data themselves. The clock, and the reason for it, are unchanged.

That matters because it happened in the same week OpenAI made the opposite-looking move, and the two together say something neither says alone.

Two labs, one week, opposite in public

On 19 August OpenAI previewed Private Safety Processing, a system it says lets it keep Zero Data Retention while still identifying misuse across related interactions, with no staff access to content. Anthropic, in its August risk report, took the reverse stance in plain words:

We have recently announced our plan to require 30-day data retention on our most capable models, a decision we believe will be unpopular with customers who have come to expect zero retention, and pose real risks to our business success (especially if competitors do not follow), but which we believe is essential to detect and prevent sophisticated attacks that span multiple requests.

One lab says: we must keep your data, and we will say so. The other says: we will not keep it, and we have built something clever so we do not have to. On privacy those are genuinely different, and the difference is worth money to a buyer.

Underneath, they are the same conclusion.

Opposite public positions, one shared conclusion

Opposite in public, identical underneath

Aug 2026

AnthropicRetain it, and say so plainlyOpenAIProcess it, promise no staff lookSomething readsmore than one interactionThe part neither route removes
Anthropic’s position is quoted from its August 2026 risk report; OpenAI’s from its 19 August post. The routes differ on privacy and on who holds the keys. They agree on the thing in the centre, which is why this week’s concessions changed where the data sits and not whether it is read.
Anthropic's stance is quoted from its August 2026 risk report and OpenAI's from its 19 August post. The two routes differ on privacy and key control; they meet on the node in the centre, which is why the week's concessions moved where data sits rather than whether it is read.

Both labs independently decided that the serious risks in a frontier model do not show up in a single prompt and response. OpenAI's own product policy lead gave the example: a user asks about a weakness in one conversation and about remote access in another, and only the pair reveals the intent. Anthropic reached the identical view from the identical reasoning. A multi-interaction attack is only visible to something that reads across interactions, and neither lab found a way around that, because there is not one.

The distinction the word hides

"Is my data private" sounds like one question. For a frontier model it is three, and this week's moves touched two of them while leaving the third exactly where it was.

One promise, three layers, and the one nobody moved

One promise, three layers, and the one nobody moved

Location

Where does the content physically sit?

Anthropic BYOC: moved to the customer's own cloud

Retention and access

How long is it kept, and who may look?

OpenAI ZDR: nothing retained, no staff access

Processing

Is the content read across interactions at all?

Neither move touched this. It is the point of the exercise

Both concessions this week were real and both were improvements. They moved the first two layers. The third is the one a buyer is usually asking about when they say “is my data private”, and it is the one that did not move, because a system that detects an attack spread across sessions has to read across sessions.

Layers as described in OpenAI’s 19 August post and Anthropic’s August 2026 risk report and 20 August retention change. The split into three is this site’s framing; the facts on each row are the vendors’ own.
The split into location, retention-and-access, and processing is this site's framing; the fact on each row is the vendors' own, from OpenAI's 19 August post and Anthropic's June and August statements.

Location is where the bytes sit. Retention and access is how long they are held and who may look. Processing is whether the content is read at all. Anthropic's BYOC changed the first. OpenAI's ZDR and Private Safety Processing change the second. Neither touched the third, because the third is the capability the whole exercise exists to preserve.

This is not a criticism of either lab. It is the point a buyer needs, because the marketing on both sides speaks to location and access, and the question a security team is usually asking is the processing one.

Anthropic called its own shot

The sequence is worth reading in order, because it is a rare case of a company predicting the market's move against itself in writing.

How the retention position moved, June to August 2026

  1. Jun 2026

    Anthropic requires 30-day retention

    For its most capable models, Mythos 5 and Fable 5, to detect multi-request attacks. Customers who expected zero retention object.

  2. Aug 2026

    Anthropic predicts the risk

    Its risk report calls the policy essential but warns of real risks to the business “especially if competitors do not follow”.

  3. 19 Aug

    OpenAI appears not to follow

    Previews Zero Data Retention with Private Safety Processing: cross-interaction detection without retaining content or granting staff access.

  4. 20 Aug

    Anthropic softens to BYOC

    Keeps the 30-day requirement but lets enterprises hold the data on their own cloud. Location moves; retention stays.

Dates from Anthropic's June retention announcement and August risk report, OpenAI's 19 August post, and the 20 August reporting of Anthropic's BYOC change. The risk-report quote is the one that predicts the outcome.

The risk report named the exact pressure, "especially if competitors do not follow", and within days a competitor appeared not to follow and Anthropic adjusted. That is not weakness. It is a company reading the board correctly and saying so before it had to.

What each move actually gives a buyer

The two concessions, by what they change and what they do not

OpenAI, ZDR plus Private Safety ProcessingAnthropic, 30-day retention plus BYOC
Content retained?No, per the ZDR promiseYes, for 30 days
Where it sitsCustomer infrastructure, or OpenAI under customer keysCustomer’s own cloud, under the new option
Staff access to contentNone statedGoverned by the retention arrangement, not eliminated
Content read by machine across interactionsYes, that is Private Safety ProcessingYes, that is what the 30 days is for
The buyer’s real questionWhat is in the safety signal that leaves?Who can reach the retained data on our cloud, and how?
Rows from OpenAI's 19 August post and Anthropic's June and August statements. The last column is the question a security team should carry into either contract, and neither vendor answers it in the announcement.

What to ask, whichever you buy

Take this with you

For a security or procurement team, not for the launch blog

  • Separate the three layers before you compare vendors. Location, retention and access, and processing are different guarantees, and a strong promise on one tells you nothing about the other two.
  • For OpenAI, ask what the safety signal contains, field by field, in writing. Category and severity is a good answer; a long run of categorised signals on one account is a channel, and worth understanding.
  • For Anthropic BYOC, ask who can reach the retained data while it sits on your cloud, and under what process. Bring your own cloud moves the location and can move the control, but only if the access model moves with it.
  • Ask both the same processing question: what is read, across how many interactions, and can any artefact derived from it outlive the content. Retention promises rarely cover scores, embeddings or flags computed from your data.
  • Decide your own regulatory line on machine processing without human access. Whether that is a disclosure under your obligations is a legal question with different answers by regime, and neither vendor can answer it for you.

The position

Both moves are real improvements and both labs deserve credit for making the trade-offs visible rather than burying them. Anthropic in particular said an unpopular thing plainly, which is rarer than it should be.

The thing to carry out of the week is not that one lab is more private than the other. It is that two frontier labs, working independently, arrived at the same technical necessity and dressed it in opposite marketing. Serious safety monitoring on a capable model reads your content across interactions. You can keep it and admit it, or refuse to keep it and process it in a sealed enclave, but you cannot both monitor for multi-step misuse and promise that nothing reads more than one step.

This is the fourth piece here this fortnight where an accurate document answers a narrower question than the reader is asking, after a framework that never named who produces its evidence, a breach notice that left the data types blank and a retention promise that was never a promise about processing. The word this time is "your own data". It is true, and it is about where the data lives, not about what reads it.

Sources

  1. PrimaryOffering Zero Data Retention for frontier models, 19 August 2026OpenAIaccessed 2026-08-21
  2. Reported byOpenAI previews zero-retention safety system as Anthropic requires data logsAxiosaccessed 2026-08-21
  3. Reported byAnthropic plans to change data retention policy for advanced AIBloombergaccessed 2026-08-21

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.