Anthropic kept its customers' conversations for 30 days. It just backed down.
Since June, everything companies typed into Anthropic's big models stayed on the company's servers for thirty days. Everything. The questions, the code, the documents pasted into the window. There was no getting around it, including for those who were paying precisely so that nothing would be kept.
On Tuesday, the company backed down. And the solution it is proposing is smarter than a simple "okay, fine, we'll delete it".
The safe hasn't disappeared. It just moved into the customer's office.
First, why it kept all that
We have to give Anthropic credit for what is its due: the reason wasn't commercial. Those thirty days were used to spot people using the model to attack other machines. And the company had committed in writing never to use that data to train its models.
The context is the one I was talking about yesterday : these models have become very good at finding vulnerabilities and writing things to exploit them. When you put a tool like that in anyone's hands, you want to know what people are doing with it. Keeping the traffic for a month is the simplest way to spot the person preparing something nasty.
On paper, it's defensible. In real life, it hit hard very quickly.
What it broke
There is an option, in this line of work, called zero retention. Translation: what you send is processed, the answer is returned to you, and nothing is stored. Not at the provider's, not anywhere else, not for an hour.
This option isn't some paranoid whim. It's often an obligation. A law firm can't leave its client's case file lying around on a third party's server. A hospital can't let a medical report slip away. A bank has a regulator who comes to check, based on the paperwork, where its data lives.
By imposing its thirty days, Anthropic removed this option for its best models. Immediate result: those customers stopped using them. Microsoft, which is a heavyweight partner at that, restricted their use internally.
The best tool on the market, politely left on the doorstep.
And the part I find remarkable is that Anthropic itself had written it down, in black and white, in its own report: the rule would be unpopular with customers used to zero retention, and would represent a real risk to the company's success, especially if competitors didn't follow suit. It saw the wall, it documented the wall, it drove straight into it anyway.
The way out, and it's clever
The new formula is called Enterprise Frontier Safeguards. Behind the pompous name, the idea can be summed up in one sentence: the thirty days stay, but the data no longer goes to Anthropic.
It stays with the customer, in its own online storage space, at Amazon, Microsoft or Google depending on what it already uses. The customer puts on the padlock, holds the key, decides who has the right to look, and keeps the log of who looked at what.
Before, data went to see the inspector. Now, the inspector comes to your home and leaves without taking anything.
The monitoring is still running, but it is automatic and no human from Anthropic comes to read over your shoulder. The service is free. It is rolling out in stages starting this fall, and in the meantime, the customers concerned can already use the latest model with zero retention.
This reversal is neat technically. We long believed that we had to choose between monitoring and respecting privacy. Here, we simply move the location: instead of bringing the data to the control, we send the control to the data. It's the same logic as a doctor who goes to the patient's home rather than making the patient come to the hospital, and it opens up a path that the others will be watching closely. OpenAI is testing a similar approach on its side, too.
What if you're neither a bank nor a hospital?
You won't have this button in your subscription, and yet this story concerns you, for one simple reason: it brings back the question we all forget to ask ourselves.
When you paste a piece of text into an AI at work, where does that text go, and for how long? You've never read your employer's contract with the provider. You've never seen the setting that decides all this. And it can change in June without anyone warning you, exactly like here.
Two reflexes are worth adopting. The first: before pasting a sensitive document, a contract, a payslip, a client file, ask yourself if you would send it by email to an outside service provider. If the answer is no, the AI is no different. The second: in your tool's settings, go look for the line that talks about using your conversations for training. It almost always exists. It is never highlighted. I had actually written about the day Claude opened the notebook he keeps about you, and it's the same reflex: go see what is stored, you'll be surprised.
What I take away from it
A company that writes in its own report, "this decision will cost us customers", goes ahead with it anyway, then spends hundreds of hours with more than a hundred companies to find a way out, that is not the sector's usual behavior. Usually, we're told that it was very much fine as it was, or the rule is quietly changed on a Thursday evening.
The real lesson remains, and it's for all of us: it was customers who made the company fold. Not a regulator, not a court, not a petition. Companies that simply stopped paying and went somewhere else. There is no better voting button than that one!
Sources
- CNBC : Anthropic changes data retention policy after pushback from customers, September 1, 2026, the announcement, the June policy and the statements from the head of sales
- CX Today : Anthropic drops data retention requirement for Mythos and Fable, the technical details of Enterprise Frontier Safeguards, storage at the customer's premises and the rollout schedule
- PYMNTS : Anthropic revises enterprise data retention policy after customer pushback, the free service, monitoring without human review and the content of the June policy
- The Decoder : Anthropic changes data retention policy after enterprise pushback, the hundred customers consulted and the parallel approach being tested by OpenAI



Join the conversation
You need an account to comment on this article. Creating one is free and takes under a minute.
No comments yet.