For enterprises in regulated industries, the data retention terms in AI contracts have become a decisive factor. Until recently, frontier model vendors often insisted on retaining customer prompts and outputs for up to 30 days to train safety systems and improve models. That stance clashed with the strict data governance requirements of banks, healthcare providers, and public sector bodies. Now, a major vendor has reversed course, offering customer-controlled storage as a baseline. This shift gives procurement and security teams a new benchmark for negotiating zero data retention and related controls.
What changed: Anthropic's Enterprise Frontier Safeguards
On 1 September 2026, Anthropic announced Enterprise Frontier Safeguards (EFS), a set of features that let enterprise customers store model activity data in cloud infrastructure they control. Under EFS, customers use their own encryption keys and audit logging, and automated misuse monitoring flags are routed to the customer rather than to Anthropic reviewers. This effectively ends the 30-day retention policy Anthropic had introduced with its Fable 5 model.
Anthropic said it designed EFS with input from more than 100 customers across financial services, healthcare, telecom, and the public sector, including CISOs from the largest US banks via the Analysis and Resilience Center for Systemic Risk. TechCrunch independently reported the shift as part of the Fable/Mythos 5.1 release, noting that the high-privacy option was previously unavailable for Fable models over security concerns.
Why zero data retention matters for regulated buyers
For a bank handling customer financial data or a hospital processing patient records, the default vendor retention policy is a deal-breaker. Regulatory frameworks such as GDPR, HIPAA, and financial conduct rules often require that personal data be processed only for specified purposes and deleted when no longer needed. When a vendor retains prompts and outputs for 30 days, the buyer loses control over that data. Even if the vendor promises not to use the data for training, the mere fact of storage creates legal and reputational risk.
Zero data retention clauses address this by requiring the vendor to delete all customer data immediately after processing, or to store it only in customer-controlled infrastructure. The latter approach, which Anthropic now offers, gives the buyer full control over encryption keys, access logs, and deletion schedules.
A negotiation framework for data control
Procurement, legal, and security teams should treat data control as a set of distinct clauses, not a single checkbox. The following framework applies regardless of vendor or model generation.
1. Data storage location and custody
Specify where model activity data is stored. The ideal is customer-controlled cloud infrastructure, such as the buyer's own AWS or Azure account, with the vendor having no independent copy. If that is not possible, require the vendor to store data in a region that meets your regulatory requirements and to provide contractual assurances on deletion.
2. Encryption key custody
Insist on customer-managed keys (CMK) for all stored data. This means the vendor cannot decrypt the data without your permission. In practice, this involves integrating with your existing key management system (KMS) and ensuring that the vendor's service supports envelope encryption.
3. Monitoring flag ownership
Automated misuse monitoring is standard in frontier AI services. The key question is who receives the flags. In Anthropic's EFS, flags are routed to the customer, not to Anthropic reviewers. This is crucial for regulated buyers because it prevents the vendor from seeing potentially sensitive prompts that trigger a flag. Negotiate that all monitoring flags are delivered to your security team, with the vendor only receiving aggregated, non-content metadata if required.
4. Human review control
Some vendors reserve the right to have human reviewers examine flagged content. For regulated buyers, this is often unacceptable. Ensure that any human review is performed by your own staff or by a third party you approve, and that the vendor commits to no human access to your data without your explicit consent.
5. Deletion and audit
Define clear deletion timeframes and audit mechanisms. The contract should require the vendor to delete all copies of your data within a specified period after processing, and to provide a certificate of deletion. You should also have the right to audit the vendor's compliance, either directly or through a third party.
Budgeting for the shift: cloud storage and egress costs
When data storage moves from vendor to buyer, the cost burden shifts too. Under a zero retention model with customer-controlled storage, you will pay for the cloud storage and network egress associated with model activity logs. These costs can be significant for high-volume deployments. For example, if your organisation processes millions of prompts per day, the storage and retrieval costs could add up to thousands of pounds per month.
Procurement teams should model these costs during the negotiation and compare them against the potential fines and reputational damage from a data breach. In many cases, the extra cost is justified. But it is worth negotiating volume discounts or asking the vendor to absorb egress costs for the first year as a concession.
Commercial impact: what this means for buyers and vendors
The availability of zero data retention options is likely to accelerate enterprise adoption of frontier AI in regulated industries. Banks, insurers, and healthcare providers that previously held back can now deploy these models with greater confidence. This could expand the total addressable market for AI vendors, but it also increases competitive pressure on vendors that do not offer similar controls.
For buyers, the shift creates leverage. If one major vendor offers customer-controlled storage as a baseline, others will need to follow suit to win regulated deals. Procurement teams should use this as a bargaining chip, asking for zero retention and key custody as standard terms, not premium add-ons.
Risks and unknowns
Despite the progress, uncertainties remain. First, the operational details of Anthropic's EFS are still emerging. It is unclear how the monitoring flags will be delivered and whether they will include full prompt content or only metadata. Second, the security implications of customer-controlled storage are not yet fully understood. If a customer's cloud environment is compromised, the vendor may not be able to detect or respond to misuse as quickly. Third, regulatory guidance on AI data retention is still evolving. The EU AI Act and other frameworks may impose new obligations that affect how these clauses are written.
Why it matters
For regulated enterprises, the ability to negotiate zero data retention is not a luxury; it is a prerequisite for safe adoption. The shift by Anthropic signals that vendors are listening to buyer demands. But the onus is on procurement teams to translate this into robust contracts that protect their organisations over the long term.
FY Outlook
Over the next 12 to 18 months, expect more vendors to offer customer-controlled storage and zero retention options. The competitive dynamic will force smaller vendors to match these terms or lose regulated deals. Buyers should also watch for standardisation efforts, such as model clauses from industry bodies, which could simplify negotiations. The key is to stay ahead of the curve by embedding data control principles into your AI procurement framework now.
Conclusion
Zero data retention is becoming a baseline expectation in enterprise AI contracts, particularly for regulated industries. Anthropic's Enterprise Frontier Safeguards provide a concrete example of how vendors can meet this demand. By using the negotiation framework above, procurement, legal, and security teams can secure the data control they need, while managing the associated costs and risks. The vendors that adapt will win the trust of regulated buyers; those that do not will find themselves locked out of the most valuable AI deals.
Source notes
- Anthropic's announcement of Enterprise Frontier Safeguards provides the primary evidence for the policy change and the features described. Available at: https://www.anthropic.com/news/enterprise-frontier-safeguards
- TechCrunch's independent report on the Fable/Mythos 5.1 release confirms the shift and notes the previous unavailability of high-privacy options for Fable models. Available at: https://techcrunch.com/2026/09/01/anthropics-new-fable-release-is-cheaper-less-restrictive/
Internal links
- For more on AI procurement trends, see our analysis of the AI economy: /ai-economy
- For guidance on building resilient business systems, visit /future-business



