Anthropic will let enterprises keep their AI data on their own cloud. The 30-day retention it fought pushback over does not go away, it moves
In one week OpenAI promised zero retention and Anthropic conceded on location, and the two moves reveal the same buried fact: serious safety monitoring on a frontier model reads your content across interactions, whoever holds it.
By Parminder Kumar Sharma · · 7 min read

What changed this week
Anthropic told several outlets on 20 August that it will let enterprise customers satisfy its data-retention requirement on their own cloud infrastructure rather than on Anthropic's, a bring-your-own-cloud option developed with more than a hundred customers including Salesforce. The coverage framed it as Anthropic "letting companies keep their own data" after enterprise pushback.
Read the detail and the headline softens. The 30-day retention requirement does not go away. It moves.
Anthropic announced in June that it would retain all customer data for its most capable models, Mythos 5 and Fable 5, for 30 days, to detect and prevent attacks that span multiple requests. Customers disliked it. This week's change lets them hold those 30 days of data themselves. The clock, and the reason for it, are unchanged.
That matters because it happened in the same week OpenAI made the opposite-looking move, and the two together say something neither says alone.
Two labs, one week, opposite in public
On 19 August OpenAI previewed Private Safety Processing, a system it says lets it keep Zero Data Retention while still identifying misuse across related interactions, with no staff access to content. Anthropic, in its August risk report, took the reverse stance in plain words:
We have recently announced our plan to require 30-day data retention on our most capable models, a decision we believe will be unpopular with customers who have come to expect zero retention, and pose real risks to our business success (especially if competitors do not follow), but which we believe is essential to detect and prevent sophisticated attacks that span multiple requests.
One lab says: we must keep your data, and we will say so. The other says: we will not keep it, and we have built something clever so we do not have to. On privacy those are genuinely different, and the difference is worth money to a buyer.
Underneath, they are the same conclusion.
Opposite public positions, one shared conclusion
Opposite in public, identical underneath
Aug 2026
Both labs independently decided that the serious risks in a frontier model do not show up in a single prompt and response. OpenAI's own product policy lead gave the example: a user asks about a weakness in one conversation and about remote access in another, and only the pair reveals the intent. Anthropic reached the identical view from the identical reasoning. A multi-interaction attack is only visible to something that reads across interactions, and neither lab found a way around that, because there is not one.
The distinction the word hides
"Is my data private" sounds like one question. For a frontier model it is three, and this week's moves touched two of them while leaving the third exactly where it was.
One promise, three layers, and the one nobody moved
One promise, three layers, and the one nobody moved
Location
Where does the content physically sit?
Anthropic BYOC: moved to the customer's own cloud
Retention and access
How long is it kept, and who may look?
OpenAI ZDR: nothing retained, no staff access
Processing
Is the content read across interactions at all?
Neither move touched this. It is the point of the exercise
Both concessions this week were real and both were improvements. They moved the first two layers. The third is the one a buyer is usually asking about when they say “is my data private”, and it is the one that did not move, because a system that detects an attack spread across sessions has to read across sessions.
Location is where the bytes sit. Retention and access is how long they are held and who may look. Processing is whether the content is read at all. Anthropic's BYOC changed the first. OpenAI's ZDR and Private Safety Processing change the second. Neither touched the third, because the third is the capability the whole exercise exists to preserve.
This is not a criticism of either lab. It is the point a buyer needs, because the marketing on both sides speaks to location and access, and the question a security team is usually asking is the processing one.
Anthropic called its own shot
The sequence is worth reading in order, because it is a rare case of a company predicting the market's move against itself in writing.
How the retention position moved, June to August 2026
Jun 2026
Anthropic requires 30-day retention
For its most capable models, Mythos 5 and Fable 5, to detect multi-request attacks. Customers who expected zero retention object.
Aug 2026
Anthropic predicts the risk
Its risk report calls the policy essential but warns of real risks to the business “especially if competitors do not follow”.
19 Aug
OpenAI appears not to follow
Previews Zero Data Retention with Private Safety Processing: cross-interaction detection without retaining content or granting staff access.
20 Aug
Anthropic softens to BYOC
Keeps the 30-day requirement but lets enterprises hold the data on their own cloud. Location moves; retention stays.
The risk report named the exact pressure, "especially if competitors do not follow", and within days a competitor appeared not to follow and Anthropic adjusted. That is not weakness. It is a company reading the board correctly and saying so before it had to.
What each move actually gives a buyer
The two concessions, by what they change and what they do not
| OpenAI, ZDR plus Private Safety Processing | Anthropic, 30-day retention plus BYOC | |
|---|---|---|
| Content retained? | No, per the ZDR promise | Yes, for 30 days |
| Where it sits | Customer infrastructure, or OpenAI under customer keys | Customer’s own cloud, under the new option |
| Staff access to content | None stated | Governed by the retention arrangement, not eliminated |
| Content read by machine across interactions | Yes, that is Private Safety Processing | Yes, that is what the 30 days is for |
| The buyer’s real question | What is in the safety signal that leaves? | Who can reach the retained data on our cloud, and how? |
What to ask, whichever you buy
Take this with you
For a security or procurement team, not for the launch blog
- Separate the three layers before you compare vendors. Location, retention and access, and processing are different guarantees, and a strong promise on one tells you nothing about the other two.
- For OpenAI, ask what the safety signal contains, field by field, in writing. Category and severity is a good answer; a long run of categorised signals on one account is a channel, and worth understanding.
- For Anthropic BYOC, ask who can reach the retained data while it sits on your cloud, and under what process. Bring your own cloud moves the location and can move the control, but only if the access model moves with it.
- Ask both the same processing question: what is read, across how many interactions, and can any artefact derived from it outlive the content. Retention promises rarely cover scores, embeddings or flags computed from your data.
- Decide your own regulatory line on machine processing without human access. Whether that is a disclosure under your obligations is a legal question with different answers by regime, and neither vendor can answer it for you.
The position
Both moves are real improvements and both labs deserve credit for making the trade-offs visible rather than burying them. Anthropic in particular said an unpopular thing plainly, which is rarer than it should be.
The thing to carry out of the week is not that one lab is more private than the other. It is that two frontier labs, working independently, arrived at the same technical necessity and dressed it in opposite marketing. Serious safety monitoring on a capable model reads your content across interactions. You can keep it and admit it, or refuse to keep it and process it in a sealed enclave, but you cannot both monitor for multi-step misuse and promise that nothing reads more than one step.
This is the fourth piece here this fortnight where an accurate document answers a narrower question than the reader is asking, after a framework that never named who produces its evidence, a breach notice that left the data types blank and a retention promise that was never a promise about processing. The word this time is "your own data". It is true, and it is about where the data lives, not about what reads it.
Sources
- PrimaryOffering Zero Data Retention for frontier models, 19 August 2026OpenAIaccessed 2026-08-21
- Reported byOpenAI previews zero-retention safety system as Anthropic requires data logsAxiosaccessed 2026-08-21
- Reported byAnthropic plans to change data retention policy for advanced AIBloombergaccessed 2026-08-21


