Nvidia, Palantir and Booz Allen Hamilton have each tightened how their people can use Anthropic's models internally. The Information first reported the moves, and the three companies took different approaches: Palantir is requiring Anthropic to guarantee zero data retention before it will wire the models into its own software platform; Nvidia is limiting Anthropic's models to lower-sensitivity internal tasks and routing anything touching proprietary information to its own Nemotron model family; Booz Allen has barred employees from calling Anthropic's commercial models on cybersecurity projects that touch proprietary data.
All three concerns point at the same question: whether a model vendor might retain, or even learn from, a customer's intellectual property.
How the 30-day window opened
The dispute traces back to June. Anthropic adjusted its data policy alongside the Fable 5 release, setting a 30-day retention period for usage logs. At the time, the company's explanation was that some attacks unfold across multiple sessions and can't be spotted from a single request — investigators need a window of logs to piece together the full picture — while promising that the data wouldn't be used for training.
That explanation held up on the consumer side. It ran into resistance on the enterprise side. The strongest pushback came from customers in regulated industries — finance, healthcare, government contracting — where contracts often lock data inside the customer's own boundary. For them, "retained for 30 days but not used for training" and "not retained at all" are two different compliance lines, with no middle ground between them.
By their own public statements, the leading labs don't train on customer data by default, but both collect anonymized metadata unless an enterprise customer opts out. This round of pushback is about the retention itself.
Anthropic's answer
Anthropic's response is a mechanism called Enterprise Frontier Safeguards: enterprise customers can store activity data in their own cloud infrastructure — Amazon S3, Azure Blob Storage or Google Cloud Storage all work — encrypted with their own keys. Security monitoring shifts to an automated process that doesn't require an Anthropic employee to manually review the logs. The rollout is happening in phases, with a broader release planned for fall 2026.
It hands both questions — where the logs live, and who can decrypt them — back to the customer in one move. What the reporting doesn't spell out is exactly how automated monitoring works against a customer's own storage, or what process triggers once it flags something.
Laying the timeline out straight
The sequence runs like this: the retention policy changed in June, enterprise customers pushed back, three major customers each set their own restrictions, and Anthropic is rolling out a self-hosted logging option for a broader release this fall.
Large companies restricting outside models isn't new on its own. Meta has previously limited engineers' use of Claude Code and Codex, and Google has long allocated Claude access internally by headcount quota. What's different this time is that the stated reason centers on data terms, not cost or competition with in-house tools.
Each company's position also shaped how it tightened access. Nvidia has its own Nemotron family, so falling back to in-house models when proprietary data is involved is a path that's already built. Palantir resells models to government and large enterprise customers, and based on the terms it's proposing, zero data retention looks more like a prerequisite for closing contracts. Booz Allen is a consulting firm managing specific projects its employees touch, so a blanket ban is the simplest route.
What's still unanswered
None of the three companies have disclosed how much of their business the restrictions cover or how many employees are affected. Whether these restrictions will be lifted once Enterprise Frontier Safeguards rolls out more broadly this fall can't currently be verified, and Anthropic hasn't publicly responded to any of the three companies' approaches. OpenAI faces similar questions about its training data, and there's no public information on whether it has a comparable self-hosted option.
Nvidia's stock closed down about 3% that day, though the broader AI sector pulled back that same day, so it's hard to say how much weight this news carried in the move.
Sources: The Information, Quartz, CocoLoop, Yahoo Finance. Details of each company's restrictions, the 30-day retention policy and the storage options under Enterprise Frontier Safeguards are as reported in the original coverage.