Claude adds watermarks while asking enterprises to retain data for 30 days: Anthropic reopens the control debate
Reuters reports Anthropic plans to let enterprise customers keep retained data in their own cloud while still requiring 30 days of retention; this is not a launched zero-retention policy, and scope and timing remain pending.
The bottom line
Claude just caused a round of unsubscription controversy for "adding text watermarks", and Anthropic took out the control of corporate chat data and renegotiated it.
Reuters reported on August 21 that Anthropic plans to adjust its enterprise data retention plan: commercial customers will still need to retain relevant data for 30 days, but can choose to put the data in their own cloud environment; the new security system is expected to be launched later this year.
This isn’t “Anthropic is going to permanently archive all enterprise chats” or an official product announcement. A more accurate statement is: companies do not want to hand over all prompts, codes and internal documents to model providers, so Anthropic tried to change "must keep" into "you can keep it yourself".
Why are Claude enterprise customers suddenly so sensitive?
Because what companies often give Claude is not "write me a poem."
May be:
- Product routes that have not been disclosed yet;
- Company source code and vulnerability reports;
- Client lists, contracts and financial documents;
- Medical, legal or financial business information;
- A set of internal permissions that allow Agents to directly perform tasks.
As the model becomes more and more powerful, the question that enterprises are most concerned about has changed from "Is it smart?" to:
How long will this conversation last? Who can see it? If something goes wrong, who is responsible?
This is also the other side of the Claude watermark controversy. What users worry about is "whether AI will be misjudged if it has participated", while companies worry about "what will be left on the platform after I hand over the most sensitive things to AI."
What does 30 days actually mean?
Anthropic's existing commercial privacy statement states that API inputs and outputs are generally deleted from the backend within 30 days of receipt or generation, subject to exceptions such as longer retention services, zero-retention agreements, legal requirements, or usage policy investigations.
For products such as Claude for Work and Enterprise that allow saving and continuing conversations, chat records will be saved according to the workspace function; if the automatic security system determines that the usage policy is violated, the relevant input and output can be retained for up to two years, and the security classification score can be retained for up to seven years.
Therefore, "30-day retention" cannot be simply translated into "all data will automatically disappear after 30 days." The rules are different for different products, models, contracts and security scenarios.
What exactly does Anthropic want to change this time?
Anthropic is working with more than 100 customers, including Salesforce, to design the new system, Reuters said, citing people familiar with the matter.
The key change in the plan is not to cancel the 30 days directly, but to allow enterprises to keep the data they need to retain in their own cloud computing environment. Anthropic still gets the signals it needs to complete security monitoring, but companies don't have to keep their complete business data in Anthropic's infrastructure for long periods of time.
It sounds something like:
You must install surveillance, but surveillance videos can be placed on your own hard drive.
For Anthropic, this can take into account cutting-edge model security and the compliance requirements of large customers; for enterprises, it can at least take data sovereignty, access permissions and deletion processes into their own hands.
But why now? The answer may lie in stronger models
Anthropic announced in June that it would enforce a 30-day retention requirement on the more powerful Fable, Mythos series, and Future Frontier models, citing reasons related to security research and abuse monitoring.
This is actually in line with recent AI security news: the more the model can call tools, find vulnerabilities, and continuously perform tasks, the more manufacturers want to retain enough operating data to investigate abnormal behaviors; the more worried companies are, precisely because these data contain their own secrets.
On one side is "If you don't provide logs, you can't review if something goes wrong"; on the other side is "If you keep logs for too long, companies won't dare to use them."
What Anthropic needs to do now is to find a way in the middle to sell to big customers.
OpenAI is playing the “we can retain nothing” card next door
Reuters reported that OpenAI on Wednesday announced a secure system that does not retain customer data but can still identify potential abuse.
This makes Anthropic’s changes more like a product competition in the enterprise market:
- Anthropic: Keep necessary data but let businesses choose where to store it.
- OpenAI: try not to retain customer data and do abuse detection at the same time.
- Enterprise customers: demand both—strong security without giving the provider unnecessary access to their data.
Of course, suppliers’ “zero retention” is not a slogan that can cover all products. What really matters is the terms of the contract, the scope of the model, authority to investigate anomalies, who holds the encryption keys, and who has access to logs after a security incident.
The awkward trade-off: security and privacy may be pulling in opposite directions
If the AI Agent only answers questions, the manufacturer may be able to keep fewer records.
But when an agent can read code, execute commands, and access enterprise systems, the security team needs to know what it did, why it did it, and whether it was misled by prompt injection. Without logs, investigation becomes very difficult.
But if nothing is left, enterprises will worry that anyone may become a data accessor: the model manufacturer itself, internal employees, attackers or future regulatory requirements.
This is not a contradiction of Anthropic, but a wall that the entire enterprise AI industry will hit: the more powerful the Agent, the more audit it needs, and the more stringent the audit, the more likely it is to scare away customers.
My verdict: The next trump card in enterprise AI may not be models, but “data dashboards”
In the future, when an enterprise purchases Claude, ChatGPT or other Agents, the most important terms in the contract may no longer be just price and context length, but:
- Where does the data exist?
- How long to keep by default;
- Whether the enterprise can delete and export by itself;
- Whether to support own cloud, private network and self-sustained keys;
- How much original content the provider can see when abuse occurs;
- How long does it take for cache, logs and backups to disappear after closing the account.
Anthropic’s plan this time has not yet become a fully public product, nor does it prove that the company has obtained the final option. But it at least shows that large model companies have discovered that: "We will not train your data" is not enough. Customers also need to know whether you will keep it, where to put it, and when it can be deleted.
What to watch
- When will Anthropic announce its official policy, applicable products, and customer configuration options.
- Whether the self-owned cloud reservation supports all enterprise packages or is it only open to a few large customers.
- "Security monitoring" needs to see the complete content, or only encrypted signals and metadata.
- Whether OpenAI's unreserved abuse detection exposes technical boundaries.
- Whether the EU, US and industry regulations will further stipulate the minimum retention period for enterprise AI logs.
The last sentence:
AI companies are vying for your workflow and the right to explain who can see the chat logs when something goes wrong.
Why this matters to you
If you've pasted company code, customer information, or unpublished files into Claude, ChatGPT, or Coding Agent, don't just read the phrase "will not be used for training." What should really be confirmed are data retention periods, exception review exceptions, administrator permissions, deletion mechanisms, and enterprise contract terms.