Anthropic's 30-day Mythos-class retention rule is staying, while enterprises may soon hold the data themselves on their own cloud infrastructure.
They are saying the rule exists because some attacks only become visible across multiple requests, so covered-model prompts and outputs are retained for 30 days.
So the proposed mechanism is that instead of Anthropic storing the 30-day logs, the enterprise would keep them inside its own AWS/GCP environment under its own access controls. Anthropic says it would retain no copy;
Boris Cherny, head of Claude Code, clarified that they have been building the system with customers for some time and plans to ship it this fall.
Anthropic's current documentation already says retained covered-model data stays inside AWS or GCP when customers use Bedrock or Google Cloud Agent Platform.
Direct Claude Platform retention, however, is still handled by Anthropic under today's rules.
The fall rollout therefore appears to broaden customer-controlled custody across Anthropic's enterprise access paths, rather than invent the pattern from scratch.
OpenAI, on the other hand, yesterday announced, that they are taking a different technical route with Private Safety Processing, which it says preserves Zero Data Retention while detecting abuse across related interactions.