Anthropic has officially updated its enterprise data policies, mandating a 30-day data retention period for prompts and outputs generated by its Claude Mythos 5 and Claude Fable 5 models. Effective as of June 9, 2026, the requirement applies across direct API integrations, Claude Code, and third-party cloud platforms, effectively ending zero data retention (ZDR) options for this model tier. Anthropic stated in its support documentation that temporary logging is essential for detecting advanced threat patterns that unfold across multiple requests.
Why Anthropic Is Requiring 30-Day Logs
According to Anthropic, Claude Mythos 5 represents a substantial jump in technical capabilities that introduces new dual-use risks. While Claude Fable 5 shares the same underlying architecture with added domain safeguards for biological and cyber risks, both models require broader visibility to prevent abuse. Anthropic noted that single-prompt evaluations are insufficient to detect complex, multi-stage attacks.
Key security threats driving the mandatory retention include:
- Best-of-N Jailbreaking: Automated attacks that send hundreds of slight prompt variations to uncover safety bypasses.
- State-Sponsored Espionage: Coordinated intelligence campaigns that are only identifiable when classifiers analyze queries in aggregate.
- Data Extortion Operations: Multi-session threat campaigns that require cross-request analysis to detect.
Impact on Enterprise Workspaces and Cloud Platforms
The policy change exclusively impacts organizations that previously maintained ZDR configurations in Claude Console, Claude Enterprise, or third-party cloud partners. Consumer plans—such as Claude Free, Pro, and Max—already include data retention and remain unaffected.
To access Mythos-class models, enterprise administrators must explicitly enable data retention within their respective deployment environments. On Amazon Bedrock and Google Cloud Agent Platform, retained logs remain within the customer's cloud provider environment. For Microsoft Azure Foundry users, accessing designated models requires setting up a dedicated Azure Subscription configured for data logging.
Safeguards and Enterprise Privacy Controls
Anthropic emphasized that retained data is protected by strict access controls. By default, no human personnel can read user prompts or outputs; human review is strictly restricted to automated safety flags handled by a small team of vetted reviewers. All access attempts are recorded in tamper-proof logs, and stored data is automatically purged after 30 days unless flagged for ongoing safety investigations or required by law.
However, this policy creates a clear trade-off for organizations operating under strict legal zero-retention mandates. Enterprise legal teams in regulated industries like finance or healthcare must now determine whether 30-day logging complies with their internal governance frameworks.