HomeAIAnthropic Data Policy U-Turn: Enterprise Data Moves Back to Client Clouds

Anthropic Data Policy U-Turn: Enterprise Data Moves Back to Client Clouds

Anthropic is preparing a significant shift in how it handles enterprise data, moving away from a system that stored customer information on its own servers toward one that keeps it inside each customer’s private cloud. The move, first reported by Bloomberg, marks a notable reversal for the Anthropic data policy that has drawn criticism from business customers since it was introduced earlier this year, and it signals just how much pressure AI labs are under to balance safety monitoring with corporate privacy demands.

Key takeaways

  • Since June, Anthropic has stored all customer data from its Mythos and Fable models on its own servers for 30 days to detect potential misuse.
  • Anthropic itself admitted the rule was unpopular with clients and represented a real business risk.
  • Under the revised Anthropic data policy, information will remain in the customer’s own cloud instead of Anthropic’s infrastructure, though the 30-day window stays intact.
  • The new system was built with input from more than 100 customers in regulated industries, according to Bloomberg.
  • Anthropic developer Boris Cherny confirmed the change publicly on X, with rollout expected in the fall of 2026.

Anthropic’s original data storage policy and its purpose

Anthropic’s original approach centered on collecting a broad slice of customer activity to catch emerging threats before they spread. Since June, the company has kept all customer data generated through its Mythos and Fable models, along with future flagship releases, on its own servers for a full 30 days. The goal was straightforward: give Anthropic’s safety teams a window long enough to spot new cyberattacks that use the technology, including attempts to weaponize its models for malicious code or coordinated abuse.

That kind of monitoring makes sense from a security standpoint. Attackers rarely tip their hand in a single conversation, and a longer retention window gives a company more room to notice patterns across sessions. But it also meant Anthropic was sitting on sensitive corporate data for a month at a time, a detail that did not sit well with everyone using its enterprise data storage arrangements.

Challenges and enterprise pushback on Anthropic’s policy

Enterprise customers pushed back almost immediately, and Anthropic has not tried to hide it. In its own reporting, the company admitted the rule was unpopular and acknowledged it as a genuine business risk, a rare moment of candor for an AI lab discussing something that could scare off paying clients.

The concern is easy to understand. Companies in finance, healthcare, and other regulated sectors handle information that cannot simply sit on a third party’s servers without raising compliance questions. For those customers, having their data physically housed with Anthropic, even temporarily and even for safety purposes, clashed with internal governance rules and, in some cases, with legal obligations tied to where and how sensitive data can be stored.

That friction helps explain why Anthropic went back to the drawing board rather than simply defending the original design.

New data storage approach emphasizing customer cloud control

Anthropic’s fix keeps the same 30-day detection window but moves the data itself. Instead of housing it on Anthropic’s own infrastructure, the new setup lets the information sit inside the customer’s own cloud environment. Anthropic still gets the visibility it needs to catch misuse, but the customer keeps physical and administrative control over where its data lives, an important distinction for any company answering to regulators or internal audit teams.

Collaboration with regulated industry customers

This wasn’t a policy change dreamed up in isolation. According to Bloomberg, Anthropic spent months building the new system alongside more than 100 customers from regulated industries, the exact group most affected by the original rule. That kind of direct collaboration suggests Anthropic treated the backlash as a design problem to solve with its biggest clients rather than a public relations issue to manage from a distance.

Confirmation and timeline for policy change

Anthropic developer Boris Cherny confirmed the coming changes publicly on X, giving the shift an official stamp beyond the initial reporting. The company has set a target of this fall, meaning enterprise customers should expect the cloud-based retention model to roll out in fall 2026. The 30-day retention period itself is not going away; only its location is changing.

Comparative industry context on AI data security

Anthropic isn’t alone in wrestling with this trade-off, and its main rival is taking a different route entirely. OpenAI has been testing an alternative method built with Databricks and Microsoft, also aimed at pairing security monitoring with stronger data control for enterprise clients. Rather than moving stored data to a customer’s own cloud, OpenAI’s approach leans on a system it calls Private Safety Processing, which watches for abuse across multiple sessions using automated agents while retaining none of the underlying customer data itself.

That distinction matters for anyone comparing options in AI data security. Anthropic’s model still involves retaining data, just relocated to regulated industries cloud environments the customer controls, with human review limited to a small set of approved reviewers and logged in a way the company describes as tamper-proof. OpenAI’s model, by contrast, tries to avoid retaining conversation data altogether, flagging only narrow signals of possible misuse and letting the customer decide how much, if anything, to share afterward.

The rivalry between the two labs is playing out on more than one front, and this data-policy contest is really a proxy for a bigger question the whole industry is facing: how much visibility should an AI company keep over what its enterprise customers are doing, and how much should stay entirely in the client’s hands? Anthropic’s answer, at least for now, is to keep watching but hand back the keys to where the watching happens. Whether that compromise satisfies regulators and cautious enterprise buyers once it actually ships this fall remains the open question for the rest of the year.

FAQ

Why did Anthropic originally store customer data for 30 days?

The 30-day data storage was implemented to detect new cyberattacks using the technology, giving Anthropic’s safety teams enough time to spot suspicious patterns across sessions.

What is the key change in Anthropic’s data storage policy?

Anthropic will keep customer data in the customer’s own cloud rather than on Anthropic’s servers, giving enterprise clients direct control over where their information is physically stored.

Will the data retention period change under the new policy?

No, the 30-day data retention period remains unchanged under the new policy. Only the storage location is shifting from Anthropic’s infrastructure to the customer’s cloud.

When will Anthropic implement these changes?

The policy changes are planned to be implemented in the fall of 2026, following months of development with more than 100 customers from regulated industries.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Francesco Antonio Russo
Web 3.0 entrepreneur for over 4 years, expert in Cryptocurrencies and Artificial Intelligence. He uses his cross-functional skills for functional and trend-following Social Media Management.
RELATED ARTICLES

Stay updated on all the news about cryptocurrencies and the entire world of blockchain.

Featured video

LATEST