Nvidia, Palantir, and other large enterprises are tightening controls on external generative-AI services over concerns that proprietary prompts, interaction data, and technical metadata could be retained or exposed. Palantir reportedly sought a zero-data-retention commitment from Anthropic and may limit access to certain Anthropic models pending such assurances; Nvidia has limited Anthropic models to low-sensitivity tasks while using its internal Nemotron model family for operations. Booz Allen Hamilton has also restricted commercial Anthropic-model use for some proprietary cybersecurity work.
The concern is especially acute for organizations handling government, defense, customer, and industrial-secret information. Anthropic reportedly retains some usage data for up to 30 days to detect and prevent sophisticated abuse, while Anthropic and OpenAI say enterprise data is not used to train models by default without explicit consent. In response, customers are pursuing isolated-cloud, customer-hosted, on-premises, and air-gapped AI deployments, and in some cases have paused or cancelled evaluations that lacked zero-data-retention guarantees.

Track how attackers are adapting to this technology.
8 events from the most recent confirmed update back to the earliest known activity.
Palantir reportedly requested that Anthropic guarantee zero data retention for user data and may temporarily suspend access to certain Anthropic models on its platform until its requirements are met.
Booz Allen Hamilton took measures to prevent employees from using Anthropic commercial models for certain proprietary cybersecurity tasks, seeking to avoid transmitting confidential government and private-client information to external AI services.
NVIDIA restricted Anthropic model use to low-sensitivity work because of a lack of zero-data-retention guarantees. It uses in-house AI, including its Nemotron model family, for internal and more sensitive tasks.
A large U.S. utility cancelled planned testing of Anthropic's Fable for core power infrastructure after Anthropic would not agree to a nonrevocable zero-data-retention policy.
Novo Nordisk continued using Anthropic's Claude for some tasks while prohibiting employees from using proprietary data with the model.
Northrop Grumman chose to run open-source AI models on its own air-gapped servers instead of using OpenAI or Anthropic services.
C Spire said its OpenAI and Anthropic agreements prohibit use of its data for model training but allow collection of technical usage data. The company requested clearer explanations of what data is collected, including information about connected applications and model-use activity.
Anthropic changed its Fable policy in June to permit retention of customer data, stating that retention is intended to ensure the model is not misused. Anthropic reportedly may retain certain usage data for up to 30 days to detect and prevent sophisticated attacks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
zdnet.fr
Open sourcetomshardware.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.