📊Freshcollected in 11m

Anthropic Gives Enterprises More Data Control

PostLinkedIn
📊Read original on Bloomberg Technology

💡Claude’s planned retention change could remove a major enterprise data-control barrier.

⚡ 30-Second TL;DR

What Changed

Business customers may be able to retain model-use data on their own cloud infrastructure.

Why It Matters

The change could make Claude more attractive to regulated enterprises that require control over sensitive data. It also shifts some operational responsibility for retention, access, and security from Anthropic to customers.

What To Do Next

Ask your security team to evaluate whether customer-managed cloud retention for Claude fits your data-governance and incident-response requirements.

Who should care:Enterprise & Security Teams

Key Points

  • Business customers may be able to retain model-use data on their own cloud infrastructure.
  • The planned system will still require enterprise customers to retain data for 30 days.
  • The policy reverses an earlier approach that kept data retention at Anthropic to help mitigate cyberattack risks.

🧠 Deep Insight

Background and context from public sources — not the original article. 28 sources cited.

🔑 Enhanced Key Takeaways

  • Anthropic's default API log retention for enterprise customers was previously reduced to 7 days as of September 14, 2025, with an option to extend to 30 days for auditing purposes via a Data Processing Addendum.
  • Qualifying enterprise API customers can enter into Zero Data Retention (ZDR) agreements, ensuring that inputs and outputs are not stored beyond what is necessary for abuse screening.
  • The 30-day data retention policy specifically applies to 'covered models,' such as Mythos-class models and future models with similar advanced capabilities, for the purpose of supporting safety work and detecting patterns of misuse.
  • This data retention for covered models is implemented across various deployment paths, including Claude Console workspaces with ZDR, Claude Code with ZDR in Claude Enterprise, or when accessing Claude through AWS Bedrock, Google Cloud Agent Platform, or Microsoft Foundry with ZDR.
  • Anthropic's enterprise offerings include advanced security features such as customer-managed encryption keys (CMEK), allowing organizations to provision and control encryption keys in their own cloud provider, and the ability to enforce US-only inference for data residency.
📊 Competitor Analysis▸ Show
Feature / ProviderAnthropicOpenAIGoogle Cloud AI (Vertex AI)Microsoft Azure AI
Data Retention/Control7-day default API retention, 30 days for 'covered models', ZDR for qualifying enterprise, customer-managed infrastructure plannedPreviewing 'Private Safety Processing' with ZDR, customer-controlled infrastructure/keys possibleDeep cloud IAM, VPC Service Controls, CMEK, extensive residency optionsData processed under Microsoft's DPA, isolated by tenant/subscription; Anthropic models may process data in US
Data Training PolicyNo training on enterprise customer data by default; consumer data opt-in for trainingEnterprise data not used for trainingEnterprise data not used for trainingNeither Microsoft nor Anthropic use your data to train AI models in Azure SRE Agent
Data Residency OptionsUS-only inference option; EU residency via AWS Bedrock/Google Vertex AI or direct API workspace settingOffers data residency optionsExtensive regional options, including EUAnthropic models in Azure SRE Agent may process data in US, not covered by EU Data Boundary commitments
Security CertificationsHIPAA-ready, ISO 27001:2022, ISO/IEC 42001:2023, SOC 2 Type I & Type IISOC 2 Type II, ISO 27001Enterprise-grade maturity, extensive certifications (implied as major cloud provider)(Implied as major cloud provider)
Pricing ModelCustom/negotiated for Enterprise, usage-based billingCustom/negotiated for EnterpriseCustom/negotiated for EnterpriseCustom/negotiated for Enterprise, usage-based
Key Enterprise FeaturesSSO, audit logs, SCIM, Compliance API, Analytics API, CMEK, workplace connectorsSSO, audit log APIs, admin consolesDeep cloud IAM, VPC Service Controls, CMEK, audit logging(Implied, as major cloud provider)

🛠️ Technical Deep Dive

  • Anthropic utilizes a multi-tenant architecture for serving model responses, and does not offer single-tenancy deployments.
  • All customer data stored by Anthropic is encrypted at rest using AES-256 GCM and protected in transit using TLS 1.2+.
  • Human review of retained conversations, primarily for safety purposes, is restricted to a small set of approved reviewers through a controlled access path, with every instance of access recorded in a tamper-proof log.
  • The Compliance API provides programmatic access to Claude usage data, including activity logs, chat histories, and file content, with filtering capabilities by user and time range.
  • Customer-managed encryption keys (CMEK) allow organizations to provision an encryption key in their own cloud provider, which Anthropic then uses to protect the organization's chats, projects, and files.
  • The 30-day retention for 'covered models' is specifically designed to enable the detection of misuse patterns that may only become visible across multiple interactions, forming part of Anthropic's safety work.
  • Anthropic's models are developed using a 'Constitutional AI' approach, which trains AI systems to adhere to a structured set of ethical and safety guidelines.
  • The Anthropic API supports an inference_geo setting, allowing customers to pin inference to US-based infrastructure, with EU data residency also configurable via direct API workspace settings or through cloud providers like AWS Bedrock and Google Cloud Vertex AI.

🔮 Future ImplicationsAI analysis grounded in cited sources

Anthropic's enhanced data control will intensify competition among AI providers for enterprise customers in highly regulated sectors.
By offering more granular data control, including customer-managed infrastructure and CMEK, Anthropic directly addresses critical compliance and security requirements, pressuring competitors to match or exceed these offerings to attract and retain businesses in finance, healthcare, and government.
The policy shift will accelerate the adoption of Anthropic's most capable AI models within enterprises that previously hesitated due to data governance concerns.
Moving storage control to customer cloud infrastructure, combined with existing ZDR options and robust compliance certifications, removes significant barriers for enterprises needing to maintain strict data sovereignty and security, enabling wider deployment of advanced AI capabilities.
This move could lead to a more fragmented AI deployment landscape, where data residency and control become primary determinants of enterprise AI vendor selection.
As AI providers differentiate on data sovereignty features, enterprises with stringent regulatory and internal policy requirements may increasingly be limited to specific vendors or deployment architectures, potentially hindering multi-cloud or multi-model AI strategies.

Timeline

2021-01
Anthropic founded by former OpenAI researchers as a Public Benefit Corporation, focusing on AI safety.
2024-09
Claude Enterprise launched, offering features like SSO, audit logs, admin controls, and custom data retention.
2025-09
Anthropic updated its consumer privacy policy, introducing an opt-in for model training, which could extend data retention for opted-in users to 5 years (effective October 2025).
2025-09-14
Anthropic reduced its default API log retention for enterprise customers from 30 days to 7 days.
2026-05-26
Anthropic announced Claude's integration with 28 security and compliance platforms, leveraging its Compliance API for enhanced governance.
2026-06-09
A new 30-day data retention policy for 'covered models' (Mythos-class and similar highly capable models) went into effect for safety monitoring purposes.
📰

Weekly AI Recap

Read this week's curated digest of top AI events →

👉Related Updates

AI-curated news aggregator. All content rights belong to original publishers.
Original source: Bloomberg Technology

This is a summary, not the original. Read the source, or get the weekly briefing.

Weekly AI briefing

One email a week. Unsubscribe anytime.