
When a chip maker, an intelligence-community data analytics firm, and one of the largest US consulting firms all pull back from the same AI vendor within days of each other, that’s more than an isolated complaint. Nvidia, Palantir, and Booz Allen Hamilton are restricting the use of Anthropic’s Fable 5 model for sensitive work or demanding fixes. The trigger is a policy introduced in June to retain usage logs for 30 days — a dispute that shows how quickly a security measure can turn into a real trust problem once companies fear for their intellectual property.
Key takeaways
- Since June, Anthropic has retained Fable 5 usage logs for 30 days to detect sophisticated multi-session cyberattacks — not for training, the company says.
- Nvidia limits Claude to less sensitive tasks and uses its own Nemotron models for internal projects; Booz Allen Hamilton bars its use for proprietary cybersecurity work.
- Palantir is blocking Fable’s availability through its own platform until Anthropic commits to irrevocable zero-data-retention guarantees.
- Anthropic is responding with “Enterprise Frontier Safeguards”: customers will be able to store logs in their own cloud infrastructure under their own encryption keys.
- OpenAI faces similar criticism over its data practices and introduced its own storage options for security-focused customers back in August.
What Anthropic changed in June
With the rollout of Fable 5, Anthropic began retaining usage logs for 30 days in June. The reasoning: only over that window could the company detect sophisticated, multi-session cyberattacks that unfold gradually. Anthropic stressed from the start that it does not use this data to train its own models. For customers in regulated industries and the defense sector, that assurance wasn’t enough — what matters to them isn’t only what the data gets used for, but the fact that it leaves their own infrastructure at all.
Three heavyweights pull back
The break is clearest at Nvidia, even though the chipmaker is itself an Anthropic investor and hardware supplier. Justin Boitano, Nvidia’s vice president of enterprise AI, told The Information that his company believes zero data retention should be the default. Nvidia still uses Fable for open, less sensitive projects, but for internal applications like AI-driven supply-chain monitoring, it relies on its own Nemotron models instead. At Booz Allen Hamilton, one of the earliest adopters of Anthropic’s previous model, “Mythos,” CTO Bill Vass put it just as bluntly: the firm worries Fable could learn from its own code, so employees are barred from using the commercial model for proprietary cybersecurity work. Palantir goes furthest: the software company is refusing to make Fable available through its own platform until Anthropic commits irrevocably to storing no data at all. CEO Alex Karp captured the mood at a customer event when he said companies are tired of being exploited by AI labs — though the push also serves Palantir’s own interests, since it would rather route customers to its own, more secure-branded platform than let them go straight to the model vendors.
Anthropic’s answer: handing control back to customers
Anthropic responded with a program called Enterprise Frontier Safeguards. It lets enterprise customers store their activity logs in their own cloud infrastructure going forward — in Amazon S3, Azure Blob Storage, or Google Cloud Storage, for instance — under encryption keys they manage themselves. Automated safety monitoring will still scan for misuse, but manual review by Anthropic staff should no longer be necessary. The program is rolling out in phases, with broader availability planned for later in the fall. OpenAI had already made a similar move: since August, customers of its cybersecurity-focused GPT-5.6 Cyber models have been able to keep security logs on their own servers instead of OpenAI’s. The concern isn’t fully resolved even so, according to an analysis by Aragon Research: the trust gap doesn’t close, it just shifts.
A pattern that reaches beyond Anthropic
The dispute lands in a period when the major AI labs are already under heightened scrutiny — for instance through the debate over Anthropic’s and OpenAI’s push to slow the pace of model development, itself widely read as a trust signal to the public and regulators. In parallel, the Project Lily case drew attention, where OpenAI contractors read and rated real ChatGPT conversations — another example of how quickly data practices can become a reputational risk, even when they’re officially meant to protect users. Prominent researchers weighed in too: former OpenAI co-founder John Schulman warned on X that “de-identification” of user data is a weak promise, since people can be re-identified from just a handful of data points. Former Cohere and Google DeepMind researcher Sarah Hooker added that companies with valuable intellectual property have only a limited window to build their own AI capabilities — otherwise they end up feeding the very frontier lab that will later move into their industry. Nvidia and Palantir have already acted on that logic, unveiling a joint platform that combines Palantir’s software with Nvidia’s open Nemotron models — built so organizations can run AI entirely on their own data locally, without ever handing anything to an outside vendor.
What this means for businesses
For IT and security leaders, the dispute offers a clear takeaway: a vendor’s data retention, telemetry, and logging policies belong on the table before any production deployment, not after. Anyone working with sensitive or regulated data should consider hybrid deployment models that keep data inside their own cloud environment, or specifically test open models that can run locally. Above all, the episode shows that model quality alone no longer wins enterprise deals. The ability to credibly guarantee control over one’s own data is now just as much a competitive edge as a more capable model.

