BLOG · MODELE I INFRA

Zero data retention is no longer a vendor promise — it is a property of the model

Modele i infra
  • #modele-i-infra
  • #retencja-danych
  • #zero-data-retention
  • #wybor-dostawcy
  • #ochrona-danych
  • #operator-lens

On 19 August OpenAI committed to keeping zero data retention on frontier models and previewed Private Safety Processing — abuse detection with no human looking at the content, rolling out from September. A day later Bloomberg reported that Anthropic is keeping the mandatory 30 days of retention for its most capable models and simply moving that data into the customer's cloud. In Anthropic's documentation the requirement is already enforced in code: calling a covered model from an organization on ZDR returns an HTTP 400. Data-processing terms have stopped being a property of the vendor and become a property of a single model — which changes what an answer in a procurement questionnaire is worth.

Adam WszendybyłAI operator-architect

What happened

On Wednesday 19 August OpenAI published a post titled "Offering Zero Data Retention for frontier models". The commitment: eligible API customers keep zero data retention on frontier models, so prompts and responses are not retained once a request has been processed, and are not available to the provider's staff. To reconcile that with abuse monitoring, the company is previewing Private Safety Processing — automated detection of patterns across related interactions, with no human looking at the content, and the data held either on the customer's own infrastructure or on the provider's under the customer's keys. Rollout is planned for September, alongside a technical paper. This is a preview announcement, not something you can switch on today.

A day later Bloomberg reported that Anthropic is moving in the opposite direction — or more precisely, it is not withdrawing the requirement, it is relocating it. The mandatory 30 days of retention for its most capable models stays, but from the autumn the data is meant to sit in the customer's cloud rather than the provider's. The person leading Claude Code confirmed the plan and added that the system had been built over several months with more than a hundred customers involved.

The background sits in Anthropic's own documentation, and it is harder than either announcement. Claude Fable 5 and Claude Mythos 5 are designated Covered Models: they require 30-day retention and are not available under ZDR. Calling Fable 5 from an organization on zero retention returns an HTTP 400 error saying the model requires data retention to be enabled. There is a way around it — a toggle at the level of a single workspace — while the rest of the organization stays on zero retention.

Two more sentences on the same page never make the headlines. Even with ZDR in place, the provider may retain data where the law requires it, or where automated abuse systems flag a session — in the latter case for up to two years. And features that are incompatible with zero retention, such as the Batch API, the Files API or code execution, are not blocked: the request goes through and the data is stored under that specific feature's policy.

Our take

In July we wrote that a new risk axis had opened at the model layer: not price, but availability. The past week adds a second one — the terms under which your data is processed. With one difference: this axis does not run between vendors, it runs inside each vendor's own line-up.

Which is why "we use Claude" or "we're on OpenAI" has stopped being an answer in a vendor questionnaire. The answer is a model name. Same organization, same contract, same endpoint — and the retention terms depend on a single string in your configuration.

The most interesting thing here is the 400. Retention has moved out of a contract annex and into the request path. That is good news: switching to a model that breaks your zero-retention commitment does not happen quietly — it simply stops working, and somebody has to click the toggle deliberately. The bad news sits right next to it, in the same documentation: for features incompatible with ZDR, nothing is blocked. The gate on the model shouts; the gate on the feature says nothing. If a team turns on the Files API or code execution inside an organization on zero retention, nobody sees an error — they see a working feature, and keep believing nothing is stored.

It is also worth seeing what neither announcement changes. Zero is never quite zero: both providers reserve retention required by law, plus retention after an automated system flags a session. That is not a loophole, it is normal construction — and it belongs in your impact assessment in advance, rather than being discovered during an audit.

We flag this explicitly as our expectation, not an established finding: both companies will end up at "data in the customer's cloud, keys with the customer", because that is the only version that clears a European procurement questionnaire without footnotes. Except neither is live yet. OpenAI says September, Anthropic says the autumn. Until then, replanning an architecture around a promise is a bet, not a decision.

Why this matters

Private Equity

A zero-retention clause signed a year ago need not cover the model the company runs today. This is a cheap item in due diligence and it does not need a lawyer: ask for the list of model identifiers actually called in production and match it against the provider's current data-retention page. Often more revealing than the result is how long the company takes to assemble that list. If nobody has it to hand, every answer about AI data processing is being written from memory.

Enterprise

The retention exception is pinned to the model, so raising its version is a change to processing, with consequences for your impact assessment, your record of processing activities and your sub-processor list. In most organizations a model upgrade is a ticket rather than a process change, and it travels the same path as a library bump.

The second thread is organizational. A retention toggle at workspace level means the company's compliance posture can be changed from a console in a matter of seconds, with no risk function and no legal involved. This is not a complaint about the provider — the design is sensible, because it lets you carve out one team instead of the whole organization. You just need to settle who holds that toggle before somebody needs it on a Friday afternoon.

SMB / mid-market

Start with the thing that is easy to miss: zero retention is not a default setting or a field in a panel. It is a contractual arrangement for approved customers, so a mid-sized company most often simply does not have it and never did. Nothing bad has happened — but you need to know it before you write into a client proposal that their data is not stored.

The practical move costs less than a negotiation: pin the model version in your configuration and do not let it update itself. When we build an agent on an existing pattern from our product library, the model layer is a line in the specification together with its data terms, not an environment detail somebody bumps while tidying up dependencies.

One move this week

Write out the model identifiers your systems actually call — not the ones from the deck, the ones in your environment variables and your code. Put two columns next to each: what the provider's retention policy for that model is today, and who in your organization can change it. If assembling that list takes more than half a day, that is the real output of the exercise and a topic for your next architecture review, not something to be embarrassed about. Describe your case: mailto:[email protected]?subject=Rozmowa%20z%20Aurora%20AI.

Reading us regularly? Set us as a preferred source.

In your Google search settings you can add aurora-ai.pl as a preferred source — our analysis will then surface more often in your results.

LET'S START

Bring the process, not the slides.

If you read our blog and spot an area you want to improve in your own organization — write to us. We start every conversation from something concrete.