Data Retention Terms Prompt Restraints on AI Model Use for Sensitive Operations

Deep News09-14 21:31

Companies including NVIDIA, Palantir Technologies Inc., and Booz Allen Hamilton are limiting how Anthropic's frontier model, Fable, handles sensitive data such as source code, supply chain, and cybersecurity information. Some clients now demand irreversible "zero data retention" guarantees, while others want all data kept entirely on infrastructure under their own control. Anthropic has rolled out an enterprise security offering that permits qualifying customers to manage their own activity data.

Palantir Technologies Inc. offers third-party models to corporate customers through its own software, but it has withheld Fable from that channel until it secures an irrevocable zero-data-retention guarantee. Clients can still go around Palantir and buy the model service directly from Anthropic. NVIDIA, meanwhile, primarily uses Fable for lower-sensitivity tasks like open-source software work. For areas such as internal supply chain monitoring, the company leans on its proprietary Nemotron model. Justin Boitano, vice president of enterprise AI at NVIDIA, stated that zero data retention should become the standard default.

Booz Allen Hamilton has barred employees from using the commercial version of Fable with its proprietary cybersecurity software that it delivers to clients. Although the company still applies Anthropic models in most low-sensitivity scenarios, it worries that some proprietary code could be affected by data retention policies. An executive at a major U.S. utility revealed that his agency had considered testing Fable to manage core power infrastructure for millions of homes, but abandoned that plan after failing to obtain an irrevocable zero-retention commitment. The utility still uses the model for employee onboarding, finance, and human resources tasks.

Where to begin with Fable's standard data policies

Following Fable's launch in June, Anthropic required customer usage records to be kept for 30 days to help detect sophisticated or novel cyberattacks. According to its official technical documentation, Fable 5, Fable 5.1, Mythos 5, and Mythos 5.1 are classified as special coverage models that default to a 30-day retention period. Only clients with explicit authorization are permitted to use these models under a zero-retention arrangement. Zero data retention means that after the API returns results, customer prompts and model outputs are no longer stored in static form. Some functions may still retain limited data for technical operations, compliance audits, or usage metrics, so enterprises must verify whether the policy covers all models, interfaces, and features. Data retention is not the same as model training—Anthropic says retained information is never used for training without explicit customer consent.

Some firms remain uneasy that contract terms on allowable data collection, technical metadata definitions, and exceptions are too vague, and they want tighter and more binding commitments. In response, Anthropic launched Enterprise Frontier Safeguards in September, enabling eligible companies to store activity data required for security monitoring in their own cloud accounts, using their own encryption keys, access controls, and audit logs. This setup still relies on automated systems to analyze usage patterns over continuous timeframes, flagging serious risks such as offensive cyber capabilities, biological weapon development, or credential leaks. Alerts go straight to the customer for internal staff to review, without Anthropic employees needing to inspect the content. Developed in collaboration with more than 100 enterprises, the program is rolling out in stages this autumn. Some clients are still pressing for long-term contractual guarantees so that vendors cannot later revoke self-hosting or zero-retention status.

How enterprises are separating model use cases

Restrictions on frontier models typically focus on a small set of highly sensitive operations rather than a complete ban. Novo-Nordisk A/S lets employees use Claude to analyze public materials and draft general content but forbids entering proprietary data. Northrop Grumman runs open-source models on servers isolated from external networks for tasks like code generation and research support.

Enterprise and API data from OpenAI is not used for model training by default, unless customers actively choose to share it. Its API typically stores security monitoring logs—including prompts, responses, and related metadata—for up to 30 days, and eligible clients can apply for zero retention or modified monitoring arrangements. Zero data retention is not automatically applied to every function. Interfaces that must preserve session states, files, or agent runtime records will still retain application data. Vendors may also suspend zero-retention eligibility for particular customers or models with notice when investigating serious abuse risks.

These changes have made data control capabilities, not just model performance, a key purchasing criterion for enterprises. Customers are increasingly segmenting use cases across public information handling, general office work, proprietary code, client data, and critical infrastructure, choosing hosted models, in-house models, or isolated deployment options based on the sensitivity of each scenario.

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Comments

We need your insight to fill this gap
Leave a comment