This website uses cookies

Read our Privacy policy and Terms of use for more information.

On 14 September, The Information reported that Palantir, Nvidia and Booz Allen Hamilton have started demanding new guarantees from Anthropic, or cutting back their use of its Claude Fable models, over the way the company retains customer data. The article is paywalled, but Reuters, Quartz, PYMNTS and Investing.com relayed the substance within hours, and Anthropic's own privacy pages confirm the policy at the centre of it.

That policy is not complicated. Since 9 June, prompts sent to and outputs generated by Anthropic's 'covered models', which include Fable 5 and 5.1, are retained for 30 days on every platform where those models are offered, so that safety classifiers can spot misuse that only shows up across many requests. Content flagged by those systems can be held for up to two years. Organisations that previously held zero data retention (ZDR) agreements lost that guarantee for the covered models, which is what set the large customers off.

Most of us are not Palantir. But think about what goes into Claude or ChatGPT on a normal Tuesday: a client's cost report, a subcontractor's tender return, the payment terms from an appointment you are trying to summarise. The firms in this story applied a simple test to their most sensitive work, and there is nothing stopping a cost consultancy or a contractor's commercial team from applying the same one. We flagged zero data retention in passing last month in an OpenAI context. It now has named casualties.

Who pulled back, and how far

Nvidia reportedly restricts Fable to lower-stakes tasks such as open-source software and relies on its own Nemotron models for sensitive work like supply chain monitoring, according to The Information as relayed by PYMNTS.

As a company, you know, we believe ZDR [zero data retention] should be on by default.

Justin Boitano, Nvidia's vice president of enterprise AI

A hardware supplier and Anthropic investor is recommending the stricter setting by default. That is useful context when your own IT team says retention is fine because nobody reads it.

Booz Allen has barred staff from using Fable on the proprietary cybersecurity software it sells to clients. Its chief technology officer Bill Vass told The Information: "We worry a little bit that [Fable] might be learning from some of our code." He added that the concern applies to only a small share of the firm's work, which is the more interesting half of the quote. Booz Allen did not ban the tool. It drew a line around one category of work and left the rest alone.

Palantir reportedly will not offer Fable through its platform until Anthropic provides an irrevocable ZDR guarantee, though Palantir customers can still contract with Anthropic directly. Investing.com reports that Palantir continues to offer OpenAI's GPT-6 Astra under explicit ZDR agreements.

An executive at a major US utility reportedly told The Information the company scrapped plans to test Fable on core power infrastructure after Anthropic declined to give the same assurance, while keeping it for finance and HR work. Microsoft, meanwhile, is reportedly pitching private, isolated server environments to worried clients, having restricted its own employees' access to Fable in June while its lawyers reviewed the terms.

Retention is not the same as training

It is worth being exact here because the two ideas get blurred. Anthropic's statement is that it "has never trained on enterprise data without explicit permission, and never will". OpenAI says enterprise customer data is not used to train its models unless customers opt in. Reuters reported that neither lab trains on customer data by default, though both collect anonymised metadata for product improvement.

What the 30 days actually means, per Anthropic's privacy centre, is that prompts and outputs sit in storage whereby default no Anthropic personnel can read them. Human review can happen only through a controlled access path when automated systems flag content, by a small set of approved reviewers, with every access recorded in a tamper-proof log. After 30 days the data is deleted unless flagged or legally required.

Palantir's chief executive Alex Karp has gone much further than the retention argument. On CNBC in July he claimed frontier labs are "stealing [their customers'] weights and alpha" and that enterprises are "livid" at paying for tokens that create no value. The claim comes from a competitor, while Anthropic’s own position says otherwise. Your client will not care about the distinction unless you can explain it clearly.

What the labs are offering instead

Anthropic announced Enterprise Frontier Safeguards on 1 September. Under it, the retained data lives in the customer's own cloud account, whether Amazon S3, Azure Blob Storage or Google Cloud Storage, under the customer's own encryption keys.

Anthropic's automated monitoring still runs, but flags go to the customer's security team, and no Anthropic human review is required. It was designed with more than 100 customers including Comcast, KPMG, Mastercard, Salesforce, Visa and the security chiefs of the largest US banks. It is free, though your cloud provider bills for the storage. It rolls out in phases later this autumn, and eligible customers get ZDR on Fable 5 and 5.1 in the meantime. Access is by application form.

OpenAI got there first on paper. On 19 August it reaffirmed ZDR for eligible API customers and previewed Private Safety Processing, which analyses patterns across interactions without OpenAI staff seeing the content, with rollout due in September. The word doing the work in both announcements is 'eligible'. A firm of 40 surveyors is not the customer either lab built these programmes for.

Why Pro versus Enterprise is the real question for smaller firms

Anthropic's own covered models page makes a point that most of the coverage skipped, and it cuts closer to home than anything Palantir did.

  • Consumer plans, including Claude Pro and Max, already retained inputs and outputs before June, so the change did not touch them, which means anyone pasting client data into a personal subscription never had zero retention to lose.

  • Zero data retention has only ever been an organisational arrangement, agreed in contract for API workspaces, Claude Enterprise or access through Bedrock, Google's Agent Platform and Microsoft Foundry.

  • Outside the covered models, Anthropic's standard API position is deletion within 30 days, with exceptions for usage policy enforcement and legal requirements, so 30 days is the ordinary case rather than the exception.

  • A hosted model is a third-party processor whether or not the vendor trains on your data, so the clauses in your appointment and your client NDAs about sub-processors and confidential information apply to it in exactly the way they apply to a cloud document platform.

  • If a client asks where their cost plan went after you ran it through a chatbot, "the vendor deletes it within 30 days" is an answer you should be able to give with a document behind it, and if you cannot, that is the gap to close first.

Takeaway

The firms in this story did not abandon frontier models. They sorted their work into two piles, sensitive and not, and gave the sensitive pile stricter terms or a different tool. A commercial lead or practice manager can handle this without needing a data scientist, and it can be done in an afternoon. Before the next tender goes through an AI tool, put four questions to whoever holds your contract with the vendor and get the answers in writing.

  • Which of our plans and models retain prompts and outputs, for how long, and under what conditions can the period be extended?

  • Is zero data retention available to an organisation of our size, on which products, and what does the agreement actually say about flagged content?

  • Who at the vendor can read our data, under what access path, and is that access logged in a way we could audit?

  • Do our appointment terms and client NDAs permit this processing, and have we told the clients whose data is going in?

Project Flux tracks how the AI tools construction teams actually use are governed, priced and restricted, so you know what to ask before your client does. Subscribe at projectflux.ai for the weekly read.

All content reflects our personal views and is not intended as professional advice or to represent any organisation.