What Anthropic changed in July
Anthropic introduced mandatory 30-day data retention for its newest models - Claude Fable 5 and the so-called Mythos-class models. Prompts sent to these models, and the outputs they generate, are retained for that period, regardless of which platform is used to access them. Crucially, an existing zero-data-retention (ZDR) agreement, which many companies have in place for other Claude models, doesn't automatically extend to these new models. Anyone wanting access to Fable 5 or a Mythos-class model loses the ZDR option for that specific traffic, even if it still applies to other models.
Important context: the established Claude models most companies currently use via the API - Opus 4.8, Sonnet 4.6, Haiku 4.5 - aren't affected by this change and can still be run under zero-data-retention agreements. Thirty-day retention was also already the standard default for the API without a ZDR agreement, and consumer plans are explicitly unaffected as well. The change specifically concerns access to the newest, most capable features - not Anthropic's entire product line.
Anthropic's own justification
Anthropic justifies the move as necessary to detect sophisticated attacks that span multiple requests - a pattern that's difficult to catch under a pure zero-retention architecture, where every request is handled in isolation without context from previous ones. Notably, Anthropic itself openly acknowledges how unpopular this step is: the change is 'unpopular with customers who have come to expect zero retention' and poses 'real risks to our business', but is considered 'essential to detect and prevent sophisticated attacks that span multiple requests'. That candor is unusual for a product change of this magnitude, and suggests Anthropic made a deliberate internal trade-off between safety capability and customer trust, rather than marketing the change as a pure improvement.
The concrete reaction: Microsoft restricts its own use
How seriously this change is being taken in practice shows in a very concrete reaction: Microsoft restricted internal employee use of Anthropic's newest model while the company reviewed the new policy. That's not an abstract comment from trade press, but a real procurement and security decision by one of the world's largest software companies - a company that also maintains a close business relationship with OpenAI, which is worth keeping in mind when weighing this reaction. Even so, the episode shows that the 30-day retention requirement for Fable 5 and the Mythos class isn't a marginal issue for privacy-sensitive organizations, but a question that can trigger an active review and, potentially, a usage restriction.
OpenAI's counter-approach: Private Safety Processing
On 19 August 2026, OpenAI unveiled its own system, Private Safety Processing, explicitly positioned as an alternative to Anthropic's approach. The basic idea: detect suspicious patterns across multiple interactions without storing or viewing the underlying customer data itself. Technically, per available reporting, that means OpenAI receives only a narrowly scoped signal when an issue is detected - the type and severity of the activity - not the actual content of the requests or responses. Customer data is meant to stay on the customer's own infrastructure or be stored encrypted, with the customer retaining the keys.
The system is currently in preview with select customers; a wider rollout, along with a technical white paper detailing exactly how it works, is planned for September 2026. At this point, the actual effectiveness and robustness of the approach can't be conclusively judged from the outside - the announced white paper will show whether the method delivers on the concept's promise.
Why this is a concrete question for companies with GDPR obligations
This series has already written about the boundaries between AI use and GDPR requirements in general terms. This case turns that into a very concrete, vendor-specific decision rather than a general rule: a company currently using, or considering, access to Claude Fable 5 or a Mythos-class model - say, for particularly demanding tasks the established models can't handle - is automatically processing personal or confidential data under a 30-day retention period, regardless of any ZDR agreement that might exist for other models. Whether that's compatible with your own data protection impact assessment and legal basis for processing can't be answered in general and should be reviewed case by case before deploying such a model in production for sensitive use cases.
For the established, widely used Claude models via the API, nothing changes about the existing legal situation - zero data retention remains possible there. The decisive question for a company therefore isn't 'do we use Anthropic', but precisely: 'do we use one of the specific models this new rule applies to, and does our own department know that?' Especially where model access is procured by individual teams or departments without central IT sign-off, that's not a trivial question.
What this means in practice
- Actively check whether Claude Fable 5 or a Mythos-class model is already in use somewhere in your company - especially where AI tools are procured by individual teams rather than centrally through IT.
- If an affected model is in use, check whether your data processing agreement with Anthropic covers the 30-day retention, and whether that's compatible with your own data protection impact assessment - particularly for especially sensitive data categories.
- Keep OpenAI's Private Safety Processing in mind as a possible alternative, but only evaluate its actual technical effectiveness once the announced white paper is published in September 2026, rather than treating the announcement as an equivalent substitute already.
- When choosing between AI vendors for privacy-sensitive use cases, treat retention policy as its own explicit criterion alongside model quality and price - as this case shows, differences between vendors can be larger than assumed, and can vary between models within the same vendor's lineup.
The real value of this analysis isn't a verdict on which vendor is fundamentally more trustworthy, but the concrete call to action: retention periods and policy are model- and vendor-specific, they change, and their practical consequence only becomes clear when you actively check, as Microsoft did, rather than relying on general trust in a given vendor.