Skip to content

Product1 publisher3 min readPublished

Anthropic keeps its most capable models outside its zero-data-retention offer

WIRED's guide to private AI use reports that OpenAI, Anthropic and Google sell no-retention terms only to paid enterprise and developer accounts, and that Anthropic's Mythos-class models are excluded from them.

The Product Desk · Product desk

Illustration accompanying Anthropic keeps its most capable models outside its zero-data-retention offer

What happened

  • WIRED reports that the major AI chatbots default to collecting and storing conversations, often with no restriction on sharing, sale, training reuse, or handover to litigants and police through a legal process.
  • Zero data retention, the term that obliges a provider to delete interaction records as soon as they are processed, is offered by OpenAI, Anthropic and Google on their enterprise versions.
  • Those no-retention terms are sold only with paid enterprise and developer accounts, and WIRED says they carry significant exceptions even there.
  • Anthropic does not offer zero data retention on its most sophisticated Mythos-class models, including Fable 5.1, citing misuse potential and what it calls autonomous misbehavior.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • constraint A no-retention contract only reaches the accounts it names, so the personal login someone uses because their enterprise seat was never provisioned sits outside every control the policy document claims.
  • decision Choosing Anthropic's top model class and choosing a retention posture are now one decision for the buyer, because the strictest deletion term and the most sophisticated models are not sold together.
  • cost Privacy here has a per-seat price: whoever is not on a paid enterprise or developer account is on the defaults, so the budget decides who is covered and who is not.
  • exposure An employee's health or finance questions typed into a default account are reachable by a civil litigant with a subpoena. The company's discovery risk then includes conversations nobody logged deliberately.

Matt Green, a privacy- and security-focused computer science professor at Johns Hopkins University, described to WIRED what a person is actually doing when they open a chatbot. "You have this intelligent thing staring back at you, and you're basically telling it, one question at a time, every possible thing there is to know about your life," he said. "You're giving it this huge profile on you." Moxie Marlinspike put the same point in categories: "People are integrating AI into their personal lives. They talk with it about their deepest insecurities, their finances, their health, their relationships," he said.

Three providers offer a contract that stops those records being kept: OpenAI, Anthropic and Google. All three sell it only with paid enterprise and developer accounts.

WIRED writes that with ChatGPT, Claude or Gemini it is "safest to start with a baseline expectation of approximately zero real privacy from anyone who is determined to access your conversation records and has a legal path to obtaining them." The guide lists who that includes: the owner of the service, advertisers and other partner companies, contractors who help fine-tune the systems, law enforcement, and anyone who subpoenas the records in a civil lawsuit.

Anthropic's exclusion comes with a stated reason. According to WIRED, the company points to the potential for misuse such as scamming or hacking, and to "autonomous misbehavior" like AI agents independently hacking targets to carry out an unwitting user's request, which the guide says has already happened in several cases.

Marlinspike built Signal in 2014, and the encrypted messenger is now used by well over a hundred million people. "Those same things I was concerned about with messaging are happening in the AI space, but several orders of magnitude more significantly," he said. Earlier this year he launched Confer, which uses cryptography to technically prevent its own server from logging or surveilling conversations. "Confer is designed to be a service where you can explore ideas without your own thoughts potentially conspiring against you someday," he wrote in a blog post introducing it.

WIRED describes the newer privacy-first tools as a growing crowd offering confusing assurances, and sorts them three ways: some advertise as a matter of policy that they never record conversations, some anonymize what they record, and a few build technical restrictions on their own access. Those are three different promises. A policy page can be rewritten by the vendor that wrote it. A contract term is enforceable against a named counterparty, within the accounts it names. A cryptographic restriction still holds when a subpoena arrives.

So the shortlist sorts on two questions, in that order. Which of the three kinds of promise does this tool make, and which model classes and account tiers does the promise actually cover. For a team that wants both the strictest retention term and Anthropic's most sophisticated models, WIRED's answer is that the combination is not on sale. The guide does not say what the enterprise tiers cost.

What to watch

  • Whether Anthropic extends zero data retention to its Mythos-class models, or publishes a fuller list of excluded models.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories