Security
Report: Palantir Demands Zero Retention as Anthropic Excludes Frontier Models
—

Palantir, Nvidia and Booz Allen are reportedly restricting external AI models around sensitive data, according to a report carried by Reuters. The companies did not comment on the specific restrictions. Anthropic's official policies nevertheless expose the technical issue: “not used for training” and “not retained” are different commitments.
## What the report says
Palantir reportedly asked Anthropic for an irrevocable zero-data-retention commitment before making Claude models available through its software. Nvidia is said to restrict Anthropic to less-sensitive work while using its own Nemotron models internally. Booz Allen reportedly bars Claude from proprietary cybersecurity work. Reuters attributes these claims to The Information and unnamed sources, so they should be treated as reporting rather than confirmed company policy.
Anthropic's commercial terms explicitly say customer content is not used for training. The provider's standard API policy can nevertheless retain inputs and outputs for up to 30 days. Zero Data Retention is agreed at organisation level and does not automatically cover every product or feature.
Crucially, Anthropic's documentation excludes Claude Fable 5.1, Mythos 5.1, Fable 5 and Mythos 5 from ZDR by default. These “Covered Models” require 30-day retention unless Anthropic expressly authorises an exception. Code execution, files, batch processing, stateful resources, abuse review and legal obligations can also trigger different periods. OpenAI similarly says API customer data is not used for training by default, while Zero Data Retention is a separate option available by request.
## Pandorex Analysis
For regulated organisations, a general privacy promise is insufficient. Procurement and security reviews must identify the exact model, endpoint, enabled tools, cloud processor and every exception to the deletion window.
That creates a practical trade-off: the strongest model may be ineligible for a sensitive workload even when the provider does not train on the data. A benchmark lead matters little if the required model or tool falls outside the contractually required zero-retention boundary.
Sources and references
Sources used for the facts and context in this article.
- https://www.anthropic.com/legal/commercial-termsanthropic.com
- https://platform.claude.com/docs/en/manage-claude/api-and-data-retentionplatform.claude.com
- https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-dataprivacy.claude.com
- https://openai.com/api/openai.com
- https://www.reuters.com/business/palantir-nvidia-curb-ai-model-use-over-data-fears-information-reports-2026-09-14/reuters.com