Anthropic's Engineers Just Announced a Major Privacy Shift—on X. That's the Problem.
Anthropic's engineers announced a major enterprise privacy shift on X—but the company itself has published nothing. If you're evaluating Claude for regulated workloads, here's why you shouldn't let a tweet dictate your contract terms.

Boris Cherny runs Claude Code at Anthropic. On August 20, he hopped on X and dropped some news: soon, enterprise customers will own and control their own data infrastructure. Anthropic will retain nothing. "It's coming this fall," he wrote. His colleague Sholto Douglas jumped in to explain the mechanics: your data sits in your environment, with monitoring handled by automated systems Anthropic provides.
That's a big deal—if it happens.
Here's the thing. None of this is official yet. Anthropic itself has published exactly zero about it. No press release. No blog post. No updated policy page. Just two engineers tweeting and some unnamed sources talking to Bloomberg and Reuters.
The Old Rules Still Apply
Back in June, Anthropic set a clear policy: all traffic on its Mythos-class models gets 30-day retention. Your data sits with your cloud provider (AWS or Google), but under Anthropic's rules. Flagged data? Anthropic keeps it. The only binding document on their website—the covered-models page dated July 9—still says exactly that.
So if you're a CISO or procurement lead evaluating Claude for regulated workloads, here's your reality check: tweets are not contract exhibits.
OpenAI Did It the Boring Way
Compare this to OpenAI. On August 19, they published an actual post—on the record, with named customers. Glean's CISO, Sunil Agrawal, went on record saying, "OpenAI's no-training commitment and ZDR give Glean confidence to build with OpenAI." Boring? Maybe. But if you're the person signing the check, boring is exactly what you want.
The irony? Both companies seem to have landed on the same technical solution. Pure zero retention kills your safety monitoring along with the data. Customer-owned storage with vendor-supplied monitoring keeps the safeguards running while removing Anthropic from custody. Douglas even acknowledged the convergence: "It looks like we've arrived at both the same conclusion—and the same solution."The difference? OpenAI wrote theirs down.
What to Actually Do
If you're negotiating with Anthropic right now, stop pricing this "fall" architecture into any deal you sign today. That timeline comes from one engineer's tweet. The "100+ customers" figure? Two unnamed sources and another tweet. Salesforce's involvement? Zero on-the-record confirmation.
As of August 25, Anthropic's privacy page, help center, newsroom, release notes, and Trust Center all still reflect the July 9 policy. Nothing has moved.
So do this instead: email your Anthropic account team. Ask for customer-owned data architecture as a written contract term. Until that document lands, negotiate against what's actually published—the July 9 page, the only thing Anthropic has put its name to.
The design is smart. The delivery? That's a trust exercise.
Source: privacy.claude.com