CourionAI
EN
Newsletter
← All news
anthropic 2 min read

Anthropic Kept Your Data for 30 Days to Hunt Attackers. After Enterprise Pushback, It Will Sit in Your Cloud Instead

The 30-day window stays, but the data moves to the customer's own cloud. Anthropic spent months building the system with more than 100 customers from regulated industries, and admits the original rule was a business risk.

A data folder moving from one cloud into a second cloud shaped like a building

Since June, Anthropic has stored all customer data passing through its most powerful models for 30 days on its own servers. The reasoning was security: to spot novel cyberattacks carried out using its models, you have to be able to look at what went through them. Customers in regulated industries hated it. Bloomberg reported on 20 August that Anthropic is changing the arrangement.

The 30-day window stays. What changes is where the data sits. Under the new setup it stays in the customer’s own cloud rather than on Anthropic’s servers. The company has spent months building this with more than 100 customers from regulated industries, and in its own report it acknowledged the original rule was unpopular and a business risk. The changes are due this autumn. Anthropic developer Boris Cherny confirmed the plans publicly.

Why this keeps happening

There is a real tension underneath, and it is not going away. If a lab wants to catch someone using its model to build malware, it has to inspect the traffic. If a hospital, a bank or a European company wants to use that model, it usually cannot let its data leave its own infrastructure, sometimes as a matter of law rather than preference. Those two requirements point in opposite directions.

What is interesting is that both major labs are now converging on the same answer from different directions. OpenAI is testing a system with Databricks and Microsoft that aims to detect misuse without storing customer data at all, which we covered earlier this week. Anthropic is keeping the retention but moving the storage to the customer. Different mechanics, same underlying admission: the naive version, where the lab holds everything and asks for trust, does not survive contact with regulated customers.

A fair caveat. Moving data into your own cloud is not automatically privacy. It changes who controls it and who is liable, which matters a great deal legally, but the data still exists for 30 days and someone still analyses it. Read the eventual terms rather than the headline.

What this means for you: If you use Claude as an individual, this is not about you, it concerns enterprise API traffic on the top-tier models. If you are the person at a small company deciding whether an AI tool is allowed near customer data, this is the useful part: “where does the data physically sit and who controls it” is now a question vendors expect and can answer. Six months ago it was a conversation-stopper. Asking it is no longer awkward, and if a vendor cannot answer clearly, that itself is the answer.

Sources

Source: https://www.bloomberg.com/news/articles/2026-08-20/anthropic-plans-to-change-data-retention-policy-for-advanced-ai

Next story

OpenAI's Image Model Can Now Skip the Background Entirely, and It Beats Cutting It Out Afterwards

One parameter gives you a PNG with no background. Baking transparency in during generation handles glass and hair better than any removal tool, and it is in preview through the API.

A checkerboard transparency pattern behind a floating object with scissors beside it