Build1 publisher2 min readPublished
Anthropic gates Mythos-class models behind a per-workspace retention switch
Zero-data-retention organizations that want Anthropic's covered models will have to turn retention on workspace by workspace from June 9, 2026, with prompts and outputs held for 30 days for misuse analysis.
The Engineer · Build desk

What happened
- Anthropic will retain prompts sent to covered models and the outputs they generate for 30 days, on every platform where those models are offered, to support its safety work.
- Retention is enabled per workspace in the developer console at Workspace > Manage > Privacy Controls, and an organization's other ZDR-enabled workspaces keep ZDR.
- Some ZDR organizations will receive notice that they are eligible to use Fable with ZDR under Anthropic's Enterprise Frontier Safeguards, and the retention policy does not apply to them.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision A team that wrote zero data retention into its control set has to pick, workspace by workspace, between that control and access to the covered models, and the deadline is June 9, 2026.
- constraint Tighter per-prompt filtering does not qualify a workspace for an exemption, because the detection Anthropic describes only works when many requests are held together and examined at once.
- capability An eligible organization can reach the same underlying weights through Fable and keep ZDR, so eligibility, which Anthropic decides, determines whether retention applies at all.
A safeguards classifier that sees one prompt at a time cannot see Best-of-N jailbreaking, which sends hundreds of slight variations of a prompt in the hope that one will work [9]. Anthropic says the bigger cases behave the same way: state-sponsored espionage and data extortion campaigns surface only when its classifiers zoom out across many requests [10]. Anthropic's stated position is that detecting these threats requires temporarily retaining prompts and outputs so they can be analyzed together, rather than one at a time [11].
A covered model stays out of reach in a zero-data-retention workspace until an administrator enables retention in the developer console, under Workspace > Manage > Privacy Controls, and the organization's other ZDR workspaces keep ZDR [16].
That changes what an auditor should ask for. An organization-level "we run ZDR" can stay true while individual workspaces are no longer covered by it, so the useful artifact after June 9, 2026 is a per-workspace retention list [3][16]. Anthropic also says organizations on ZDR today have to set up retention in order to use the designated models when they become available [19].
Claude Fable 5 and Fable 5.1 run the same underlying model as Claude Mythos 5 and Mythos 5.1, with additional safeguards, particularly in the cyber and bio domains [7]. Some ZDR organizations will get notice that they are eligible to use Fable with ZDR under Anthropic's Enterprise Frontier Safeguards [6]. The retention requirement therefore attaches to the safeguard configuration. The article does not say what makes an organization eligible for that notice [18].
On the read path, Anthropic says no personnel can read retained conversations by default, and that human review happens only through a controlled access path, for example when automated trust and safety systems flag content, and only by a small set of approved reviewers [12]. Every instance of access is written to a tamper-proof log that reviewers cannot suppress or modify [13]. Deletion at 30 days is automatic except where content has been flagged or Anthropic is legally required to keep it [14]. Customer-managed encryption keys and access transparency audit logs are available as options to eligible organizations [15].
Five distinct ZDR paths are named: Console workspaces, Claude Code with ZDR in Claude Enterprise, and ZDR access through AWS Bedrock, Google Cloud Agent Platform or Microsoft Foundry [17]. Consumer plans on Free, Pro and Max sit outside all of this because Anthropic already retains inputs and outputs on those surfaces [4]. Everything that is not a covered model stays under existing terms, and Anthropic says the designation will extend to future models it judges similarly or more capable [2][8].
What to watch
- Whether Anthropic publishes the criteria for the Fable-with-ZDR eligibility notice before June 9, 2026.
- Whether Bedrock, Google Cloud Agent Platform and Microsoft Foundry expose the same per-workspace retention control or route it through their own consoles.
- Which models after Mythos 5.1 get the covered designation, since Anthropic makes that call.