Anthropic just walked back one of its most unpopular policies. Since June, every business using its top Claude models, known as Fable and Mythos, had all of their conversations stored on Anthropic's own servers for 30 days. The goal was to catch sophisticated fraud and cyberattacks that unfold across many separate conversations, not just one message at a time.
Enterprises hated it. Companies in banking, healthcare, and law said handing a full month of their most sensitive conversations to an outside company was a dealbreaker. Microsoft reportedly restricted its own employees from using the top model while its legal team reviewed the terms.
The numbers back up the pushback. Spending data from expense-management firm Ramp showed the flagship model stuck at around 11 percent of Anthropic's enterprise revenue months after launch, while OpenAI's comparable flagship model pulled in close to double that share of OpenAI's business. Price played a role too, since the Anthropic model costs roughly twice as much per use, but data retention kept coming up as a top concern among security and procurement teams.
OpenAI saw the opening. Weeks earlier, it rolled out its own version of the same idea: keep zero data retention as the default, but add a monitoring layer that can still catch misuse without OpenAI storing everything. That put real pressure on Anthropic to catch up fast.
Enterprise Frontier Safeguards is that answer. Instead of Anthropic holding onto a company's data, the company now keeps it in its own cloud account, whether that is Amazon, Google, or Microsoft's cloud, under its own encryption keys. When Anthropic's automated systems flag something suspicious, like stolen login credentials or an AI agent behaving strangely, the alert goes straight to the customer's own security team, and no Anthropic employee ever reviews the flagged material.
This is a genuine reversal driven by money and trust, not a routine feature update. Anthropic built it with feedback from more than 100 companies, including a group of chief security officers representing the largest US banks. That level of direct customer input into a security system is unusual, and it shows how much leverage large regulated buyers now hold over AI vendors.
For any business running Claude through a cloud provider, or weighing whether to, this removes a real obstacle. Compliance teams no longer have to treat an AI vendor as an unapproved place to park customer data. That alone could unlock spending that was sitting on the sidelines while legal departments studied the old policy.
The bigger pattern matters beyond Anthropic. As AI models become capable enough to cause real damage if misused, from fraud to actual unauthorized access to computer systems, the companies selling them are being forced to prove they can catch bad behavior without demanding customers give up control of their own data. Expect every major AI vendor to offer some version of this within the next year, because the largest and most regulated customers are now the ones setting the terms.