Anthropic Mandated 30-Day Retention To Catch Cyberattacks Using Its Models
Since June 2026, Anthropic has required 30 days of retention for certain user and enterprise data generated on its most capable models, a change from the shorter default most customers had grown used to. The stated purpose is narrow: detecting cyberattacks that use Claude, not general data collection. Anthropic and other frontier AI labs have documented cases of their models being used inside autonomous or semi-autonomous attack campaigns, covering reconnaissance, exploit code generation, and coordination steps that used to require a human operator at every stage. A rolling 30-day window gives Anthropic's security teams enough history to spot a pattern across sessions that a single interaction would never reveal, then act on it before an attack campaign completes. That is the tradeoff at the center of this story: better attack detection, in exchange for a longer window in which enterprise data sits somewhere outside the customer's own control.
More Than 100 Enterprise Customers Pushed Back, Salesforce Among Them
The mandatory retention window did not sit well with Anthropic's largest customers, and more than 100 enterprise accounts raised objections, with Salesforce named specifically among them. Their concern was not the 30 days as a security measure; it was the loss of control over where that data physically resided once it left their own systems and sat on Anthropic's infrastructure for a mandated period. For an EU-headquartered enterprise, or any company processing EU personal data under GDPR, that is not an abstract worry. Data protection teams need to be able to say, concretely, which jurisdiction a given dataset sits in, who can access it, and under what legal basis, and a vendor-held 30-day retention window on servers outside the customer's own cloud estate complicates every one of those answers. Enterprise procurement and legal teams pushed on this point hard enough, for long enough, that it became a design problem Anthropic had to solve rather than a complaint to manage.
Anthropic Is Building A Way To Hold That Data On The Customer's Own Cloud
Bloomberg reported on 20 August 2026 that Anthropic is now building a system that would let enterprise customers keep their mandatory 30-day retained data on their own cloud infrastructure, rather than on servers Anthropic operates. PYMNTS, MarketScreener and itnews.com.au have since carried or corroborated the Bloomberg report, and Anthropic has reportedly been coordinating directly with the 100-plus affected customers, Salesforce included, on how the system should work. As of this writing, Anthropic's own newsroom has not published anything about the change; the most recent post on anthropic.com/news, dated 14 August 2026, covers an unrelated topic, the Claude text watermark. This is sourced-report territory for now, not a vendor announcement, and the rollout is expected later in 2026.
| Date | Event | Detail |
|---|---|---|
| June 2026 | Retention mandate begins | 30-day retention required on Anthropic's most capable models, for cyberattack detection |
| Through mid-2026 | Enterprise pushback | 100+ customers, including Salesforce, object to loss of control over data location |
| 20 August 2026 | Bloomberg report | Anthropic building custody transfer to customer-owned cloud infrastructure; rollout later in 2026 |
The distinction in that table matters more than it looks: the mandate itself did not change, only where the resulting data is allowed to sit, and the next section explains why that difference is the whole point.
Moving Custody Is Not The Same As Opting Out Of The Rule
It would be easy to read this as Anthropic quietly backing down on retention, but that is not what is being built. The 30-day retention requirement exists because the security function needs a window of history to catch attack patterns, and nothing in the reported design removes that window or that function. What changes is custody: the data still gets retained for the same purpose, on the same schedule, but on infrastructure the enterprise customer controls rather than on Anthropic's own servers. Anthropic still needs enough visibility into that retained data to run its cyberattack detection, which makes this closer to a shared-responsibility model, similar in spirit to how cloud providers split security duties with their customers, than to a genuine opt-out. For an EU enterprise evaluating this, the honest framing is: the data stays under mandatory retention either way, and what is gained is jurisdiction and physical custody, not an exemption from the security policy itself.
What An EU Business On The Fence About Anthropic Should Do Now
For an EU or UK business owner currently weighing whether to adopt Anthropic's frontier models, the practical answer is not to default to a European-only vendor over this one issue alone. Data residency matters, but a defection decision made today, before the customer-cloud custody option ships, forecloses an option that directly answers the objection most owners actually have. The more useful next step is to ask your existing Anthropic account representative for the concrete rollout timeline for your region and contract tier, and to get in writing what infrastructure and certifications will qualify as an eligible customer cloud once the feature ships. If a business genuinely cannot tolerate any vendor-held retention today, on any infrastructure, that is a real constraint worth acting on now; but if the objection is specifically about not knowing where the data physically sits, Anthropic's own largest customers just got Anthropic to build a direct answer to that, and it is worth waiting a few months to use it rather than switching vendors over a problem that is already being solved.
Read next: Five AI Coding Agents Can Now Compete Inside Your Slack | The AI Store Manager That Fired a Human



