Anthropic’s current policy treats its most capable models as “covered models.” Its platform documentation says conversation content is not retained by default, but covered models—including Claude Fable 5 and Claude Mythos 5—require 30-day retention, making zero-data-retention arrangements unavailable for those models.
The planned update would change the location and custody of that retained data, not the basic monitoring window. According to reporting based on a source familiar with the plan, enterprise customers would still retain the data for 30 days but could store it on infrastructure they control.
In practical terms, the proposal is closer to customer-managed retention than to zero data retention:
The rollout is expected later in 2026, so the precise technical design, eligibility requirements, access controls, and deletion process remain important open questions.
Anthropic says limited retention and review are part of its safety work. Its stated concern is that sophisticated misuse may not be visible in one isolated exchange. An attack can develop across a sequence of interactions, making a longitudinal record useful for identifying patterns and investigating what happened.
That position comes with a clear trade-off. Retaining prompts and outputs can improve the ability to reconstruct suspicious activity, but it also creates an additional data-governance obligation for businesses handling confidential, regulated, or privileged information. Anthropic’s own risk report acknowledges that the decision could be unpopular with customers accustomed to zero retention and could create business risks, while presenting it as necessary for detecting sophisticated attacks.
The policy therefore reflects a safety judgment rather than a claim that retention is harmless. Enterprises must weigh the value of an evidence trail against the risks associated with storing the underlying content.
Provider-held logs can be difficult for regulated organizations to accept. Businesses may need to account for data residency, internal access controls, confidentiality duties, incident response, legal discovery, and the consequences of placing sensitive prompts in a vendor’s environment.
Allowing customer-controlled cloud storage addresses the custody question more directly than a standard provider-retention policy. It could let an organization apply its own identity controls, regional architecture, key-management practices, monitoring, and retention governance—although those protections will depend on the final implementation and contract.
The option does not eliminate the need for review. It changes who controls the storage environment and potentially who bears more of the operational responsibility for protecting and producing the data.
OpenAI’s Private Safety Processing is designed to preserve zero-data-retention protections while detecting patterns across related interactions. OpenAI says the system can send a narrowly defined safety signal without giving its personnel access to the underlying prompts or responses. For zero-retention deployments, customer content remains on infrastructure controlled by the customer; OpenAI is also developing an option involving encrypted storage on OpenAI infrastructure with customer-controlled keys.
The architectural difference is straightforward:
These are not merely different contract terms. They represent different answers to the question of how a provider can detect slow-moving misuse. Anthropic’s approach prioritizes a recoverable history. OpenAI’s approach prioritizes privacy-preserving computation and minimized data custody.
OpenAI’s proposal is still a preview, however. Its effectiveness, coverage, false-positive and false-negative behavior, technical safeguards, and incident-escalation process need to be assessed through documentation, testing, and independent scrutiny before enterprises treat its claims as established assurance.
The right choice depends on the organization’s threat model and compliance requirements—not simply on whether a provider advertises “zero retention.” Procurement and security teams should ask:
Anthropic’s customer-managed option may suit organizations that value a reconstructable audit trail and can govern 30-day storage in their own environment. OpenAI’s approach may appeal to organizations for which raw-content retention and provider access are unacceptable—but its preview status means buyers should demand evidence before relying on it for the most sensitive workloads.
The emerging dispute is not simply about privacy versus safety. It is about where the safety evidence lives, who can control it, and which party carries the compliance and incident-response burden.
Anthropic is betting that advanced models require a retained history to identify sophisticated, multi-step misuse. OpenAI is betting that privacy-preserving processing can provide comparable monitoring without keeping raw customer content. Neither claim should be treated as fully settled until the systems are documented, deployed broadly, and independently evaluated.
For enterprise customers, model capability is only one part of the buying decision. Data custody, auditability, deletion, access, and the provider’s ability to explain its safety architecture may be just as consequential.
Anthropic’s current policy treats its most capable models as “covered models.” Its platform documentation says conversation content is not retained by default, but covered models—including Claude Fable 5 and Claude Mythos 5—require 30-day retention, making zero-data-retention arrangements unavailable for those models.
The planned update would change the location and custody of that retained data, not the basic monitoring window. According to reporting based on a source familiar with the plan, enterprise customers would still retain the data for 30 days but could store it on infrastructure they control.
In practical terms, the proposal is closer to customer-managed retention than to zero data retention:
The rollout is expected later in 2026, so the precise technical design, eligibility requirements, access controls, and deletion process remain important open questions.
Anthropic says limited retention and review are part of its safety work. Its stated concern is that sophisticated misuse may not be visible in one isolated exchange. An attack can develop across a sequence of interactions, making a longitudinal record useful for identifying patterns and investigating what happened.
That position comes with a clear trade-off. Retaining prompts and outputs can improve the ability to reconstruct suspicious activity, but it also creates an additional data-governance obligation for businesses handling confidential, regulated, or privileged information. Anthropic’s own risk report acknowledges that the decision could be unpopular with customers accustomed to zero retention and could create business risks, while presenting it as necessary for detecting sophisticated attacks.
The policy therefore reflects a safety judgment rather than a claim that retention is harmless. Enterprises must weigh the value of an evidence trail against the risks associated with storing the underlying content.
Provider-held logs can be difficult for regulated organizations to accept. Businesses may need to account for data residency, internal access controls, confidentiality duties, incident response, legal discovery, and the consequences of placing sensitive prompts in a vendor’s environment.
Allowing customer-controlled cloud storage addresses the custody question more directly than a standard provider-retention policy. It could let an organization apply its own identity controls, regional architecture, key-management practices, monitoring, and retention governance—although those protections will depend on the final implementation and contract.
The option does not eliminate the need for review. It changes who controls the storage environment and potentially who bears more of the operational responsibility for protecting and producing the data.
OpenAI’s Private Safety Processing is designed to preserve zero-data-retention protections while detecting patterns across related interactions. OpenAI says the system can send a narrowly defined safety signal without giving its personnel access to the underlying prompts or responses. For zero-retention deployments, customer content remains on infrastructure controlled by the customer; OpenAI is also developing an option involving encrypted storage on OpenAI infrastructure with customer-controlled keys.
The architectural difference is straightforward:
These are not merely different contract terms. They represent different answers to the question of how a provider can detect slow-moving misuse. Anthropic’s approach prioritizes a recoverable history. OpenAI’s approach prioritizes privacy-preserving computation and minimized data custody.
OpenAI’s proposal is still a preview, however. Its effectiveness, coverage, false-positive and false-negative behavior, technical safeguards, and incident-escalation process need to be assessed through documentation, testing, and independent scrutiny before enterprises treat its claims as established assurance.
The right choice depends on the organization’s threat model and compliance requirements—not simply on whether a provider advertises “zero retention.” Procurement and security teams should ask:
Anthropic’s customer-managed option may suit organizations that value a reconstructable audit trail and can govern 30-day storage in their own environment. OpenAI’s approach may appeal to organizations for which raw-content retention and provider access are unacceptable—but its preview status means buyers should demand evidence before relying on it for the most sensitive workloads.
The emerging dispute is not simply about privacy versus safety. It is about where the safety evidence lives, who can control it, and which party carries the compliance and incident-response burden.
Anthropic is betting that advanced models require a retained history to identify sophisticated, multi-step misuse. OpenAI is betting that privacy-preserving processing can provide comparable monitoring without keeping raw customer content. Neither claim should be treated as fully settled until the systems are documented, deployed broadly, and independently evaluated.
For enterprise customers, model capability is only one part of the buying decision. Data custody, auditability, deletion, access, and the provider’s ability to explain its safety architecture may be just as consequential.