
Anthropic is letting enterprise customers store their own data instead of keeping it on Anthropic servers.
The 30-day retention window for detecting cyberattacks stays in place, but customers will now control where data sits.
The change arrives this fall after months of feedback from over 100 regulated-industry clients.
What happened
Anthropic is reversing a policy introduced in June that stored all customer data from Mythos and Fable models on its own servers for 30 days. Under the new arrangement arriving this fall, that 30-day retention window remains, but data will now reside in the customer's cloud instead of Anthropic's servers.
Why it matters
Anthropic acknowledged the original policy was unpopular and posed a business risk. The company had stored data centrally to detect new cyberattacks leveraging its technology, but enterprise customers—particularly those in regulated industries—pushed back against the practice. The shift lets businesses keep tighter control over sensitive information while maintaining the security window.
What to watch
Anthropic has spent months building the new system with more than 100 customers from regulated industries and plans to roll it out this fall. OpenAI is pursuing a different approach with Databricks and Microsoft to balance security with data control, suggesting the industry is converging on ways to address enterprise data concerns.
Ask the AI about this article →
Anthropic introduced its centralized data storage policy in June as a security measure, aiming to detect novel cyberattacks exploiting its Mythos and Fable models. The move backfired with enterprise clients, particularly those in regulated industries where data sovereignty and compliance requirements are non-negotiable. Rather than abandon the security goal, Anthropic spent months engineering an alternative with more than 100 customers, preserving the 30-day window for threat detection while shifting custody to the customer's own infrastructure. This represents a pragmatic concession to market pressure: the company recognized that a security feature customers will not adopt offers no protection. The timing also reflects broader industry tension—OpenAI's parallel work with Databricks and Microsoft on similar guardrails suggests that cloud providers and AI vendors are converging on hybrid models that try to satisfy both security and governance mandates.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Israeli startup DataAgent Ltd
SK Hynix presented a custom HBM concept at SEMICON Taiwan 2026, where compute functions are placed in the base…

Taoyuan is positioning itself as a northern hub for AI data centers (AIDC), citing the Tatan area and an LNG c…

The U.S. Department of Defense announced on August 31 that it has deployed ChatGPT Mil, a customized version o…

Nvidia reported earnings that were both remarkable and boring, reflecting its focus on avoiding a consolidated…

Anthropic has agreed to a $35bn cloud-computing contract with Lambda, a Nvidia-backed cloud provider
