AI Safety & Security
Data Custody Becomes a Frontier Model Feature
Anthropic will let enterprises hold the 30-day logs its top models require, two days after OpenAI previewed zero-retention safety monitoring.
Two of the largest model vendors changed their data-custody positions inside 48 hours, and the change belongs on every procurement checklist written this quarter. On Wednesday, OpenAI previewed Private Safety Processing, an automated system that looks for misuse patterns across related interactions while retaining no prompts or responses, described in TechCrunch’s report on the privacy move. By Thursday, Anthropic signalled it would let enterprise customers keep the 30 days of logs its most capable models require on infrastructure those customers control, a reversal reported in OfficeChai’s account of both policy shifts.
The retention requirement itself is not new, and neither is the objection. Anthropic imposed mandatory 30-day retention on its Mythos-class models with no enterprise opt-out, citing trust and safety, and drew criticism from security and compliance teams at customers including Microsoft. What is new is the concession’s shape: the obligation stays, the custody moves. That distinction is the whole negotiation.
Custody, not retention, is the term that matters
For a compliance officer, “we retain nothing” and “you retain everything on your own infrastructure” solve different problems. Zero retention answers the question of what a vendor could be compelled to produce. Customer-held retention answers the question of whether safety obligations can be met without surrendering the data — and it leaves the customer holding a 30-day corpus of prompts and outputs that is itself now a discoverable, breachable asset with a lifecycle to manage.
OpenAI’s approach, as The Next Web described the announcement, widens automated monitoring across several related interactions at once while keeping staff away from the underlying content, with customer content either staying on infrastructure the customer controls or sitting on OpenAI’s encrypted with keys OpenAI does not hold. Computerworld’s coverage notes the capability is in testing with eligible enterprise and API customers and addresses a real gap: per-interaction evaluation cannot catch misuse that unfolds across sessions.
There is also a derived cost nobody is quoting. Thirty days of retained agent traffic scales with token volume, not seat count: a fleet running long-horizon tasks generates orders of magnitude more retained content per user than a chat deployment does. A team moving from interactive chat to autonomous agents can multiply its retained-data footprint without changing a single line of its data-protection impact assessment — and the assessment is what an auditor reads.
Neither approach is free. Cross-session monitoring is compute that someone pays for, a point this paper has already put a number on in OpenAI’s 20% compute tax on safety monitoring. Customer-held logs are storage, access control, retention scheduling, and legal exposure that someone staffs. The vendor competition is over which of those costs a buyer prefers to carry, not over whether the cost exists.
What to change in the contract this quarter
Three edits, in order of value, and all three should be made before the frontier tier is switched on rather than after.
First, separate retention from custody in the language. A clause that says “no data retention” is now ambiguous: it may mean the vendor holds nothing, or that the vendor holds nothing because you agreed to hold it. Name the party, the location, the duration, and the deletion trigger. Second, price the storage obligation before accepting the frontier tier. Thirty days of prompts and outputs for an agent fleet is not a rounding error in either volume or sensitivity, and the team that owns that bucket needs to know it exists before the first regulator asks. Third, ask what happens on a violation. Retention windows extend when misuse is suspected, and the extension terms — how long, for what, decided by whom — are where the real asymmetry sits.
A fourth edit is worth adding if your agents touch regulated data: require the vendor to state, in writing, which model tiers carry retention obligations and how you will be notified when a tier’s classification changes. Anthropic’s requirement applies to covered models and “future models with similar capabilities,” which is a category that expands by the vendor’s own definition. A model upgrade should not silently import a storage obligation into an environment that was scoped without one.
The counterpoint deserves weight: this is competitive positioning as much as principle, arriving while both companies prepare public listings and while enterprise buyers in finance, healthcare, and defense treat vendor retention as a compliance defect. Anthropic argued the retention requirement served safety, and moving the logs to a customer bucket does not make the underlying monitoring less necessary — it makes it someone else’s operational burden. A policy that shifts under commercial pressure can shift again, which is an argument for contractual commitments over blog posts. That fragility is a familiar theme in coverage of Anthropic’s guarded release of Fable and Mythos, where deployment terms moved faster than customer planning cycles.
The verdict changes on documentation. OpenAI has said a technical white paper and broader rollout follow; Anthropic’s reversal is so far reported rather than published. Until both exist as terms a buyer can cite, treat custody claims as roadmap. Teams evaluating suppliers on this axis should also weigh how much leverage they have generally, which is thinner than it looks given the capital dynamics in today’s brief on Anthropic’s IPO math and the vertical-model economics driving today’s lead.