After Palantir founder Alex Karp had set off the conversation around frontier labs using data provided by their customers to compete with them, Anthropic and OpenAI have simultaneously looked to change their policies.
OpenAI announced on Wednesday that it’s previewing a system called Private Safety Processing, designed to preserve Zero Data Retention (ZDR) for business customers even as its models take on longer, more autonomous tasks. Anthropic followed within a day, signalling plans to let enterprise customers keep their data on infrastructure they control when using its most capable models, a reversal of the retention policy it had imposed on Claude Fable 5 and Claude Mythos 5 just weeks earlier.

Why this comes up now
The timing follows weeks of public pressure from Palantir CEO Alex Karp, who has repeatedly accused frontier AI labs of using enterprise data, intellectual property and expertise to eventually compete with the very businesses paying for their models. Karp has called this dynamic “colonizing” the enterprise, and has pushed the idea of “AI sovereignty,” where companies retain control over their data and workflows regardless of which AI model they use. His campaign escalated through the summer with television appearances, a Palantir shareholder letter invoking “Marxist” undertones in the AI business, and a white paper laying out steps organizations could take to protect themselves from labs like OpenAI and Anthropic.
Anthropic had given Karp’s argument fresh ammunition in June, when it launched its Mythos-class models — Claude Mythos 5 and its public-facing counterpart, Claude Fable 5. Unlike other Claude models, which can operate under Zero Data Retention agreements, Anthropic required that prompts and outputs from Mythos-class models be retained for 30 days “for trust and safety purposes,” with no opt-out available to enterprise customers. The company said the data wouldn’t be used for training and would only be accessed for safety reviews, but the policy still represented a departure from the zero-retention commitments many enterprise customers had come to expect, and drew criticism from security and compliance teams at companies including Microsoft.
What OpenAI is offering
OpenAI’s Private Safety Processing extends the automated protections already used in ZDR deployments across related interactions, rather than evaluating each interaction in isolation. The idea is to let automated systems flag patterns of misuse — coordinated jailbreak attempts, for instance, or an agent that keeps acting after being told to stop — without giving OpenAI staff access to the underlying prompts or outputs.
Under the system, customer content can either stay entirely on infrastructure the customer controls, or be stored on OpenAI’s infrastructure but encrypted with keys that OpenAI itself doesn’t hold. When automated systems detect a possible violation, OpenAI receives only a narrow signal about the category and severity of the flagged activity, not the content itself. Customers can then investigate using their own systems and choose whether to share anything further with OpenAI if they want to appeal an enforcement action.
OpenAI said it has been testing the approach with early customers including Glean, Databricks, Abridge and Microsoft, and plans a wider rollout along with a technical white paper in September.
What Anthropic is planning
Anthropic’s response, still unofficial as of this writing, points in a similar direction. Per Bloomberg’s sourcing, the company is preparing a system that would still require 30 days of data retention for its most advanced models, but would let enterprise customers hold that data on their own cloud infrastructure rather than Anthropic’s. The report notes Anthropic declined to comment, though the outlet’s source described the system as having been in development for months, developed alongside more than 100 customers in regulated industries.
Anthropic Claude Code lead Boris Cherny appeared to confirm the plans in a post cited by Bloomberg, saying Mythos-class models require additional safety measures because of enterprise privacy and compliance needs, and that customers would be able to own and control their own data with the change “coming this fall.”
The shift is notable given that Anthropic had, in an internal report acknowledged by the company, flagged its own retention policy as a competitive risk, warning it would “be unpopular with customers who have come to expect zero retention” — particularly if rivals didn’t follow suit.
The bigger picture
Both companies are framing their moves as safety upgrades rather than retreats, arguing that spotting sophisticated misuse increasingly requires looking across multiple interactions rather than one prompt at a time. But the near-simultaneous announcements, arriving just as Karp’s sovereignty argument has gained traction among enterprise CIOs, suggest the labs are also responding to a broader trust problem: convincing large customers that using a frontier model doesn’t mean handing over the keys to their data.