Anthropic’s Fable retention policy has triggered enterprise pullbacks, exposing why zero-data-retention promises have not resolved AI trust risks.

Anthropic’s decision to retain usage logs from its flagship Fable model for 30 days has prompted several major customers to restrict or block the system for sensitive work, according to reporting by The Information cited by The Decoder. The episode shows that enterprise assurances about training exclusions and data retention remain difficult for customers to evaluate and trust.
Nvidia is reportedly limiting Fable to less-sensitive work, while Booz Allen Hamilton has prohibited its use for proprietary cybersecurity software. Palantir is blocking deployment of Fable through its platform until Anthropic provides what it describes as irrevocable zero-data-retention guarantees. The reaction has turned a policy intended to support abuse monitoring into a test of whether frontier AI providers can meet the data-control expectations of corporate and government buyers.
Anthropic introduced the 30-day log-retention policy in June to help defend against what it called “complex and novel attacks,” according to The Decoder’s account. For customers handling intellectual property, source code, security research, or operational data, however, retaining logs creates a different risk: sensitive prompts and outputs may remain accessible to the provider or become part of a broader internal data-management system.
The reported response has been especially notable because Nvidia has invested in Anthropic and supplies hardware used in the company’s model development. Nvidia Vice President of Enterprise AI Justin Boitano told The Information that the company believes zero data retention, or ZDR, should be enabled by default. Nvidia is instead using its own Nemotron models for internal applications such as AI-supported supply-chain monitoring, while reserving Fable for less-sensitive tasks including open-source projects.
Booz Allen Hamilton, an early user of Anthropic’s Mythos model, reportedly barred employees from using Fable on proprietary cybersecurity software. CTO Bill Vass said the company was concerned that the model might learn from its code. Palantir’s position also carries a commercial dimension: the company benefits when customers run models through its controlled platform rather than connecting directly to external providers. That incentive does not invalidate the concern, but it is relevant context when assessing the strength of the company’s objection.
Anthropic has reportedly moved toward a customer-managed security-log program following enterprise resistance and OpenAI’s August decision to let GPT-5.6 Cyber customers store security logs on their own servers. Anthropic’s comparable program is expected to roll out to selected customers in the fall, according to the source material. The available reporting does not establish how broadly the program will be offered or whether it will cover every type of enterprise interaction.
A further complication is that zero retention applies to stored content, not necessarily to all information produced when a customer uses an AI service. The Decoder reports that both Anthropic and OpenAI collect metadata and technical usage data from enterprise customers. OpenAI describes some of this information as de-identified and says automated classifiers and security tools analyze business data to understand how its services are used. The company says those classifications contain metadata rather than the underlying business data.
That distinction has not satisfied every customer. The reporting indicates that some organizations remain uncertain about what the metadata includes, how long it is kept, and whether it could reveal commercially valuable patterns. For procurement teams, the question is therefore broader than whether a provider stores prompts. It includes logs, telemetry, classifiers, debugging records, abuse-monitoring systems, and any derived information used to improve products or detect failures.
The central claims in this story come from reported customer decisions and executive comments, not from an independent audit of Anthropic’s or OpenAI’s systems. The Information’s reporting, as summarized by The Decoder, is the basis for the accounts of Nvidia’s restrictions, Booz Allen Hamilton’s internal ban, and Palantir’s deployment policy. Anthropic’s forthcoming customer-managed logging option is also reported rather than documented here through a complete public product specification.
The debate extends beyond direct model training. Former OpenAI co-founder John Schulman has described a spectrum of possible uses for customer data, ranging from direct pretraining to distillation and reinforcement-learning tasks built from user traces. He has argued that de-identification is weak protection against intellectual-property leakage and called for stronger disclosure norms. In a later clarification, Schulman said user data is unlikely to contribute significantly to frontier capability gains compared with large-scale pretraining and reinforcement learning. He nevertheless said such data can help identify failure modes and difficult real-world cases.
Researcher Sarah Hooker has raised a related concern: synthetic-data methods may allow a lab to extract useful statistical patterns without directly retaining or reproducing the original material. These are important technical possibilities, but the source does not establish that Anthropic or OpenAI used a particular customer’s data in this way. They instead show why contractual language focused only on “training” may leave customers unsure about derived signals and model-development workflows.
The concern became more tangible after mathematician Tristan Buckmaster and co-author Levent Alpöge said they had used OpenAI’s Codex while working on the Navier–Stokes equations, then saw OpenAI present a breakthrough involving a similar solution path. OpenAI initially said it could not rule out a contribution from anonymized product data, before later stating that prompts from the relevant period could not have influenced the system. The incident did not prove misuse, but it demonstrated how quickly confidence can deteriorate when researchers cannot independently trace how their inputs were handled.
For AI product teams, the practical lesson is that a provider’s “no training on business data” promise is only one control among many. Teams deploying models for coding, security, research, or operations need to map the full data path: prompt storage, response logs, abuse monitoring, support access, metadata generation, retention periods, subcontractors, and model-improvement processes.
Builders may respond by routing sensitive work to self-hosted or internally controlled models such as Nvidia’s Nemotron, separating low-risk and high-risk workloads, or requiring customer-managed logging. Those approaches can reduce exposure, but they add costs in infrastructure, evaluation, model updates, and operational support. Smaller companies may have fewer alternatives and could be forced to accept provider policies that larger enterprises can negotiate.
The dispute also raises a competitive issue. Frontier labs want access to real-world usage signals to improve reliability and identify attacks, while enterprise buyers want those same interactions to remain isolated. Providers that offer precise retention controls, auditable telemetry policies, and clear boundaries around derived data may gain an advantage even when their models are not the strongest on benchmarks.
The immediate signal will be the scope of Anthropic’s customer-managed logging program: which customers qualify, whether it covers all Fable usage, and whether any residual metadata remains with Anthropic. Buyers should also watch for clearer definitions of “de-identified” data from OpenAI and other providers, including retention periods and permitted uses.
A second signal will be whether Nvidia, Booz Allen Hamilton, and Palantir restore broader Fable access after the policy changes. More customer disclosures, independent audits, or contractual templates could indicate that the market is moving from general assurances toward verifiable controls. Conversely, continued use of separate internal models for sensitive work would suggest that trust remains a deployment constraint rather than a procurement detail.
The Fable dispute is not evidence that AI labs are secretly training on every enterprise prompt. It is evidence that current policies often leave too much room for interpretation. “No training” and “zero data retention” address important risks, but they do not fully explain what happens to telemetry, abuse-detection signals, derived data, or temporary access by provider systems.
For AI buyers, trust is becoming an architecture and governance problem, not a marketing statement. The providers that make data flows observable, configurable, and contractually enforceable will be better positioned to win sensitive workloads. Until then, companies will continue separating convenient AI use from work they consider too valuable to place inside an opaque model service.