Anthropic's Mandatory Logging Policy Sparks Enterprise Backlash Over Data Retention
Anthropic, a leading AI lab, has announced a new policy for its frontier AI models that is causing friction among enterprise customers. The company will now log all prompts and outputs from its most powerful models, including Claude Fable 5 and Claude Mythos 5, for 30 days. This move voids any prior zero-data-retention agreements between Anthropic and its clients.
The policy change affects users across first-party and third-party platforms, with no exceptions or opt-outs. The retained data will be used exclusively for safety monitoring to detect novel attacks and vulnerabilities in the models. After 30 days, the logged data will be automatically deleted, unless it is flagged for a safety investigation or retained for legal reasons.
The move has been met with resistance from some of Anthropic's biggest clients, including Microsoft. The tech giant reportedly restricted the use of Fable 5 within certain internal deployments due to policy collisions. Other enterprise customers have expressed concerns about the mandatory logging requirement and its impact on their GDPR obligations and data governance frameworks.
Anthropic has argued that the new policy is necessary to prevent multi-request attacks against its most powerful models. The company claims that bad actors are becoming more sophisticated in spreading malicious prompts across multiple interactions, making it harder to detect abuse in real-time.