Anthropic is requiring 30-day data retention for its most capable models on AWS Bedrock, and that retained data will leave Amazon's security perimeter.
Fable 5 and Mythos 5, Anthropic's highest-capability models, are now available through Bedrock with a new condition attached. Customers who run them must agree to Anthropic holding all traffic for 30 days. The stated purpose is detecting misuse patterns that are not visible from a single exchange. After 30 days, data is deleted automatically, except when it is part of a safety investigation or subject to a legal hold.
The problem for enterprise customers is structural. AWS Bedrock's core appeal in regulated industries is data isolation: inference traffic stays within Amazon's security and compliance boundary. That guarantee disappears for Mythos-class and higher models. Companies under HIPAA, FedRAMP, or strict data residency rules now face a binary choice: stick with older, less capable models that stay inside the boundary, or accept that their data flows to a third party.
Anthropic frames this as safety monitoring, not data collection for training purposes, and the 30-day window is short by enterprise standards. But open-ended carve-outs for "safety investigations" that can pause automatic deletion are precisely the kind of clause that enterprise legal teams flag before signing.
