Dear Reader,
On 9 June Anthropic released Claude Fable 5 to the public and Claude Mythos 5 to vetted cybersecurity partners. Both carry a mandatory 30-day data retention requirement, and that requirement overrides existing zero-retention agreements. Anthropic’s own documentation says prompts sent to covered models and the outputs they generate are kept for 30 days on every platform where the models are offered, and that the same will apply to future models of similar capability.
Zero data retention is the clause that lets a bank, an insurer or a hospital group approve a frontier model at all. It is the line in the DPA the data protection officer signs against. In June it stopped applying to the two best models Anthropic sells.
Anthropic knew it would lose customers over this
The reasoning is in Anthropic’s August risk report, a 186-page document published in redacted form. The company calls the retention requirement necessary “to detect and prevent sophisticated attacks that span multiple requests”. It then sets out the cost: the policy will “be unpopular with customers who have come to expect zero retention, and pose real risks to our business success (especially if competitors do not follow)”.
Anthropic was right. OpenAI did not follow, and said so publicly a fortnight later.
OpenAI found a way to do the same job without keeping the data
On 19 August OpenAI previewed a system called Private Safety Processing. It runs the same cross-request detection that Anthropic says requires retention, but it sends OpenAI only a narrow safety signal. Prompts and responses stay hidden. The data either remains on the customer’s own infrastructure or sits with OpenAI under encryption keys the customer holds. Databricks and Microsoft are testing it, with a wider release and a technical white paper due in September.
Aleah Houze, OpenAI’s Head of Product Policy, gave reporters the worked example. Someone asks about a weakness in a company’s software in one conversation, then in a later conversation asks about remote access and what security tools can detect. Each question on its own is ordinary. Read together they are reconnaissance, and reading them together is what the retained data is for.
OpenAI posted the same day that it “will continue to offer Zero Data Retention for frontier models”. The Register called the system discreet automated prompt surveillance. Both are descriptions of the same design: the classifiers read the traffic, and OpenAI does not retain it.
Anthropic will move the data to your own cloud
On 20 August Bloomberg and Reuters both reported that Anthropic will hold the 30-day requirement but let enterprise customers keep the data on their own cloud instead of Anthropic’s, starting in the autumn. Anthropic declined to comment and both accounts rest on one anonymous source. That source also says the work started months ago, with more than 100 customers in regulated industries involved in the design.
In May the market offered one arrangement. It now offers three. OpenAI keeps nothing. Anthropic keeps the data for 30 days, on its own systems now and on the customer’s systems from the autumn.
Why the labs want the prompts at all
Issue 59 covered the reason. Between 9 and 13 July two OpenAI models escaped an evaluation sandbox and broke into Hugging Face’s production infrastructure while trying to cheat a benchmark, and nine zero-day CVEs were later disclosed and credited to the models. Individually those requests looked like ordinary evaluation traffic. The attack was only visible across the whole run.
Detecting it without keeping the data costs compute. OpenAI passes every sampled token through classifiers and escalates anything suspicious to automated investigators, aiming to alert a human inside 30 minutes. OpenAI says that monitoring uses around 20% of the inference compute it covers, and has not published what Private Safety Processing adds on top. Anthropic solved the problem by storing the data. OpenAI solved it by buying more compute.
One more thing. The Financial Times reports that OpenAI disbanded its preparedness team at the end of July and split the work into existing groups by domain. On 18 August the company halted a significant number of Astra training runs because Astra had crossed a capability threshold defined in its Preparedness Framework, and said a new version of that framework is in preparation because most of the current one dates from 2023. The team that owned it had been broken up three weeks earlier.
What the supplier’s detection needs is what sets your data term.
Impact on the Polish market
UODO published its AI guidance on 17 August in four versions: for SMEs using off-the-shelf tools, for public administration, for organisations training their own models, and an extended edition covering RODO and the AI Act together. Consultation runs to the end of September.
The guidance tells buyers to establish, before purchase, what the supplier does with the data, how long it keeps it, and whether it passes it to third parties. Those are the right questions, and they assume the answer stays put. A Polish deployer who recorded a supplier’s retention period in its record of processing activities in May has had to amend that entry twice since, and found out about both changes from journalists.
For KNF-supervised firms the same gap opens in the outsourcing file. The cloud outsourcing communiqué and DORA both expect an evidenced position on where data sits and how you exit. A retention term the supplier can revise mid-contract only tells you what was true on the day you wrote it down.
Questions to put to your supplier
Five questions a vendor can answer in writing, and which its own documentation currently does not.
- What do you need to observe to spot misuse spread across separate requests: the prompts themselves, or a signal computed from them?
- Where is retained data physically stored, in which cloud region, and which organisation’s account owns it?
- Who holds the encryption keys, and can you decrypt without us?
- How much notice will we get before this changes again, and in what form?
- Does our existing zero-retention agreement still apply to any model you sell today?
The fourth is the one neither Anthropic nor OpenAI answers at present, and it is the one that decides whether the other four stay true.
Briefing
Five months after the LiteLLM breach, the stolen credentials still work. Hudson Rock published its analysis of a 153GB archive holding 433,909 files taken in the March supply chain attack, attributing 118,829 CI/CD pipeline dumps to 2,488 corporate domains including NVIDIA, Volkswagen, Microsoft, Cisco, Deloitte and Siemens. On 13 August the security researcher Kevin Beaumont tested credentials belonging to a large US technology company that had assured him everything was rotated: “I tried them all. Almost every one worked.” So what: early coverage fixed on the 40 minutes the poisoned packages sat on PyPI. That is how long they were downloadable, not how long the exposure lasts. Exposure runs from 24 March until an organisation replaces every credential its pipelines held. CloudSEK’s warning applies to anyone who ran a unified LLM gateway in that period: no suspicious activity is not evidence that a credential was never copied.
Alphabet lost roughly $186bn of market value in a day over four researchers. Jeff Dean left after 27 years to found Discovery Loop, taking Sanjay Ghemawat, Oriol Vinyals and Quoc Le, on the same day Demis Hassabis stepped back from running DeepMind to become its chair and Alphabet’s chief scientist. Sundar Pichai says Google will be a founding investor in the new company (Barchart, Business Insider). So what: four departures moved $186bn, which is the market saying that frontier capability sits with named individuals rather than with the company that employs them. That is a supplier-concentration risk of a kind procurement has no standard way to assess, and it applies to every frontier lab, not only to Google.
The EU AI Office opened three routes for complaints. From 17 August, downstream providers can email the Office to report breaches of Articles 53 to 55 by general-purpose model providers, and complainants have to identify themselves (PPC Land). So what: early RODO enforcement was driven largely by anonymous complaints from individuals. Requiring a name changes who files: realistically, companies with a commercial interest in the outcome. And the complaints go against model providers, not against the companies deploying their models.
Summary
Anthropic withdrew zero data retention from its best models on 9 June, defended the decision in its own risk report in August, watched OpenAI answer it with a different architecture on 19 August, and changed the policy on 20 August. Every one of those decisions was made by the supplier’s security engineering teams, and customers found out by reading the news.
A data-handling promise from a frontier lab describes the detection design running on the day it was made. That design changes when the models get more capable, or when a competitor finds a cheaper way to do the same job. Both changes this summer were public before any customer was told.
Stay balanced, Krzysztof
Krzysztof Goworek is founder of Quintant — AI advisory that gets enterprises from experiment to production value.