OpenAI Promises Zero Data Retention as Anthropic Lets Customers Keep the Data

Modèles/fournisseurs associés: Claude Anthropic Anthropic Fournisseur OpenAI Fournisseur
OpenAI Promises Zero Data Retention as Anthropic Lets Customers Keep the Data
Article image
Article image

OpenAI and Anthropic have launched an autumn privacy battle. On August 19, OpenAI announced that its new zero-retention option would keep neither customer prompts nor model responses after processing. The move came two months after Anthropic required some enterprise customers to retain data for 30 days when using its most capable models. The next day, Anthropic said that the data could instead remain in the customer’s own cloud.

Article image

Boris Cherny, creator of Claude Code, said customers would be able to own and control their data, with Anthropic retaining nothing under a new approach planned for autumn. However, the two companies use “zero retention” differently.

Article image

Two policy reversals in 48 hours

Article image

Anthropic’s new rule took effect on June 9. Enterprise customers using the Fable 5 and Mythos 5 model tier had to accept 30-day retention for submitted prompts and generated outputs. On August 19, OpenAI countered with a preview of Private Safety Processing, whose central promise was that customer data would not be retained.

Article image

OpenAI was clearly seeking enterprises dissatisfied with Anthropic’s policy. Anthropic had already been developing an alternative after receiving criticism from customers and consulting more than 100 of them, including Salesforce. OpenAI’s announcement appears to have accelerated that response.

Article image
Article image

Why Anthropic required 30-day retention

Anthropic says the retention period supports safety monitoring. Some attacks are invisible in a single request. In a Best-of-N jailbreak, for example, an attacker may submit hundreds of slightly modified versions of one prompt. Each individual request can look harmless, while the collective pattern reveals the intent. Larger-scale abuse, such as data extortion, likewise requires classifiers to examine many requests together.

Anthropic’s rule targeted organizations that had configured zero data retention but wanted access to Covered Models. Despite additional safeguards, it created problems for some major customers.

Article image

Anthropic changes custody, not retention

According to people familiar with the matter, the 30-day period remains unchanged. The new option allows customers to store the data in their own cloud. For compliance teams, this changes who controls encryption keys, access logs and audit records. When data stays in Anthropic’s infrastructure, customers must rely on Anthropic’s controls and stated commitments. When it stays in the customer’s cloud, the customer controls the keys and can investigate access through its own systems.

Article image

OpenAI receives alerts instead of raw content

OpenAI’s approach is to move the safety system to the data rather than move the data to the system. Private Safety Processing has three main stages:

  1. Raw content remains in infrastructure controlled by the customer, or is stored by OpenAI with encryption using a customer-held key. OpenAI has no copy of that key.
  2. Automated systems examine related interactions across multiple turns to identify risk patterns.
  3. If a risk is detected, OpenAI receives only a narrow signal describing the activity category and severity. OpenAI personnel cannot see the underlying prompts or responses.
Article image

Customers can review alerts in their own systems. They decide whether to provide content for an appeal, clarify legitimate activity or assist with an investigation into confirmed abuse. The system was still in early customer testing, with rollout planned for September and a technical white paper expected at that time.

Article image

Retention is not the same as training

For enterprise customers, Anthropic says prompts and outputs from Covered Models are retained for safety work, while OpenAI says enterprise data is not used for model training by default unless customers opt in. Retention for abuse investigation and use for training are separate technical and policy decisions.

Article image

That distinction does not apply in the same way to consumer plans. Anthropic says consumer inputs and outputs are already retained. They may be used for training if users allow it in settings, if a conversation is flagged for safety review, or if the user joins a program such as Trusted Tester.

In August 2025, Anthropic changed the default setting so that data sharing was enabled unless users actively declined. The prominent Accept button appeared alongside a training-sharing switch that was already on, prompting criticism that the design was a dark pattern.

Article image

A safety review can also create a separate route for analysis and training of safety models, regardless of the user’s training switch. Consumer retention periods are much longer than the enterprise 30-day dispute: permitted conversations can remain in training pipelines for up to five years, policy-violating conversations for two years, and risk scores for seven years.

OpenAI’s consumer plan similarly has training enabled by default and requires users to disable it in settings. Turning training off does not delete existing conversations; deleted chats are removed after an additional 30 days.

Article image
Article image

Both companies agree that sophisticated attacks may emerge only across multiple requests, making safety monitoring necessary. Their key disagreement is whether monitoring requires retaining raw customer data. OpenAI says it can process the data without retaining it and receive only an alert, while Anthropic continues to require 30-day retention but lets customers control where the data is stored.

For AI buyers, model performance, cost and context length are no longer the only considerations. Data location, access rights and retention duration are also central procurement questions.

Partager cet article