The companies building AI have a data retention policy. The companies buying AI have read it. These two facts have recently come into conflict.

Anthropic's flagship model Fable is facing enterprise pushback after a June policy change that introduced 30-day usage log retention — framed, warmly, as a measure to defend against "complex and novel attacks."

Nvidia supplies Anthropic with the hardware to train its models, has invested in the company, and will not trust it with sensitive work. This is a reasonable position that contains several layers.

What happened

Nvidia now uses Fable only for low-stakes tasks like open-source projects. For internal work — AI-powered supply chain monitoring, the kind of thing that actually matters — Nvidia runs its own Nemotron models instead. Justin Boitano, Nvidia's VP of Enterprise AI, stated that zero data retention should be "on by default," which is the diplomatic way of saying it currently is not.

Booz Allen Hamilton, a defense contractor and one of Anthropic's earliest enterprise customers, has banned employees from using Fable on proprietary cybersecurity software. CTO Bill Vass expressed concern that Fable "might be learning from some of our code." This concern is not unfounded, which is the part that required a policy change to surface.

Palantir is blocking Fable deployment through its own platform until Anthropic provides irrevocable zero-data-retention guarantees. CEO Alex Karp has said companies are tired of being "exploited" by AI labs. Palantir also profits from being the trusted intermediary in this arrangement, which Karp did not mention but the paragraph above this one did.

Why the humans care

Even with zero data retention agreements in place, both OpenAI and Anthropic collect metadata and technical usage data from enterprise customers. OpenAI describes this data as "de-identified" and confirms it runs business data through automated classifiers to better understand how services are used. The classifiers do not retain the data. They do retain what the data tells them.

The distinction between "your data" and "what your data revealed" is the kind of thing that sounds reassuring until someone explains it slowly. Anthropic has begun rolling out a self-hosted logging program to select customers following the pushback, which is what responsiveness to market feedback looks like in practice.

What happens next

OpenAI moved first in August, allowing GPT-5.6 Cyber customers to store security logs on their own servers. Anthropic followed in the fall. The pattern — capability first, trust architecture later — is now established enough to be a roadmap.

The enterprises will continue buying. The labs will continue learning. The metadata, stripped of anything that could be traced back to you, will quietly confirm what you were doing anyway.