Anthropic moves enterprise AI data into customers' own clouds
Anthropic is walking back the most controversial part of how it watches its most powerful models for abuse — and handing control of the data back to the companies that generate it.
Anthropic is changing where it stores conversations from its most capable models, moving that data out of its own servers and into each customer's cloud after months of pushback from enterprise buyers. Since June, the company has kept all customer data from its Mythos and Fable models — plus every future flagship — on Anthropic's own infrastructure for 30 days, framing the hold as a way to spot new cyberattacks that abuse the technology. The 30-day window is not going away, but under the revised setup the logs will sit in the customer's own environment rather than on Anthropic's. According to Bloomberg, the company spent months building the new system alongside more than 100 customers from regulated industries, and Anthropic developer Boris Cherny confirmed the plan publicly on X. The changes are expected to arrive this fall.
The reversal is a telling sign of where the power sits in the enterprise AI market. Anthropic introduced the retention rule as a security measure, but businesses in finance, healthcare, and government balked at the idea of their most sensitive prompts sitting on a vendor's servers — a real business risk that, as The Decoder notes, Anthropic itself admitted was unpopular and a liability. The episode shows that "trust us with your data" is no longer a default that customers will accept from even the most safety-minded lab; the terms of deployment are now a negotiated part of the sale.
It also sharpens the contrast with OpenAI, which is testing a different approach with Databricks and Microsoft that aims to catch misuse without holding customer data at all. Both labs are converging on the same conclusion — security monitoring and customer data control have to coexist — but they are betting on different architectures to get there. Anthropic's answer keeps the 30-day inspection but relocates the data; OpenAI's tries to avoid the custody question entirely.
What to watch: whether the fall rollout actually lets regulated customers keep the cyberattack-detection benefit while the data never leaves their perimeter, and whether OpenAI's competing design reaches general availability first.
Should frontier labs be allowed to hold customer data at all in the name of safety, or is that a line enterprises should never cross? Tell us in the comments.
Sources: The Decoder · Bloomberg · The Decoder — OpenAI's contrasting method