Anthropic lets enterprise AI data stay in customer clouds

Anthropic is changing how it handles enterprise customer data tied to its Mythos and Fable models and future flagship models. The 30-day review window remains, but the data will be stored in the customer’s cloud rather than on Anthropic’s own servers.

WTF Index NEUTRAL
◄ Terminator 1 Idiocracy 0 ►

This is mainly an enterprise data-control policy update, with only mild concern around monitoring powerful models for cyberattack misuse.

Anthropic lets enterprise AI data stay in customer clouds

Anthropic is adjusting a data retention policy that drew resistance from enterprise customers. The company will keep a 30-day window for reviewing data connected to its Mythos and Fable models, along with future flagship models, but it is changing where that data lives.

Instead of storing the information on Anthropic’s own servers, the new setup will allow enterprise customers to keep the data in their own cloud environments. The change is designed to preserve Anthropic’s security goal while giving businesses more control over sensitive information.

What Anthropic is changing

Since June, Anthropic has stored all customer data from Mythos and Fable, as well as future flagship models, for 30 days on its servers. The stated purpose was to detect new cyberattacks that make use of the technology.

That basic 30-day period is not going away. What changes is the storage location. Under the revised approach, the same window applies, but the data will remain in the customer’s cloud rather than being held by Anthropic.

For enterprise AI customers, that distinction matters. A company can face internal rules, customer obligations, or sector-specific expectations around where data is stored and who controls access to it. The source article says Anthropic itself acknowledged that the previous rule was both unpopular and a business risk.

Why enterprise customers pushed back

The policy created tension because it touched one of the central questions in enterprise AI: how to balance security monitoring with data control. Anthropic wanted access to signals that could help identify cyberattacks using its more powerful models. Customers, however, had concerns about sending all relevant data to Anthropic’s own servers for the 30-day period.

The issue was especially important for regulated industries. According to Bloomberg, Anthropic spent months building the new system with more than 100 customers from regulated industries. That detail shows the change was not only a public messaging shift, but a technical and commercial response to enterprise requirements.

The source does not describe the exact technical design of the new system. What it does make clear is the intended result: Anthropic keeps the security review period, while customers retain storage in their own cloud.

The security tradeoff remains

The revised Anthropic data retention policy does not remove the company’s interest in spotting AI-related cyberattacks. The original reason for the storage rule remains part of the plan. The difference is that the data control model changes for enterprise customers.

That creates a narrower compromise. Anthropic can still maintain a 30-day review window tied to Mythos, Fable and future flagship models. Enterprise users, meanwhile, gain a setup that avoids placing the data directly on Anthropic’s servers.

In plain terms, the change separates two concerns that had been bundled together:

  • Security monitoring: Anthropic still wants a 30-day period to identify emerging cyberattack patterns involving its technology.
  • Data location: Enterprise customers can keep the data in their own cloud under the new approach.
  • Business risk: Anthropic recognized that the earlier version of the policy created friction with customers.

This is a practical shift for enterprise AI adoption. Companies evaluating powerful models often care not only about model capability, but also about how vendor policies fit with data governance needs. A retention rule that looks manageable for one buyer can be a barrier for another.

How the wider market is moving

Anthropic is not the only AI company working on ways to connect security oversight with customer control. The source article notes that OpenAI is testing a different method with Databricks and Microsoft that also aims to pair security with data control.

That comparison matters because it places Anthropic’s move inside a broader enterprise AI pattern. Vendors need to address the risk of misuse, including cyberattacks, while also convincing customers that sensitive data can be handled in a way their organizations will accept.

Anthropic developer Boris Cherny confirmed the plans publicly on X. The changes are expected to arrive this fall.

What to watch next

The most important detail is that Anthropic is not abandoning the 30-day window. It is changing the custody model. For customers using Mythos, Fable or future flagship models, the practical question becomes how the customer-cloud setup will work once it is available.

The source does not provide implementation details beyond the shift in storage location and timing. But the direction is clear: Anthropic is trying to keep a security mechanism that it considers important while reducing the enterprise objections that made the earlier rule difficult to sustain.

For the AI industry, the episode underlines a recurring tension. More powerful models raise new safety and security demands, while enterprise customers continue to expect strong control over their own data. Anthropic’s revised policy is one attempt to satisfy both sides without removing the 30-day review period.