AI 科技

Anthropic and AWS Publish Different Rules for Fable 5

Anthropic's documentation says Claude Fable 5 and Claude Mythos 5 are Covered Models: zero data retention is 'not available for either model.' AWS's Bedrock documentation says eligible customers may request full ZDR through their account team instead. Anthropic paired the June 9, 2026 launch with a rule requiring 30-day retention wherever zero retention had been configured. OpenAI's August 19 zero-retention announcement never mentions Eyes Off or Safety Retention, two clauses that already let it pull customers out of zero retention. Bloomberg reports, citing an unnamed source, that Anthropic expects to let enterprise customers keep that data on their own cloud infrastructure instead — unconfirmed.

2026.08.22 · 作者 dvdmaru · 約 9 分鐘 · 3,323 字

本文另有中文版:Anthropic 說 Fable 5 不能零保留,AWS 說有條件可申請

Call the Claude Fable 5 API from a workspace still configured for zero data retention, and the model does not answer. What comes back instead is an error: type invalid_request_error, message “In order to access this model, your organization or workspace must have data retention enabled.”

That is Anthropic’s own error text, returned by the API itself.

Not a line from a press release.

Anthropic launched Claude Fable 5 and Claude Mythos 5 on June 9, 2026, and paired the launch with a new retention rule. OpenAI published an announcement titled “Offering Zero Data Retention for frontier models” on August 19. Bloomberg reported on August 20 that Anthropic expects to roll out a system later this year letting enterprise customers keep their retained data on their own cloud infrastructure. Two official documents and one unconfirmed report describe three different arrangements for the same underlying problem.

Safety monitoring on frontier models has to touch content somewhere.

Set side by side, the two companies are answering the same constraint. They have just written the answer down in different places. Anthropic wrote it into an access condition: use the strongest model, and a mismatched retention setting gets you a 400 error before you get an answer. OpenAI kept its zero-retention promise standing, and put the exception in a separate document instead, one its own August 19 post never mentions by name.

The rule written into an error message

Fable 5 and Mythos 5 launched the same day, but only one of them is something an enterprise customer can actually reach. Mythos 5 is invitation-only, limited to approved customers inside something Anthropic calls Project Glasswing, built for defensive cybersecurity work, with no self-serve sign-up. Fable 5 is the one that went generally available on the Claude API, Amazon Bedrock, Claude Platform on AWS, Google Cloud, and Microsoft Foundry, all on June 9.

The policy itself: all traffic to Mythos-class models, across both first-party and third-party surfaces, gets 30 days of retention. That data isn’t used to train new Claude models, and isn’t used for anything outside safety work. Anthropic also says it now logs every instance of human access to the data.

The announcement leaves itself room, though. Deletion after 30 days happens “in almost all cases,” not in every case — an exception the company built into its own language and did not explain further.

Who this actually touches is buried in one qualifying sentence. It applies only to organizations that had already configured zero data retention: a Console workspace with ZDR set, Claude Code used inside Claude Enterprise with ZDR configured, or Claude reached through AWS Bedrock, Google Cloud’s Agent Platform, or Microsoft Foundry with ZDR enabled. Consumer plans are untouched. For every organization outside that list, nothing changes, because their data was already being retained under existing terms.

Fable 5 and Mythos 5 are designated Covered Models, and for a Covered Model, zero retention simply is not an option. Anthropic’s documentation states plainly that ZDR is “not available for either model.” An organization whose retention configuration does not meet the requirement gets the 400 error from the top of this article.

Access to the strongest available model comes with a condition. That condition is written into the error message itself.

More than one thing called “30 days”

The phrase “30 days” shows up again and again in this story, and it does not mean the same thing twice. Anthropic’s own wording for Covered Models is a fixed commitment, “we will require 30-day retention,” not a ceiling. Elsewhere in the same ecosystem, the number is a cap instead.

AWS’s Bedrock documentation, describing that identical Fable 5 and Mythos 5 traffic, says user prompts and completions “are shared with Anthropic and retained for up to 30 days.” Fixed value and ceiling are not the same claim, even when the digits match.

There’s a version that isn’t from Anthropic’s own documentation at all. Speaking to The Register, Anthropic said, “we automatically delete inputs and outputs on our backend within 30 days of receipt or generation.” That is Anthropic talking to a reporter, not language pulled from a policy page, and this piece did not find a first-party document making the identical claim.

Consumer accounts have their own version too. Anthropic’s privacy materials describe how deleted conversations are handled: “Deleted from our back-end storage systems within 30 days.” OpenAI has its own default, unrelated to any of the above: by default, its API generates abuse-monitoring logs for all traffic and retains them “for up to 30 days.”

Different documents, different mechanisms, one recurring number, and none of them substitute for each other.

Where the retained data actually sits

The 30-day requirement for Covered Models applies wherever those models are offered, but which company holds the data depends on the channel. Through the Claude API, including Claude Platform on AWS, Anthropic’s documentation says Anthropic itself handles the retained data. Through Amazon Bedrock and Google Cloud’s Agent Platform, the same documentation says retained data “stays within your cloud provider’s environment,” the cloud vendor’s environment.

AWS’s own Bedrock documentation describes that same arrangement differently. Fable 5 and Mythos 5 are models that “require provider data sharing” on Bedrock. A customer has to explicitly set their retention mode to provider_data_share before either model will even respond; leave it at none or default, and the model shows up as unavailable.

Under that mode, the documentation continues, “user prompts and completions are shared with Anthropic and retained for up to 30 days for trust and safety purposes.” The data, on this account, is not staying in the cloud provider’s environment alone — it is going to Anthropic.

Anthropic’s documentation says retained data stays with the cloud provider. AWS’s documentation, describing the same models on the same platform, says the data is shared with Anthropic. Those two statements do not match.

Anthropic published its version on July 9, 2026, more than a month before Bloomberg’s report — and the disagreement sits exactly where it matters most: who actually holds the data.

There’s a second mismatch in the same pair of documents, this time about whether zero retention is available at all. Anthropic’s documentation is unambiguous: Fable 5 and Mythos 5 are Covered Models, and “ZDR is therefore not available for either model.” A separate AWS document, covering abuse detection on Bedrock, says something else: “For these models, eligible customers may request full ZDR through their AWS account team.” Not any customer, and not automatically. Eligible customers, through a request.

The same AWS document also attributes the underlying data-sharing requirement to the model’s maker: “In order to use Claude Fable 5, as required by Anthropic, you must opt in to sharing retained traffic with Anthropic.”

That same passage adds one more detail that lines up with Anthropic’s own language about logging human access: the data is retained, AWS writes, “for abuse detection and potential human review.” Anthropic’s phrasing is close, logging “all human access to the data.” Both sides describe the possibility of a person looking at retained content. Neither one says every piece of retained content gets read by a person.

A reported system that isn’t final yet

Bloomberg’s Rachel Metz reported on August 20 that Anthropic expects to roll out a new safety system later this year, one that would still require enterprise customers to retain data for 30 days, but with the added option of keeping it on their own cloud infrastructure instead of Anthropic’s. The verb is still require.

In Bloomberg’s account, the 30-day period itself is not the thing changing; where it sits is.

The reporting rests on a single unnamed source, described only as speaking on condition of anonymity because the information isn’t public. Anthropic declined to comment, and there is no public statement from the company confirming or denying any of it.

The same source said the system has been in development for months and that Anthropic was already coordinating with more than 100 customers in highly regulated industries to build the option. The source also said that Anthropic began working on the system before users started criticizing the existing policy.

What OpenAI’s August 19 announcement leaves out

OpenAI’s promise is stated plainly: “OpenAI does not retain their prompts or model responses after a request is processed,” extended to “eligible API customers,” eligible, not automatic. The default state is different. By default, per OpenAI’s own documentation, “abuse monitoring logs are generated for all API feature usage and retained for up to 30 days”; getting excluded from that requires applying for, and being approved for, Zero Data Retention or Modified Abuse Monitoring.

The August 19 announcement itself uses the verb “continue to offer,” describing something already in place, not a new policy. It covers the API only. ChatGPT Enterprise, Business, and Edu don’t appear in it.

The new piece is Private Safety Processing, described as “currently being tested with early customers,” with a wider rollout and a technical white paper both planned for September. The design: customer content stays either on infrastructure the customer controls, or on OpenAI’s infrastructure encrypted with keys the customer controls and OpenAI does not hold. When risk is flagged, OpenAI says it receives only “a narrowly defined signal indicating the type of activity involved,” not the underlying content, even once something has been flagged.

The one exception the announcement names outright is CSAM. Images flagged for potential child sexual abuse material are retained for review and reporting, in every deployment, zero retention included.

What the announcement doesn’t name is an older, broader exception that already exists on a separate OpenAI page. That page describes two clauses, Eyes Off and Safety Retention, both available only to customers already approved for Zero Data Retention or Modified Abuse Monitoring. Under Safety Retention, OpenAI can pull a specific customer’s specific model out of ZDR or MAM eligibility “if reasonably necessary to investigate or prevent severe risk activity.” Once that happens, content the classifiers flag as a possible policy violation can be retained and human-reviewed.

Under Eyes Off, the same kind of eligibility loss happens, but the retained content goes into abuse-monitoring logs and stays out of human review unless the law requires otherwise. The August 19 announcement never uses either phrase. How the new preview relates to those two existing clauses is something the announcement does not say. It does not claim to replace them, and it does not mention them at all.

One line in the announcement reads like it could be describing Anthropic’s policy, without saying so: “Some recent frontier-model deployments have required customers to allow their AI provider to retain sensitive content for safety monitoring. For many organizations, such requirements conflict with their security obligations or commitments to the people they serve.” Across that post and three other OpenAI privacy pages, the word “Anthropic” does not appear once.

Read that sentence next to Anthropic’s own June 9 policy, and the description tracks closely. OpenAI never makes that connection itself.

What “zero retention” covers, table by table

A single “zero retention: yes or no” column hides more than it shows. Whether data trains future models and how long it sits somewhere are two separate questions, and a vendor’s answer to one says nothing about its answer to the other.

The table below splits retention into five columns: whether data is used for training, the default retention for ordinary inference, retention tied specifically to a safety or abuse-review exception, and where the data physically sits and who can reach it. A cell with no public number reads “Not specified.” It isn’t left blank, and it doesn’t borrow a figure from a different row.

Tier / contract typeUsed for training?Default retention (inference)Safety / abuse-review exceptionData residency & access
Anthropic Covered Models (Fable 5 / Mythos 5), ZDR-configured orgsNoPer Anthropic’s documentation: zero is not available; requires 30-day retention. AWS’s documentation separately says eligible customers may request full ZDR — see above.Same 30 days as the previous column, for safety review only; Anthropic’s documentation describes no self-service waiver.Claude API / Claude Platform on AWS: handled by Anthropic. Google Cloud: stays within the cloud provider’s environment (per Anthropic). Bedrock: Anthropic’s and AWS’s documentation describe this differently — see above.
OpenAI API, ZDR not approved (default)No, unless the customer opts inAbuse-monitoring logs, up to 30 days, generated for all trafficDefault state already carries abuse-monitoring logging; Eyes Off / Safety Retention don’t apply — those require prior ZDR/MAM approvalNot specified
OpenAI API, ZDR approvedNo, unless the customer opts inZero, but requires prior approval and additional conditionsCan lose ZDR/MAM eligibility under Safety Retention or Eyes Off. Safety Retention: flagged content retained and human-reviewed. Eyes Off: flagged content goes to abuse logs only, excluded from human review unless legally required.Existing ZDR deployments: infrastructure the customer controls. Private Safety Processing (currently tested only with early customers): may sit on OpenAI’s infrastructure, encrypted with customer-controlled keys.
Google Gemini API, paid tierNoNo single stated default; feature-level defaults vary — Grounding with Search and Grounding with Maps: 30 days each, cannot be disabled; Interactions API: enables state storage by default, disabled by setting store to false; Live API: if a session handle is generated, conversation state held up to 24 hoursNot specifiedNot specified
Google, standard Cloud Platform ToSNoNot specified90 days, trigger-based — logged only if automated classifiers flag suspicious activity, not by default; opt-out available; applies only to customers governed by the standard Google Cloud Platform Terms of ServiceNot specified
Google, Master AgreementNoNot specifiedExempt by default: Master Agreement customers are outside the scope of this abuse-monitoring prompt loggingNot specified
Azure OpenAI / FoundryNoModels are described as stateless: “no prompts or completions are stored in the model.” Certain stateful features carry their own separate storage rules.Flagged content is stored and may be reviewed by authorized personnel; customers meeting Limited Access eligibility can apply for modified abuse monitoring, after which human review does not occur; day count not specifiedFor certain stateful features, data at rest is stored within the customer’s own Azure tenant
Amazon BedrockNoFour modes exist — inherit, default, none, provider_data_share. New accounts and projects default to inherit. Only none is zero retention, and it must be set explicitly; an organization can lock every account to none with IAM or an SCP. Fable 5 and Mythos 5 only support provider_data_share, so retention stays at up to 30 days regardless.Not specifiedA standard Model Deployment Account is operated by AWS, and the model’s maker has no access to it. The provider_data_share exception — which covers Fable 5 and Mythos 5 — does share data with the model’s maker.

Every row’s training-use answer is no. The retention-length answers are almost all different from each other. The one repeat, appearing twice, both times reads Not specified.

Bedrock’s account-and-project-level API, lockable at the organization level with IAM or an SCP, is the closest thing in this table to a programmable, organization-enforced control over retention. Google has a programmable option of its own: setting the store parameter to false on the Interactions API, though that is narrower than an organization-wide lock. This doesn’t mean Azure or Google lack any other self-service or programmable controls. No equivalent to Bedrock’s organization-level IAM or SCP enforcement appears in either company’s public documentation.

Bedrock’s own documentation adds a caution that keeps setting store=false and getting guaranteed zero retention from being the same claim: “Setting store=false does not guarantee zero data retention. Some models may still retain data for safety review even when store=false — in this case, data is retained but is not retrievable by the customer through GET /v1/responses/{id}. If you require guaranteed zero retention, set data_retention_mode to none.”

A parameter that looks like an off switch can still leave data sitting somewhere the customer who set it can’t reach. The only setting AWS calls guaranteed is a different one.

A vendor’s zero retention isn’t your company’s zero obligation

A vendor’s retention promise covers the vendor’s own systems. It says nothing about what a customer using that vendor is separately required to keep. Article 19 of the EU AI Act requires providers of high-risk AI systems to keep the logs their systems automatically generate, for a period matching the system’s intended purpose, “of at least six months,” unless EU or national law says otherwise.

If a company’s own high-risk AI system makes that company a provider under the Act, the logs it controls can carry that six-month floor. That’s a separate question from whatever its cloud vendor promises to retain. This obligation sits alongside, not inside, the Article 50 transparency rules that took effect on August 2 (in Chinese); the two articles impose different duties.

No named court order or regulatory action has surfaced, as of this writing, requiring Azure OpenAI, Google Vertex AI, or Amazon Bedrock to retain enterprise-tenant customer data past its normal deletion window. That absence is a gap in what’s public, not proof there’s no risk.

OpenAI’s own history shows the shape that risk can take, and where its limits sit. A court order tied to New York Times litigation once required OpenAI to preserve certain consumer and API content indefinitely; that obligation ended on September 26, 2025. But the order explicitly excluded the customers this article is about: “If you are a business customer that uses our Zero Data Retention (ZDR) API, we never retain the prompts you send or the answers we return. Because it is not stored, this court order doesn’t affect that data.” Enterprise and Edu plans were excluded the same way.

One legal order once reached outside a zero-retention agreement, and it stopped precisely at its edge.

Two official announcements and one unconfirmed report, laid side by side, don’t answer which company protects privacy better. They point toward a narrower, more useful set of questions. When does a vendor’s safety team actually look at content, and what does that process require: approval, a log, a notice? Which document is that written in, and would you find out if it changed? And separately from any of that: does your own organization carry a retention duty that exists whether or not the vendor keeps anything at all?

A separate piece on this site compares Anthropic and OpenAI on different ground: security-evaluation incidents and an executive-order deadline that expired August 1, not retention terms.

Sources

Primary documents: Anthropic, Claude Fable 5 and Claude Mythos 5 (June 9, 2026); Data retention practices for Covered Models (July 9, 2026); Models overview; API and data retention; Privacy Center retention page. OpenAI, Offering Zero Data Retention for frontier models (August 19, 2026); Data controls in the OpenAI platform; Enterprise privacy at OpenAI (updated January 8, 2026); How we’re responding to The New York Times’ data demands (updated October 22, 2025). European Commission AI Act Service Desk, Article 19. Amazon Bedrock, Google Vertex AI / Gemini API, and Microsoft Azure official data retention and data protection documentation.

Reporting: Bloomberg (Rachel Metz, relayed via The Star), Reuters (relayed via Yahoo Finance), and The Register (Thomas Claburn) — all August 20, 2026.