Comparing OpenAI and Anthropic’s Data Retention Policies: How OpenAI’s Private Safety Processing and Anthropic's Enterprise Frontier Safeguards affect ZDR policies

Anyone who sends private data to an AI model or service deserves a clear answer to three questions: (i) Where do they store it? (ii) How long do they keep it? and (iii) What, if anything, will they do with it (such as train on it, show to humans, etc.)

Share
Flowchart illustrating data storage and review process, highlighting customer and OpenAI roles in data handling.

Anyone who sends private data to an AI model or service deserves a clear answer to three questions: (i) Where do they store it? (ii) How long do they keep it? and (iii) What, if anything, will they do with it (such as train on it, show to humans, etc.) This week, business customers for two leading companies got two responses: one leaked, then confirmed, and another previewed. Technical details are scarce for both.

What’s new at Anthropic: Since June, businesses using Claude Fable 5 have been required to let Anthropic keep their conversations for 30 days. Now Anthropic will soften that rule, with a new program called Enterprise Frontier Safeguards (EFS) that will require companies with zero data retention (ZDR) policies to keep the data on their own servers or those of specific cloud providers instead. Until EFS is available sometime this fall, eligible enterprise customers will be able to use Fable 5 and Fable 5.1 without Anthropic retaining any data. 

Meanwhile at OpenAI: One day before Bloomberg broke the Anthropic news, OpenAI published a post promising that for business customers, its most capable models come with ZDR. This means OpenAI never logs a business’s prompts and replies. It’s offered to approved businesses that plug the models into their own software. The post also previewed Private Safety Processing (PSP), a system meant to spot misuse spread across many requests without OpenAI reading the prompts.

How it works: Both companies describe the same method: software watches requests over time and flags patterns. No human review is required. Here is what neither explains: “Our employees can’t see it” is not the same as “our systems can’t see it.” To scan the data, software the company wrote has to unlock and read it, wherever it is stored. Sholto Douglas, a member of Anthropic’s technical staff, described the plan on X as monitoring “done via automated systems we provide to you.” Here’s where each company stands.

  • In force today: Anthropic keeps Fable 5 and Mythos 5 conversations for 30 days on every platform, per its help center. Further, content that the company flags according to a process set at its discretion can be kept up to two years under its general policy, and reviewers Anthropic approves can read it through a logged process. OpenAI says its staff can’t see ZDR customers’ conversations, except where required by federal law.
  • What’s been promised: Anthropic will require data to be retained for the same 30 days, but stored on the customer’s servers — either their own or through a third-party provider such as Google Cloud, Microsoft Foundry, or Amazon Web Services. (Disclosure: Andrew Ng is a member of Amazon’s board.) The 30 day requirement will stay, but the data will sit on the customer’s designated servers instead of Anthropic’s, and customers have the option to manage their own encryption keys, audit logs, and other security data. OpenAI’s Private Safety Processing will scan data held on the customer’s servers or encrypted on OpenAI’s with keys OpenAI says its staff doesn’t have, and report back only a label for the type of activity, not the content.
  • Why both companies say they need this: The primary threats EFS and PSP are designed to address are cyberattacks. Some attacks show up only across many requests. Anthropic’s help center cites spying by governments and “best-of-N” jailbreaking, where an attacker rewords a blocked request hundreds of times until one version gets through.
  • Undisclosed: It remains unclear how either company’s software reads data they claim they can’t see. OpenAI has promised a technical paper for PSP in September; Anthropic published one for its June data retention policy but has given few technical details about how EFS would work. Neither company has disclosed the specific criteria that they apply to consider something a “cyberattack” or “unsafe.”

Behind the news: Anthropic’s June rule forced an exception to the ZDR contracts some business customers already had. These customers had to switch retention on to use the new models at all. Consequently, many businesses declined to use Fable 5. As we reported in June, the ARC Prize Foundation also declined to run its verified tests of Fable 5 rather than expose its private test questions. Anthropic has since acknowledged the cost; in an August risk report it wrote that the rule would “be unpopular with customers who have come to expect zero retention” and could hurt its business if rivals didn’t do the same. OpenAI has not; its post reaffirmed zero retention.

Why it matters: Businesses are deciding now whether to trust these models with sensitive data based only on press releases. For regulated industries like law firms, hospitals, and banks, “we won’t train on your data” and “we don’t have your data” are different promises. Businesses also lack clarity on when Anthropic may change its definition of when someone is acting "unsafely" and may have their prompts — which often contain extremely sensitive data — read by Anthropic employees. And any data that can be found on a server can be compromised by an attacker or demanded by a court. Last year, in The New York Times’ copyright suit, a court ordered OpenAI to preserve chat logs it would normally have deleted, even ones users had erased. OpenAI said ZDR customers were unaffected because it never had their data. Whether logs held on a customer’s servers could be reached in a suit against the AI company is a question neither company has addressed. Neither has published an independent audit of its design.

We’re thinking: In 2024, we described four levels of cloud AI privacy, and the strongest, where the provider cannot access your data at all, is the level that matters most for sensitive work. This is especially true given loopholes that give frontier labs discretion to apply whatever standard they wish to define what is “safe.” We contrast this with the simple privacy policies of many hyperscalers, where rules are much clearer: We expect them not to look at our data unless a warrant, court order, or other more predictable legal process requires them to. Both companies now say they can preserve user privacy while still catching misuse across many requests. Neither has shown how. Until both of them publish their designs, that’s a roadmap, not a guarantee.