Large enterprise customers are restricting sensitive use of a leading AI model because its provider retains usage logs for 30 days to investigate sophisticated attacks. Nvidia reportedly limits Anthropic’s Fable model to less sensitive work and uses its own Nemotron models for internal supply-chain tasks, while Booz Allen bars Fable from proprietary cybersecurity development.
Palantir is blocking deployment through its platform until Anthropic provides irrevocable zero-data-retention guarantees. Anthropic is now preparing an option for selected customers to store security logs on their own servers, following a similar OpenAI program. The dispute shows why a promise not to train directly on customer prompts may be insufficient: providers can still collect technical metadata, classifications or derived patterns that customers do not fully understand.
Researchers describe a spectrum from direct pretraining to reinforcement-learning environments built from user traces. Derived data may carry little risk of reproducing exact content while still exposing workflows or intellectual property. De-identification also does not automatically prevent re-identification or competitive leakage. Providers say user data contributes little to frontier capability gains and is more valuable for finding failures, but disclosure practices vary. For buyers, the practical requirement is precise contractual language covering prompts, outputs, logs, metadata, derived datasets and deletion—not a general “no training” label that leaves each of those categories undefined.