Dario Amodei Told AI Labs to Slow Down. OpenAI Blinked.
On September 1, Anthropic announced Enterprise Frontier Safeguards, a system built to undo a decision the company made less than three months earlier — and, per its own internal risk report, one it knew would be unpopular the moment it made it. Anthropic’s June rule that customer prompts to Claude Fable 5 and Mythos 5 get held for 30 days, even under existing zero-retention contracts, is effectively gone for anyone willing to store that data themselves. Same 30-day monitoring window. Different address for the data. That’s the whole fix, and it took a summer of enterprise customers pushing back to get there.
That’s not spin. Anthropic said as much in its own risk assessment, reported by Business Today: the retention requirement would “be unpopular with customers who have come to expect zero retention, and pose real risks to our business success (especially if competitors do not follow).” Anthropic wrote that down, published Fable 5 anyway with the policy attached, and then spent the next 11 weeks watching the prediction come true.
Quick Summary: What Happened
Detail Info Original policy 30-day data retention for Fable 5 and Mythos 5, effective June 9, 2026, overriding existing zero-retention agreements Stated reason Catching misuse patterns that only show up across sessions — Best-of-N jailbreaking, distillation campaigns, state-sponsored attacks The fix Enterprise Frontier Safeguards, announced Sept 1, 2026 What changes Monitoring stays; the data itself moves into the customer’s own AWS, Google Cloud, or Azure environment, under the customer’s own keys Who helped design it 100+ customers, including CISOs from Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo via the Analysis and Resilience Center for Systemic Risk Cost No fee from Anthropic (customers pay their own cloud provider for storage and egress) Rollout Phased, beginning fall 2026, across Claude Code, Claude Enterprise, Claude Platform, Bedrock, Google’s Agent Platform, and Microsoft Foundry Bottom line: Anthropic tried to keep enterprise activity logs on its own servers for a month at a time, banks and other regulated customers said no, and Anthropic redesigned the whole system around keeping the surveillance but losing custody of the data.
Roll back to June 9. Anthropic shipped Claude Fable 5 as its first public Mythos-class model, alongside the more restricted Mythos 5. Bundled into that launch was a policy change that got far less attention than the benchmark scores: prompts and outputs from “covered models” — Fable 5, Fable 5.1, and anything Anthropic later designates comparably capable — would be retained for 30 days, full stop, according to Anthropic’s own privacy documentation. That applied even to organizations running under a pre-existing zero data retention agreement, as long as they touched Fable 5 through Claude Console, Claude Enterprise, Bedrock, Google Cloud’s Agent Platform, or Microsoft Foundry.
Anthropic’s justification wasn’t unreasonable on its face. Some attacks don’t look like anything suspicious inside a single request — they only resolve into a pattern once you can see dozens or hundreds of requests together. Best-of-N jailbreaking works by brute-forcing slight variations until one slips past a classifier. State-sponsored espionage and credential-theft campaigns get spread across sessions and accounts specifically to avoid looking like one continuous attack. Anthropic argued it needed a 30-day window to connect those dots, and that zero retention made that kind of detection structurally impossible.
Regulated enterprises heard a different sentence: we’re going to hold your data on our servers for a month, whether you agreed to that or not. For a bank, a hospital system, or a law firm, that’s not a minor inconvenience — it’s a compliance event. New data-handling terms mean legal review, customer notification obligations in some jurisdictions, and internal policies about where sensitive material is allowed to live, none of which move at product-launch speed. Our privacy guide has flagged this exact tension all year: enterprise buyers don’t just want privacy promises, they want custody, and custody is the one thing a vendor-hosted retention policy can’t offer no matter how well-intentioned the reasoning behind it is.
Anthropic didn’t build this alone, and it’s worth naming who was in the room. Per Anthropic’s announcement and confirmed by Help Net Security, more than 100 customers across financial services, healthcare, manufacturing, and the public sector fed into the design — including CISOs from Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo, coordinated through the Analysis and Resilience Center for Systemic Risk, the industry group that represents every U.S. globally systemically important bank. Wells Fargo’s CISO put the arrangement bluntly: “We keep custody of our data while Anthropic operates the detection.” That sentence is the entire product in eight words.
Strip away the engineering and this is a story about leverage, and about Anthropic badly misjudging how much of it enterprise buyers actually have right now. Anthropic wrote in its own risk assessment that the June policy would be unpopular and could hurt the business “especially if competitors do not follow” — and then shipped it anyway, apparently betting that Fable 5’s capability lead would carry the policy through the objections. It didn’t. Regulated customers didn’t grumble and adapt. They held out, and Anthropic rebuilt the system around their terms in under three months.
Compare that to how slowly the industry usually moves on data-handling policy, and the speed here says something. Anthropic’s own compute spending tells you the company is racing toward an October IPO that needs a growth story built on enterprise demand, not consumer subscriptions. Enterprise demand, in turn, runs straight through the eight banks in ARCSR and the compliance officers like them at every Fortune 100 company Anthropic is trying to sign. When your growth story depends on customers who can’t legally accept your default terms, you don’t get to hold that line for long. Anthropic didn’t.
There’s also a competitive angle Anthropic’s own risk report anticipated almost word for word. Axios reported in August that OpenAI was previewing a competing approach called Private Safety Processing — designed to detect misuse without retaining customer data on OpenAI’s servers at all. Anthropic was the outlier holding data while a direct competitor pitched a cleaner privacy story to the same buyers. “Especially if competitors do not follow” turned out not to be a hypothetical.
If you’re an enterprise Claude customer currently under the 30-day policy, check whether your account already qualifies for the interim zero-retention treatment Anthropic says it’s applying to Fable 5 and 5.1 traffic during the transition. If you haven’t heard from your account team, ask — this isn’t automatic for every workspace on day one.
If you’re evaluating Enterprise Frontier Safeguards for your own cloud environment, budget for it like infrastructure, not like a software feature. Anthropic isn’t charging anything, but AWS, Google Cloud, and Azure will bill you directly for the storage, read/write operations, and egress that logging generates — and egress fees in particular have a way of showing up bigger than teams expect once monitoring runs continuously across every seat.
If you’re comparing frontier labs on data-handling terms right now, don’t just read the marketing page. Read what each vendor’s own risk disclosures say about the tradeoffs, the way Anthropic’s report telegraphed this reversal months before it happened. Our guide to AI safety and privacy is a reasonable starting checklist for what to ask any vendor, not just Anthropic, before you sign.
Every frontier lab is running into the same wall this year: the safety case for retaining data and the compliance case against it point in opposite directions, and there’s no version of “trust us” that satisfies a bank’s legal department. OpenAI’s answer, still in early testing per Axios’s reporting, is to try to detect misuse without retaining anything identifiable at all — a harder engineering problem, if it works, but one that sidesteps the custody question entirely. Anthropic’s answer is closer to a compromise: keep the surveillance, hand over the keys. Both are real attempts at the same problem. Neither is obviously the final word, and enterprise buyers now have two competing architectures to hold each vendor to.
It also fits a pattern this site has tracked all year with Anthropic specifically. The company has repeatedly shipped aggressive defaults — the Mythos-class capability jump, the export-control pullback on Fable 5, the compressed three-day pricing decision window at the end of June — and then walked pieces of them back once the market pushed. Enterprise Frontier Safeguards is the cleanest example yet, mostly because Anthropic’s own paper trail admits the walk-back was foreseeable before the policy even shipped.
We think this is a genuine win for enterprise buyers, and a useful data point on how little patience regulated industries have for “trust our infrastructure” as a security model in 2026. Wells Fargo’s CISO didn’t get a better privacy policy out of Anthropic’s goodwill. Eight systemically important banks organized through ARCSR and made non-negotiable custody a condition of continued business. That’s the model working as intended, and more vendors should expect this exact playbook from this exact customer segment going forward.
We’d also flag the caveat The Register raised and think it’s the right one: Enterprise Frontier Safeguards moves the data, but it also moves the operational burden. Automated alerts now land in the customer’s own security team’s queue instead of Anthropic’s, which means the actual review quality depends on whether that team has the staffing and expertise to act on it. A bank the size of Wells Fargo has that. A mid-sized manufacturer or a regional healthcare system signing up for the same architecture might not, and “you now own the monitoring pipeline” is a meaningfully different commitment than “your vendor handles it,” even when the marketing language sounds like an unambiguous privacy upgrade.
The part we’d bet on mattering past this specific announcement: the design-partner list. This wasn’t Anthropic polling the broad market — it was 100-plus large, well-resourced customers with the leverage to demand a rebuild. Smaller Claude customers are getting the same architecture without having had a seat at the table that shaped it, which is worth remembering the next time a vendor says a policy was “built with customer input.” Ask whose input, and how much revenue they represented.
Enterprise Frontier Safeguards (EFS) is a system Anthropic announced on September 1, 2026, that lets enterprise customers keep the same 30-day misuse-monitoring window Anthropic uses on Fable 5 and Mythos 5, while storing the underlying activity data in the customer’s own AWS, Google Cloud, or Azure environment instead of Anthropic’s servers.
Starting June 9, 2026, Anthropic began retaining all prompts and outputs from Fable 5 and Mythos 5 for 30 days, even for customers with existing zero-retention agreements, in order to detect misuse patterns like Best-of-N jailbreaking and multi-session attack campaigns that a single-request review couldn’t catch.
Regulated industries — banking, healthcare, and others — generally can’t accept a vendor holding sensitive activity logs on the vendor’s own servers without triggering compliance reviews, customer notification requirements, and internal data-handling rules. Storing the data with Anthropic, rather than in infrastructure the customer already controls, was the core objection.
Anthropic isn’t charging a fee for it. Customers do pay their own cloud provider — AWS, Google Cloud, or Azure — for the storage, data operations, and egress that the monitoring generates, at that provider’s standard rates.
Anthropic is rolling it out in phases starting fall 2026, across Claude Code, Claude Enterprise, Claude Platform, Amazon Bedrock, Google’s Agent Platform, and Microsoft Foundry. Customers not yet in their rollout phase are meant to receive zero data retention on Fable 5 and 5.1 in the meantime.
No. The original 30-day policy and its replacement both apply to enterprise and API access paths — Claude Console, Claude Enterprise, Bedrock, Google Cloud’s Agent Platform, and Microsoft Foundry. Consumer Claude.ai plans were never subject to the June retention change.
OpenAI’s approach, called Private Safety Processing and still in early testing as of August 2026, aims to detect misuse without retaining identifiable customer data at all. Anthropic’s Enterprise Frontier Safeguards still retains data for 30 days — it just relocates where that data lives, into infrastructure the customer controls rather than Anthropic’s own.
Anthropic says more than 100 customers across financial services, healthcare, manufacturing, telecom, and the public sector provided input, including CISOs from Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo, coordinated through the Analysis and Resilience Center for Systemic Risk, which represents every U.S. globally systemically important bank.
Last updated: September 8, 2026. Sources: Anthropic — Developing Enterprise Frontier Safeguards with our customers · Anthropic — Risk Report: August 2026 · Anthropic Privacy Center — Data retention practices for Covered Models · Business Today — Zero retention vs data logs · Help Net Security — Anthropic’s Enterprise Frontier Safeguards · The Register — Anthropic promises zero data retention, but customers must check it worked · Axios — OpenAI previews zero-retention safety system as Anthropic requires data logs.
Related reading: Claude Fable 5 Review: Anthropic’s Best Model Yet · AI Safety and Privacy: What You Need to Know · Anthropic’s $45B Nscale Deal Caps a $100B Compute Bet · Fable 5 Goes Paid June 22: Your 3-Day Decision · Fable 5 Pulled: What Buyers Need to Know