Anthropic is preparing to soften the data retention policy it imposed on its most advanced AI models in June, moving to let enterprise customers keep the required logs on their own cloud infrastructure rather than on Anthropic's systems, according to reports from Bloomberg and Reuters on August 20, 2026.

The change, reported citing an unnamed source familiar with the plans, is the latest turn in an escalating battle over enterprise AI privacy — one where rival OpenAI has been aggressively positioning itself as the safer bet for corporate data. The episode has become one of the defining competitive storylines in enterprise AI this summer, and you can follow every development in our ongoing AI industry coverage.

What Anthropic announced in June

On June 9, 2026, Anthropic introduced a new 30-day data retention policy for Claude Fable 5 and other models with similar or higher capability levels. The policy applied both to Anthropic's own products and to third-party surfaces that host its models, with the company pledging to delete the data after 30 days in what it described as "almost all cases."

Anthropic framed the retention window as a security necessity. "The data will help us defend against complex and novel attacks (including new jailbreaks and attacks that operate across many requests) as well as help us identify and reduce false positives," the company said in its June 9 announcement.

The policy also contained a stricter provision: prompts and outputs flagged by Anthropic's trust and safety classifiers as potentially violating the company's usage policy could be retained for up to two years.

The backlash from corporate customers was swift. A day after the announcement, on June 10, it was reported that Microsoft was limiting its employees' use of Claude Fable 5 while the company's legal teams evaluated the changes to Anthropic's data retention requirements.

How the revised policy would work

Under the planned revision, enterprise customers using Anthropic's most capable models would still be required to retain their data for 30 days — but they would be allowed to hold that data on their own cloud computing infrastructure instead of handing it to Anthropic, according to Bloomberg's report.

Anthropic plans to roll out the new arrangement later this year and has reportedly been working with customers in highly regulated industries for months to develop the option. The company did not immediately respond to a request for comment from PYMNTS.

The compromise is designed to preserve Anthropic's safety argument — that a retention window helps detect sophisticated attacks and reduce false positives — while addressing the sovereignty concerns of banks, healthcare providers, and other enterprises that cannot ship regulated data to a third party.

OpenAI sees an opening

The policy shift comes as OpenAI has made enterprise privacy a direct attack line against its rival.

On August 19, 2026, OpenAI announced it was testing Private Safety Processing, a system the company says can identify serious safety risks that only become visible across multiple interactions — all while continuing to offer Zero Data Retention for eligible API customers. OpenAI plans to begin rolling out the feature in September.

The announcement was accompanied by an unusually direct public argument: OpenAI told Axios that it does not need to store customers' business data to keep its models safe, implicitly framing Anthropic's retention requirement as both unnecessary and risky.

The pitch appears to be working. New data reported by TechCrunch on August 20 indicates that OpenAI is gaining ground on Anthropic with business users, a segment where Anthropic's Claude models had built a strong early lead among developers and enterprises.

Why retention became a battleground

For enterprise buyers, data retention has become one of the most consequential questions in AI procurement. Prompts and outputs sent to frontier models can contain customer information, source code, financial data, and trade secrets. How long a vendor keeps that material — and where — determines compliance obligations under regimes such as GDPR, exposure in the event of a breach, and the legal risk of vendor-side safety review.

Anthropic's original policy essentially asked enterprises to accept that their most sensitive AI interactions would sit on Anthropic's servers for a month, with flagged content potentially held far longer. For companies in regulated industries, that was a hard sell — and OpenAI moved quickly to make it harder.

The revised arrangement, if implemented as reported, would let such customers meet the retention requirement inside their own security perimeter, potentially neutralizing the objection without abandoning the safety rationale.

What to watch

Several questions remain open. Anthropic has not publicly detailed how customer-held data would be audited or verified, nor how the two-year retention provision for flagged content would interact with the new option. OpenAI's Private Safety Processing, meanwhile, will face its own scrutiny when it launches in September over whether privacy-preserving safety analysis can actually match the detection performance of conventional retention.

What is clear is that enterprise AI privacy has moved from a compliance footnote to a primary competitive weapon — and that both companies now treat the handling of customer data as a product feature in its own right.

---

Stay Ahead of AI

Get the latest AI news, analysis, and breakthroughs — all in one place.

Read more AI news →