Skip to content
Beyond Prompt AI Studio

Governance & guardrails

Anthropic's newest models force 30-day data retention - Microsoft restricted its own use over it

August 20, 2026 · 11 min read · Beyond Prompt AI Studio

AnthropicOpenAIData protectionGDPR

In July 2026, Anthropic introduced a policy change that often shows up only as a footnote in coverage so far, but forces a real decision for companies handling sensitive data: for its newest and most capable models - Claude Fable 5 and the so-called Mythos class - there's no longer a zero-data-retention option. Prompts and generated outputs are retained for 30 days, on every platform where these models are offered, explicitly to detect attack patterns that span multiple requests. How seriously this shift is being taken in practice shows in one concrete response: Microsoft restricted internal employee use of Anthropic's newest model while reviewing the policy. Yesterday, on 19 August 2026, OpenAI responded with its own system, Private Safety Processing, designed to detect misuse without storing customer data itself.

Key points at a glance

  • Since July 2026, Anthropic has required mandatory 30-day data retention for its newest models, Claude Fable 5 and the Mythos class. A zero-data-retention agreement no longer applies to these models, even if a company already has one in place for other Claude models.
  • Important caveat: the established Claude API models - Opus 4.8, Sonnet 4.6, Haiku 4.5 - aren't affected by this change and continue to support zero data retention. Only access to the newest, most capable models is affected.
  • Anthropic justifies the move as necessary to detect multi-step attack patterns spanning several requests, and openly acknowledges the change is 'unpopular with customers who have come to expect zero retention' and poses 'real risks to our business'.
  • In response, Microsoft restricted internal employee use of Anthropic's newest model while reviewing the policy - a concrete signal that even a major corporation isn't treating this change as routine.
  • On 19 August 2026, OpenAI unveiled Private Safety Processing as a counter-approach: the system is designed to detect suspicious patterns across multiple interactions, but only receives a narrowly scoped signal about the type and severity of an issue - not the customer's actual data. The system is currently in preview with select customers, with a wider rollout and technical white paper due in September.
  • For companies with GDPR obligations, this isn't an abstract debate: anyone using or planning to use Anthropic's most capable models should actively check whether their data processing agreement covers this 30-day retention and whether that's compatible with their own data protection requirements.

What Anthropic changed in July

Anthropic introduced mandatory 30-day data retention for its newest models - Claude Fable 5 and the so-called Mythos-class models. Prompts sent to these models, and the outputs they generate, are retained for that period, regardless of which platform is used to access them. Crucially, an existing zero-data-retention (ZDR) agreement, which many companies have in place for other Claude models, doesn't automatically extend to these new models. Anyone wanting access to Fable 5 or a Mythos-class model loses the ZDR option for that specific traffic, even if it still applies to other models.

Important context: the established Claude models most companies currently use via the API - Opus 4.8, Sonnet 4.6, Haiku 4.5 - aren't affected by this change and can still be run under zero-data-retention agreements. Thirty-day retention was also already the standard default for the API without a ZDR agreement, and consumer plans are explicitly unaffected as well. The change specifically concerns access to the newest, most capable features - not Anthropic's entire product line.

Anthropic's own justification

Anthropic justifies the move as necessary to detect sophisticated attacks that span multiple requests - a pattern that's difficult to catch under a pure zero-retention architecture, where every request is handled in isolation without context from previous ones. Notably, Anthropic itself openly acknowledges how unpopular this step is: the change is 'unpopular with customers who have come to expect zero retention' and poses 'real risks to our business', but is considered 'essential to detect and prevent sophisticated attacks that span multiple requests'. That candor is unusual for a product change of this magnitude, and suggests Anthropic made a deliberate internal trade-off between safety capability and customer trust, rather than marketing the change as a pure improvement.

The concrete reaction: Microsoft restricts its own use

How seriously this change is being taken in practice shows in a very concrete reaction: Microsoft restricted internal employee use of Anthropic's newest model while the company reviewed the new policy. That's not an abstract comment from trade press, but a real procurement and security decision by one of the world's largest software companies - a company that also maintains a close business relationship with OpenAI, which is worth keeping in mind when weighing this reaction. Even so, the episode shows that the 30-day retention requirement for Fable 5 and the Mythos class isn't a marginal issue for privacy-sensitive organizations, but a question that can trigger an active review and, potentially, a usage restriction.

OpenAI's counter-approach: Private Safety Processing

On 19 August 2026, OpenAI unveiled its own system, Private Safety Processing, explicitly positioned as an alternative to Anthropic's approach. The basic idea: detect suspicious patterns across multiple interactions without storing or viewing the underlying customer data itself. Technically, per available reporting, that means OpenAI receives only a narrowly scoped signal when an issue is detected - the type and severity of the activity - not the actual content of the requests or responses. Customer data is meant to stay on the customer's own infrastructure or be stored encrypted, with the customer retaining the keys.

The system is currently in preview with select customers; a wider rollout, along with a technical white paper detailing exactly how it works, is planned for September 2026. At this point, the actual effectiveness and robustness of the approach can't be conclusively judged from the outside - the announced white paper will show whether the method delivers on the concept's promise.

Why this is a concrete question for companies with GDPR obligations

This series has already written about the boundaries between AI use and GDPR requirements in general terms. This case turns that into a very concrete, vendor-specific decision rather than a general rule: a company currently using, or considering, access to Claude Fable 5 or a Mythos-class model - say, for particularly demanding tasks the established models can't handle - is automatically processing personal or confidential data under a 30-day retention period, regardless of any ZDR agreement that might exist for other models. Whether that's compatible with your own data protection impact assessment and legal basis for processing can't be answered in general and should be reviewed case by case before deploying such a model in production for sensitive use cases.

For the established, widely used Claude models via the API, nothing changes about the existing legal situation - zero data retention remains possible there. The decisive question for a company therefore isn't 'do we use Anthropic', but precisely: 'do we use one of the specific models this new rule applies to, and does our own department know that?' Especially where model access is procured by individual teams or departments without central IT sign-off, that's not a trivial question.

What this means in practice

  • Actively check whether Claude Fable 5 or a Mythos-class model is already in use somewhere in your company - especially where AI tools are procured by individual teams rather than centrally through IT.
  • If an affected model is in use, check whether your data processing agreement with Anthropic covers the 30-day retention, and whether that's compatible with your own data protection impact assessment - particularly for especially sensitive data categories.
  • Keep OpenAI's Private Safety Processing in mind as a possible alternative, but only evaluate its actual technical effectiveness once the announced white paper is published in September 2026, rather than treating the announcement as an equivalent substitute already.
  • When choosing between AI vendors for privacy-sensitive use cases, treat retention policy as its own explicit criterion alongside model quality and price - as this case shows, differences between vendors can be larger than assumed, and can vary between models within the same vendor's lineup.

The real value of this analysis isn't a verdict on which vendor is fundamentally more trustworthy, but the concrete call to action: retention periods and policy are model- and vendor-specific, they change, and their practical consequence only becomes clear when you actively check, as Microsoft did, rather than relying on general trust in a given vendor.

Frequently asked questions about Anthropic's retention rule and OpenAI's Private Safety Processing

Does the 30-day retention requirement affect all Claude models?

No. Only Claude Fable 5 and Mythos-class models are affected. The established API models Opus 4.8, Sonnet 4.6, and Haiku 4.5 aren't affected and can still be run under zero-data-retention agreements. Consumer plans are explicitly unaffected as well.

We have a zero-data-retention agreement with Anthropic - does it cover Fable 5?

Not automatically. Per available information, an existing ZDR agreement doesn't extend to Fable 5 or Mythos-class models. Anyone using or planning to use these models should clarify that explicitly with Anthropic or their contracting partner, rather than assuming automatic coverage.

Is OpenAI's Private Safety Processing already a full alternative?

Not conclusively yet. The system is currently in preview with select customers, and a technical white paper detailing how it works isn't due until September 2026. Until then, its actual effectiveness and robustness can't be fully evaluated from the outside.

Why did Microsoft restrict its own use of Anthropic's model?

Per reporting, Microsoft restricted internal employee use while reviewing the new 30-day retention requirement. It's worth noting Microsoft also maintains a close business relationship with OpenAI, which should factor into how this reaction is read. Regardless, the episode shows the policy change can trigger a real review for privacy-sensitive organizations.

Want a review of which AI models are actually in use across your company, and whether your data processing agreements cover them?