News analysis · Published

Anthropic's Enterprise Data Retention Plan: What Businesses Should Review

By the ELYMENT AI editorial team · Free to read

Reuters reported on 20 August 2026 that Anthropic plans to let enterprise customers keep retained Claude data inside their own cloud infrastructure. The reported change would alter where data is stored, not necessarily remove the 30-day safety-retention requirement for organisations that previously used zero-data-retention settings and want access to designated frontier models. Anthropic has not published a final replacement policy, so businesses should treat the report as a direction of travel and review product coverage, storage location, deletion rules, safety exceptions and contractual terms before relying on it.

A secure enterprise cloud vault holds encrypted AI data beside a 30-day retention timeline under the headline Claude Data May Stay in Your Cloud.
Original ELYMENT.AI editorial illustration.

What Anthropic is reported to be changing

According to Reuters, citing a person familiar with the matter, Anthropic plans to change its enterprise data-retention approach so customers can keep retained data in their own cloud infrastructure. Reuters reported that the company has coordinated with more than 100 customers, including Salesforce, and expects to introduce the new safety system later in 2026.

This is not yet a final public policy announcement from Anthropic. The distinction matters: a reported implementation plan can change before release, and customer contracts may differ. Businesses should wait for official documentation and written commercial terms before treating customer-cloud storage as available for a specific Claude product or model.

The current covered-model rule targets zero-retention users

Anthropic's current privacy documentation says organisations that previously used zero-data-retention settings must allow prompts and outputs to be retained for 30 days if they want access to designated covered models. The change took effect on 9 June 2026. Anthropic identifies Mythos-class models and future models that it designates as covered, while saying organisations already using standard retention and most other model use remain under existing terms.

Separate documentation says API inputs and outputs are generally deleted within 30 days, subject to longer service settings, usage-policy enforcement, legal requirements or contractual arrangements. Approved zero-data-retention agreements can cover eligible API and Claude Code Enterprise traffic, but Anthropic says classifier results may still be retained. These overlapping rules show why a single claim such as '30-day retention' does not describe every product, model or exception.

Storage location is not the same as data use

Keeping data in a customer's cloud could improve control over location, encryption keys, access logs and deletion evidence. It does not automatically answer whether Anthropic can access the data for safety investigations, whether derived signals are retained elsewhere, whether the data is used for model training or how backups and subprocessors are handled.

Procurement teams should separate five questions that are often compressed into one privacy discussion:

  • What is retained: prompts, outputs, tool calls, files, logs, classifier results or metadata?
  • Where is it stored: Anthropic infrastructure, a customer's cloud account or both?
  • How long is each category retained, and when does deletion complete across backups?
  • Who can access it, for which purposes, and under what audit controls?
  • Which product, model version, region and contractual schedule does the rule cover?

What enterprise Claude customers should do now

First, map every Claude deployment to its product surface and model. A Claude API integration, Claude for Enterprise workspace and Claude Code deployment may not share identical controls. Record whether the workflow handles personal, confidential, regulated or privileged information, then compare the applicable documentation with the data-processing agreement and order form.

Next, ask Anthropic or your reseller for written answers on customer-cloud availability, encryption-key ownership, safety-review access, deletion evidence, regional storage, subprocessors and incident notification. Existing Anthropic Enterprise plans also offer configurable retention for conversations and project data, but this should not be assumed to override the separate covered-model safety rule.

Treat the proposal as a governance signal, not a shortcut

The reported plan suggests frontier-model providers are looking for ways to preserve safety monitoring while giving enterprise customers more control over where sensitive data resides. That is commercially meaningful, but customer-managed storage does not remove the need for data minimisation, least-privilege access and human approval around consequential AI actions.

ELYMENT AI's guides to [agent security controls](/insights/frontier-ai-control-assessment-business-agent-security), [document intake automation](/insights/ai-document-intake-automation-workflow) and [approval workflows](/insights/ai-agent-approval-workflow-businesses) show how to translate vendor settings into operational safeguards. Use the reported change as a prompt to build a product-by-product data map, then update it only when Anthropic publishes final terms.

Sources

Continue learning

Related analysis

Frequently asked questions

What is Anthropic's current enterprise data retention policy?

Anthropic documents different rules by product and model. Organisations using zero-data-retention settings must allow 30-day safety retention to access designated covered models. API data is otherwise generally deleted within 30 days, subject to settings, enforcement, legal and contractual exceptions.

Has Anthropic officially launched customer-cloud data retention?

Not in the sources available on 21 August 2026. Reuters reported that Anthropic plans to introduce the approach later in 2026, citing a person familiar with the matter. Businesses should wait for official documentation and contract terms.

Does storing Claude data in a customer's cloud mean it cannot be accessed by Anthropic?

Not necessarily. Storage location does not by itself define access, safety-review rights, metadata handling, backup deletion or model-training use. Those controls must be confirmed in the applicable documentation and contract.

Explore ELYMENT AI