Skip to main content
Anthropic's cloud data storage solution, addressing privacy concerns after criticism.

Editorial illustration for Anthropic keeps 30-day data rule but stores it in customer clouds after criticism

Anthropic Shifts Data Storage to Customer Clouds

Anthropic keeps 30-day data rule but stores it in customer clouds after criticism

4 min read

Since June, Anthropic has held onto every prompt and output run through its Mythos and Fable models for 30 days, keeping the data on its own servers so it could scan for signs of cyberattacks built with the technology. Enterprise customers, particularly those in regulated industries like finance and healthcare, didn't like handing over that control, and Anthropic is now unwinding the arrangement, at least partly.

The company spent months working with more than 100 customers to build a system that keeps the 30-day retention window intact but moves the storage itself into the customer's own cloud rather than Anthropic's. Anthropic developer Boris Cherny confirmed the change on X, with the new setup expected to roll out this fall.

The shift puts Anthropic in the same territory as OpenAI, which is testing its own version of split custody with Databricks and Microsoft, aiming to let companies keep security scanning without giving up their data. Anthropic's own report on the matter didn't dodge the criticism, admitting the original policy had become both unpopular with clients and a genuine liability for the business.

In a report, Anthropic admitted the rule was unpopular and a business risk. The 30-day window stays in place, but under the new setup, the data will sit in the customer's cloud rather than with Anthropic.

Why this matters

For anyone building on Claude, this is a real concession, not a cosmetic one. The 30-day retention window hasn't gone away, so Anthropic still gets its cyberattack-detection window. What's changed is custody: data now sits in the customer's own cloud instead of Anthropic's servers, which matters enormously for regulated industries, government contractors, and any founder whose enterprise contracts have data-residency clauses baked in.

Anthropic's own admission that the policy was "unpopular" and a "business risk" is notable, too. It suggests the pushback from enterprise customers since June actually moved the needle, rather than being absorbed and ignored. The fact that this took months of engineering work with more than 100 people, per Bloomberg, tells us this wasn't a quick policy memo, it required real infrastructure changes.

For developers and researchers, the lesson is that safety monitoring and data sovereignty aren't automatically at odds. Watch whether OpenAI, Google, or Meta feel pressure to match this custody model, and whether Anthropic's flagship models beyond Mythos and Fable inherit the same treatment by default.

Common Questions Answered

Why did Anthropic change its 30-day data retention policy for Mythos and Fable models?

Enterprise customers in regulated industries like finance and healthcare objected to Anthropic storing their prompts and outputs on its own servers for 30 days. The policy created business risk and was unpopular among customers with data-residency requirements, prompting Anthropic to redesign the system after working with over 100 customers.

How does the new data storage arrangement differ from Anthropic's previous 30-day retention rule?

Under the new setup, customer data still remains subject to the 30-day retention window, but instead of being stored on Anthropic's servers, it now sits in the customer's own cloud infrastructure. This change allows Anthropic to maintain its cyberattack-detection capabilities while giving customers control over data custody and location.

Which industries benefit most from Anthropic's updated data residency policy?

Regulated industries such as finance, healthcare, and government contractors benefit significantly from the new policy since they typically have data-residency clauses in their enterprise contracts. The shift to customer-controlled cloud storage ensures these organizations can comply with regulatory requirements while still using Anthropic's Claude models.

Did Anthropic eliminate the 30-day data retention period entirely?

No, Anthropic kept the 30-day retention window in place because it serves an important security function for detecting cyberattacks built with the technology. What changed is not the duration of retention but the location where the data is stored—now in customer clouds rather than on Anthropic's servers.

LIVE13:18Meta Pays Microsoft Hundreds of Millions Annually for AI