TL;DR

Anthropic intends to give business customers more say over where their Claude data lives, according to a source cited by Reuters. The 30-day retention requirement stays, but companies will be able to hold that data on their own cloud infrastructure instead of Anthropic’s. A new safety system is expected later this year, developed with input from more than 100 customers including Salesforce.

What changes and what does not

The distinction here is custody, not duration. Anthropic announced in June that all enterprise traffic on its more capable Fable and Mythos models, and on frontier models to come, would be retained for 30 days as a guard against its technology being used in cyberattacks. That requirement survives.

What moves is the location. Under the revised approach the data can sit in infrastructure the customer already controls. For a UK organisation with data residency obligations, or a board that has spent two years being told sovereignty means control rather than geography, that is a materially different proposition from handing logs to a US vendor for a month.

The timing is not accidental

OpenAI announced a safety system on Wednesday that identifies potential misuse without retaining customer data at all. Anthropic’s plan surfaced on Thursday. Reuters reports the changes have been in development for months and involved coordination with over 100 customers, so this is not a same-week response — but the sequencing means enterprise buyers now have two clearly differentiated postures to compare.

Neither is strictly better. OpenAI’s approach removes the data entirely, which is cleaner for privacy and leaves less for an investigator to work with. Anthropic’s keeps a 30-day window but puts it under the customer’s own key management and jurisdiction.

Looking forward

For UK enterprise procurement this makes an abstract argument concrete. The choice between vendors is now partly a choice between “we hold nothing” and “you hold it yourself” — and the second is easier to explain to an auditor who wants to know where the records are.

Expect the question to move from privacy teams to legal ones. Retention you control is retention you can be compelled to produce, which is a different risk profile from data that was never kept.