Skip to content

AI Governance

OpenAI and Anthropic are both rewriting their data retention rules this week. Here is what business owners should know before sending sensitive data to either one.

On August 19, 2026, OpenAI previewed a system called Private Safety Processing that is designed to flag misuse without ever giving OpenAI staff access to a customer's actual content. A day later, Bloomberg reported that Anthropic is preparing to change its own data retention policy so business customers can keep required data on their own cloud infrastructure instead of Anthropic's, a move Reuters corroborated the next day. The direct answer for a business owner: neither system is fully live yet, one of the two changes is still an unconfirmed report and not a vendor announcement, but the direction is clear. AI vendors are competing on where your data physically sits and who can look at it, and that is now a real question to ask before you sign up, not a detail to skip past in the terms.

By Fabio Rabelo · Founder, ATLACIS ·

What happened

On August 19, 2026, OpenAI published a blog post previewing "Private Safety Processing," a system built to catch patterns of misuse across related interactions, an attacker probing safeguards repeatedly, or an AI agent that keeps acting after being told to stop, without giving OpenAI personnel direct access to the content involved. Under the system, a customer's content either stays on infrastructure the customer controls, or sits on OpenAI's infrastructure encrypted with keys only the customer holds. If something looks risky, OpenAI says it receives only a narrow signal describing the type of activity, not the underlying content itself. The customer can choose to share the actual content to support a review or appeal. OpenAI says the system is being tested with early customers now, with a full rollout and a technical white paper planned for September 2026. TechCrunch's coverage the same day made the target of the move explicit: this "runs counter" to a policy Anthropic put in place in June 2026, which requires 30 days of retention for enterprise traffic on Anthropic's most capable models, reviewable by a small set of approved Anthropic staff through a logged access process. Anthropic introduced that policy to help guard against misuse of its models, including cyberattacks carried out with AI assistance. The next day, August 20, Bloomberg reported, citing a person familiar with the matter, that Anthropic is preparing its own change: business customers would still be required to retain 30 days of data, but would gain the option to store it on their own cloud infrastructure rather than Anthropic's. Bloomberg's source said the new system had been in development for months and Anthropic declined to comment on the record. On August 21, Reuters independently corroborated the report, adding that Anthropic has reportedly been working with more than 100 customers, naming Salesforce as one, to help build the new system, and confirming Bloomberg had broken the story first. One distinction matters here and the post is not going to blur it: OpenAI's move is a company announcement, on OpenAI's own blog, in OpenAI's own words. Anthropic's move is, as of this writing, a report based on unnamed sources at two respected wire services, not a confirmation from Anthropic itself. Both are worth understanding. They are not the same kind of fact.

Why it matters for business owners

Most owners never read an AI vendor's data retention terms closely, because the product decision usually gets made on price, features, and whether the tool solves the immediate problem. This week is a reminder that retention terms are not a fixed background detail. They move, they differ meaningfully between vendors doing the exact same job, and right now they are moving because vendors are competing on them directly. That matters because retention policy answers a concrete question: if your business sends customer records, internal documents, financial data, or proprietary code to an AI tool, where does that content sit afterward, for how long, and who, if anyone, can look at it. Two vendors offering what looks like the same chatbot or coding assistant can have very different answers to that question, and the answer can change without your business doing anything.

What owners should not misunderstand

This is not a story about one vendor being reckless and another being careful. Anthropic's original 30-day retention policy exists for a stated defensive reason: giving the company a window to catch misuse of its own models, including AI-assisted attacks. Retaining data is not automatically the wrong choice. It is a tradeoff between two real risks, misuse going undetected versus customer content sitting somewhere a vendor can access it, and different vendors are weighing that tradeoff differently in public, in real time. It is also not evidence that OpenAI's system is already protecting your data today. Private Safety Processing is in early testing with a limited set of customers, with a full rollout not expected until September 2026. And it is not evidence that Anthropic has actually changed anything yet. Reuters and Bloomberg's reporting rests on unnamed sources, and Anthropic has not made its own announcement or confirmed a timeline as of this writing. A business owner reading headlines this week should come away knowing the industry is moving in this direction, not that either specific system is available to buy right now.

The operational lesson

The lesson is not to pick a side between OpenAI and Anthropic based on this week's headlines. It is that data retention terms are a live, negotiable, competitive variable, not a fixed fact about a vendor you check once and forget. A vendor's retention policy today may not be its policy in six months, in either direction, tighter or looser, and the businesses actually coordinating with a vendor on a system change, the way Anthropic is reportedly doing with over 100 customers, are the ones getting a say in how it lands for their use case. The more durable question underneath all of this is not which vendor's marketing sounds more private. It is what data your business is already sending to any AI tool, sanctioned or not, and whether anyone has actually read that vendor's current retention terms rather than assumed them. Retention policy is one piece of a broader mapping exercise: what data goes in, where it sits, who can see it, and what happens to it after the request is done.

What a serious business should do next

Pull the actual current data retention and data usage terms for every AI vendor your business uses today, not the vendor's marketing page, the terms document itself. Note the retention window, whether content can be reviewed by vendor staff and under what process, and whether training on customer data requires an explicit opt-in. Before adopting Private Safety Processing or any equivalent system once it is generally available, ask the vendor directly what "early customer" access looks like, when the general rollout date is confirmed, and what the technical white paper actually specifies once it exists. A preview blog post is not a signed commitment. If your business is currently sending sensitive customer, financial, or proprietary data to Anthropic's covered models, know that the 30-day retention on Anthropic's own infrastructure is the current, confirmed policy, not the reported change. Do not act as though the reported self-hosted option already exists. If it matters enough to your risk tolerance, ask Anthropic directly what its current retention terms are and whether it will confirm a timeline for any change. More broadly, treat vendor data retention policy as a standing item to revisit, not a one-time check. The vendors moving fastest on this right now are the ones with the most enterprise customers asking hard questions about it. Being one of the businesses asking is how you end up with terms that fit your actual risk tolerance instead of terms you never noticed you accepted.

The Atlacis view

A vendor's data retention policy is not fine print. It is one of the clearest signals of how much control a business actually keeps over its own data once it starts using an AI tool. Atlacis helps owners slow down, read the terms that actually apply to their business rather than the ones a headline implies, and decide where private or on-premise deployment is worth the added cost and effort, instead of assuming every AI vendor handles data the same way.

The short version

  • On August 19, 2026, OpenAI previewed Private Safety Processing, a system designed to flag AI misuse patterns without giving OpenAI staff access to customer content. It is in early testing, with full rollout planned for September 2026.
  • OpenAI's move explicitly targets Anthropic's June 2026 policy, which requires 30 days of enterprise data retention on Anthropic's own infrastructure for its most capable models.
  • On August 20 and 21, 2026, Bloomberg and Reuters separately reported, citing unnamed sources, that Anthropic is preparing to let business customers keep that required retained data on their own cloud infrastructure instead of Anthropic's.
  • Anthropic has not confirmed this change publicly. It is a reported plan, not a vendor announcement, and the reported detail that Salesforce is among more than 100 coordinating customers comes from a single unnamed source.
  • Two vendors offering similar AI tools can have materially different data retention terms, and those terms are moving right now as vendors compete on them.
  • Pull the current, actual retention terms for every AI vendor your business uses today, and revisit them periodically rather than assuming a policy read once still applies.
Tags:AI governancedata retentiondata privacyvendor dependencyprivate AIAI buying decisionsbusiness AIAI vendor trust
FAQ

Common questions

Is OpenAI's Private Safety Processing available to use right now?
Not generally. As of this writing it is in early testing with a limited set of customers. OpenAI has said a full rollout and technical white paper are planned for September 2026, so treat it as a preview, not a live option to build a decision around yet.
Has Anthropic actually changed its data retention policy?
Not as of this writing. Bloomberg and Reuters reported the planned change citing unnamed sources, and Anthropic declined to comment to Bloomberg. Anthropic's confirmed, current policy still requires 30 days of retention on Anthropic's own infrastructure for its covered models. Do not assume the reported self-hosted option is already available.
What should I actually check before sending sensitive data to an AI vendor?
Read the vendor's current data retention and usage terms directly, not a summary. Confirm the retention window, whether staff can review your content and under what process, and whether training on your data requires an explicit opt-in. Revisit those terms periodically, since they can change.
Keep reading

More from the blog

Google's AI agents found 100 critical vulnerabilities in stolen code in two days. Here is what business owners should know before trusting an 'AI-verified' security claim.

Google's Mandiant threat intelligence team disclosed an AI agent pipeline, built over 10 months on a decade of internal security work, that found more than 100 confirmed critical vulnerabilities in stolen corporate source code in two days. Every single finding still passed through a human before it counted. Here is what that detail means for how you evaluate any vendor's AI security claims.

Researchers tricked an AI chatbot into stealing chat data by hiding instructions inside encryption. Here is what business owners should know before trusting a vendor's AI guardrails.

Security researchers at Adversa AI showed how encrypting a malicious instruction lets it slip past Grok's guardrails entirely, then steal a user's name, location, and full chat history with no warning. The same instruction in plain text gets blocked. Here is the guardrail gap that exposes, and what it means for any business letting an AI agent browse, run code, or handle private data.

IBM surveyed 1,000 executives on AI vendor risk. 91 percent do not know what they depend on. Here is what that means for your business.

A June 2026 IBM Institute for Business Value study found that 91 percent of senior executives do not fully understand their AI dependencies. The research puts a profit number on that gap. The lesson is not to buy more AI. It is to understand what you already depend on.

Make better AI decisions, starting with one call.

Book a free AI Fit Call. We will tell you what to use, what to avoid, and where to start. No jargon, no pressure.