Several major technology companies, including Palantir, Nvidia, and Booz Allen, have restricted or threatened to drop frontier AI models unless OpenAI and Anthropic can offer stronger guarantees on the safety of their sensitive data and intellectual property. At the root of this fresh demand is one policy change Anthropic made to its Fable model in June.
The Policy That Changed the Terms
The updated policy that Anthropic made in June of this year stated that the company would now retain usage logs for 30 days. Anthropic’s stated reason for this change is to detect and protect against complex, multi-session attacks. “Organizations who prefer the old zero retention guarantees are likely to get stuck using older models,” says Steven Swift, Managing Director at Suzu Labs. “Anthropic and other labs have very publicly been fighting against wide scale misuse of their products. In order to meaningfully find and fix novel abuse techniques, it is essential that Anthropic maintain logs for a period of time.”
This new policy means that the zero-retention arrangements that some customers relied on are no longer assured by the company. Both Anthropic and OpenAI labs state that their models will not be trained on customer data without the customer opting in.
Three Responses to One Policy
After the policy change, three leading technology companies have reacted in different ways. Palantir has insisted that Anthropic must offer irrevocable promises of zero data retention before its models are made available through Palantir’s software. Nvidia has limited usage of Anthropic’s tools to less sensitive tasks and routed proprietary projects to its own Nemotron AI models. Booz Allen has barred use of Anthropic’s models on cybersecurity work with proprietary software.
All three of these companies are taking these steps in order to protect sensitive data and IP from being retained by Anthropic in line with the new policy. “Possession is not ownership,” says Donald McFarlane, Board Member, Xcape Inc. “When I entrust proprietary code, business records, personal information, or other unpublished material to a cloud or AI provider, that must be deemed to create duties much like a traditional bailment: use it for the agreed purpose, protect it, and do not retain, repurpose, sell, or disclose it beyond that purpose.”
Not Training vs. Not Storing
In spite of the promise that Anthropic and OpenAI models are not trained on customer data by default, leading companies with sensitive proprietary data are not reassured. Misuse of the data and retention of it are two separate risks, each with its own potential consequences.
Customers worry that a model may end up learning from proprietary code, endangering their IP. In areas like government operations, chip design, and security work, any retention of customer data raises questions of compliance with security standards and regulations.
The Security Paradox
This issue is not between two sides where one approach is objectively more or less secure than the other; rather, it arises from AI labs and their enterprise customers having conflicting and contradictory security needs. Logging and monitoring is a core security practice that Anthropic is applying to itself in an effort to protect against the rising threat of “complex and novel” cyberattacks exploiting AI models.
On the other hand, security firms want their own code not to be kept in any other company’s logs. They are falling back on local open-weight models for certain tasks in order to keep their most sensitive work purely internal and protect proprietary data from external retention.
Anthropic's Answer and What Remains Open
Anthropic has responded to the pushback from major enterprise customers with the announcement of Enterprise Frontier Safeguards, which enables a balance between activity logging needs and customer privacy demands. The solution stores activity data in the customer’s own cloud under their own keys, rather than in Anthropic’s systems. Automated monitoring of these logs remains, but without any required human review by Anthropic’s staff.
The company is releasing this solution through a phased rollout, with broader availability of the product targeted for later this fall. The exposure window between the policy update in June and the fall release of the newly developed solution may have an impact on customers and their data in the intervening time.
What Enterprise Buyers Should Ask Before Signing
Enterprise customers of advanced AI models must ensure the security of their data as a top priority by weighing the retention terms against the performance of the model. With competing security demands creating friction between major AI labs and their customers, sovereign and self-hosted AI usage is gaining ground. Security leaders should be prepared to ask questions regarding retention policies and guarantees before agreeing to the terms offered by an AI company.