Anthropic now keeps prompts and outputs from its Mythos-class models for 30 days, and the policy overrides zero-data-retention agreements, effective 9 June 2026.
ZDR has meant exactly that: nothing kept. The new rule carves out Claude Mythos 5 and "future models with similar capabilities," reaching ZDR workspaces in Claude Console, Claude Code on Enterprise, and Claude accessed via AWS Bedrock, Google Cloud Agent Platform, or Microsoft Foundry. Anthropic's reasoning is that some attacks only show up across many requests. Best-of-N jailbreaking fires hundreds of prompt variants hoping one lands, and state-sponsored espionage or extortion campaigns only surface when classifiers can look across a batch rather than one call at a time. Detecting them, it says, requires holding data long enough to analyse it together.
For regulated buyers who chose ZDR precisely so prompts never persist, "zero" now carries an asterisk on the frontier model. The safety case is real; so is the contractual surprise.