Anthropic is reportedly preparing a change in data storage for corporate clients, according to a report by Reuters. Those who must comply with the 30-day retention requirement for the models Mythos and Fable, introduced in June, will be able to store data on their own infrastructure instead of Anthropic’s cloud infrastructure. More than 100 companies from regulated industries contributed to the development.
Storage location changes, retention requirement remains
The fundamental principle remains unchanged: corporate clients using Mythos or Fable must continue to retain their interaction data for 30 days so that Anthropic can detect misuse and potential cyberattacks through the models. The new option is the choice of storage location: instead of being required to keep the data on Anthropic’s own servers, companies will be able to store it in their own, self-controlled cloud environment.
For highly regulated industries such as financial services or healthcare, this is more than a technical detail: companies that cannot store customer data with an external provider for legal reasons have had trouble using the most powerful Claude models without compliance risk. Anthropic already offers enterprise customers tools such as a compliance API and audit logs; the new storage option would extend that offering to include physical control over the raw data.
June rule for Mythos and Fable sparked criticism
The starting point of the debate is an announcement from June 9, 2026: Anthropic introduced a mandatory 30-day data retention policy alongside the launch of the Fable 5 and Mythos 5 models, citing the need to detect novel cyberattacks through the models early. For companies that were previously accustomed to zero retention, this meant a break with familiar privacy commitments – criticism from customers reportedly followed.
More than 100 corporate clients from regulated industries, including Salesforce, have contributed to the revision in recent months. Competitors are also positioning themselves with privacy pledges of their own: Mistral introduced a strict separation of EU and US data processing in August, and OpenAI CEO Sam Altman assured German business customers of a binding zero-data-retention policy the same month.
OpenAI counters with a storage-free safety check
One day before the reports about Anthropic’s plans, OpenAI presented its own alternative: Private Safety Processing is designed to automatically detect suspicious patterns across multiple interactions without letting employees view individual prompts or responses. According to OpenAI, the system sends only a narrowly defined safety signal, while the underlying content stays inaccessible. An exception remains the discovery of material related to child sexual abuse, where human review still applies.
OpenAI plans a technical white paper for September 2026 and, further down the line, an option to store data encrypted with customer-owned keys on its own infrastructure. The rivalry between the two approaches comes down to two different answers to the same question: safety through guaranteed non-retention, or safety through controlled retention on the customer’s own terms.
What matters now is whether companies actually gain the control they need for strict compliance requirements with the new option, or whether Anthropic still retains effective insight through its access rights for misuse detection. It also remains unclear exactly when the system will launch and whether it will be available outside the United States – Anthropic itself has not publicly commented on the reports so far.


