Fable 5 Needs Retention On. ZDR Was Never Zero.

Claude Fable 5 and Mythos 5 are Covered Models: they refuse to run in a zero-data-retention workspace on the Claude API, Bedrock, Google Cloud or Microsoft Foundry. Anthropic's own docs also say flagged prompts can be held up to two years even under ZDR — while OpenAI previews the opposite bet.

By Rajesh Beri·August 20, 2026·13 min read
Share:
A manila folder of printed contract pages lying open on a polished boardroom table, one paragraph circled in red ink, beside a closed silver laptop.

Illustration generated using AI

If your organization runs a zero-data-retention workspace, Claude Fable 5 and Claude Mythos 5 will not run inside it. Not on the Claude API, not on Amazon Bedrock, not on Google Cloud's Agent Platform, not in Microsoft Foundry. Anthropic designated both as Covered Models requiring 30-day retention of prompts and outputs, effective June 9, 2026, and the API enforces it: a request from a workspace without retention enabled comes back as a 400 invalid_request_error reading "In order to access this model, your organization or workspace must have data retention enabled."

So the decision on your desk is binary. Turn retention on and update every artifact that says you don't retain — or keep ZDR and take the frontier tier off your approved model list. Before you pick, there is a third fact worth having, and it is in Anthropic's own developer documentation: the ZDR arrangement you are weighing against was never zero. OpenAI previewed a rival approach on August 19 that keeps ZDR intact and ships derived safety signals out instead. That branch needs a contract change too.


What a Covered Model Does to Your Workspace

A Covered Model is a model Anthropic will not serve without logging it. Claude Fable 5 and Claude Mythos 5 share the same specs and pricing — a 1M-token context window, 128K output, $10 per million input tokens and $50 per million output — and the same designation: "Claude Fable 5 and Claude Mythos 5 carry 30-day data retention and are not available under zero data retention." Mythos 5 ships without Fable's refusal classifiers and is limited to approved customers through Project Glasswing; Fable 5 is generally available.

Anthropic's fix for a ZDR organization is per-workspace, not per-organization. In Claude Console under Settings > Workspaces > Privacy controls, an admin turns on 30-day retention for one workspace and the rest of the organization keeps zero data retention. That is a genuinely useful containment boundary — it means "Fable 5 is approved" does not have to mean "the whole tenant now logs." It also means the control is a console toggle held by an organization admin, which is a different risk than the one your DPA describes. We covered Fable 5's pricing tier when it launched; this is the clause that came with it.

Bedrock and Foundry Are Not a Way Around It

Buying Claude through a hyperscaler does not buy you an exemption — it changes the mechanics and, on one platform, makes residency worse. On Amazon Bedrock, retention is a four-value mode rather than a toggle, and Fable 5 and Mythos 5 declare allowed_modes: ["provider_data_share"], which is the only mode they accept. If your effective mode is none or default, the model reports status: "unavailable" in your model list with status_reason: "This model is not available under data retention mode 'default'." — and AWS blocks the request and returns an error if you call it anyway. AWS's own launch post is blunt about what opting in costs: once provider_data_share is set, "your data will leave AWS's data and security boundary."

Two Bedrock details deserve to be in your risk register. First, there is no console UI for this at launch — it is an API-only setting at account or project scope, resolved as project → account → model default. Second, AWS states that "if cross-region inference is enabled for these models, retained inputs and outputs are stored in destination regions." An EU data-residency commitment and cross-region inference on a covered model are not compatible, and nothing in the API will tell you that.

Microsoft Foundry is the sharper case. Foundry offers Claude in two hosting versions, and the model table shows claude-fable-5 and claude-mythos-5 as available only on Anthropic infrastructure — the Azure-hosted version is not offered for either. Microsoft's own privacy page for that option says plainly that "data might be processed outside of Azure including outside of your selected Azure region." If you adopted Foundry so Claude traffic would stay on Azure, the frontier tier is the exception, by design. Anthropic's guidance for Foundry customers with ZDR is to stand up a separate Azure Subscription — a new billing and governance boundary, not a setting. Google Cloud's Agent Platform is the same bargain: Anthropic says the 30-day requirement applies wherever Covered Models are offered, with retained data staying inside the cloud provider's environment and enablement handled by that platform.


Zero Data Retention Was Never Zero

This is the part that should change how you brief your board, and it is on Anthropic's own docs page rather than in a critic's blog. Under the heading Retention regardless of arrangement, the API data-retention documentation states: "Even with ZDR or HIPAA arrangements in place, Anthropic may retain data where required by law or where it has been flagged by Anthropic's automated trust and safety systems. As a result, if a chat or session is flagged, Anthropic may retain inputs and outputs for up to 2 years." Anthropic's consumer retention policy puts a second number on the parallel consumer-account exception — trust and safety classification scores held "for up to 7 years" on flagged sessions.

Nobody hid this. It has simply never been the sentence anyone quotes, because "zero data retention" is a phrase that does its own arguing. Read alongside the Covered Model policy, the shape is clearer than the headline: 30 days is the floor for Fable 5 traffic, and up to two years is the ceiling for anything a classifier flags — under ZDR, under a BAA, on any tier.

The same page names three more gaps a ZDR org usually assumes are covered. Claude Console usage including Playground is not ZDR-eligible. Claude Managed Agents persist session transcripts until you delete them. And for stateful features marked ineligible — Batch API, Files API, code execution — Anthropic's FAQ is explicit that "nothing blocks the request… Using them is a choice to step outside your ZDR arrangement for that specific data." A silent, per-request opt-out of your own compliance posture is the kind of thing that surfaces in an audit rather than in a dashboard. If your controls assume governance tooling catches this at the inventory layer, test that assumption against a Files API call.

Your Processor Changes With the Front Door You Use

The contractual chain behind Fable 5 depends on where you bought it, and most buyers have not mapped it. Anthropic's documentation draws the line itself: the Claude API, Claude Platform on AWS and Claude in Microsoft Foundry are surfaces "where Anthropic is the data processor," while "on Amazon Bedrock and Google Cloud's Agent Platform, the cloud provider is the data processor." Microsoft's page describes Anthropic as an "independent data processor" for prompts and outputs in Foundry. So the same model, under three purchase routes, produces three different answers to "who is my processor, and who is the subprocessor I must disclose."

That matters because Anthropic's DPA states that "Customer is the controller and Anthropic is Customer's processor," processing "in compliance with Customer's documented instructions." A retention period that the customer cannot decline, set by the vendor for the vendor's safety programme, is not obviously a documented customer instruction — a point raised repeatedly in the Hacker News thread on the policy, where commenters flagged the controller-status question and the erosion of a simple message to customers. The DPA does contemplate this: its deletion clause carves out cases where "retention of the Customer Data is necessary to combat harmful use." Whether that carve-out carries a mandatory 30-day log plus a two-year flagged tail is a question for your DPO, and the honest answer is that it is unsettled, not that it is fine.

One more asymmetry worth pricing. HIPAA readiness is available on the Claude API — and not on Claude Platform on AWS, not in Microsoft Foundry, not on Bedrock or Google Cloud's Agent Platform, and not for Claude Code. If you route PHI through Claude and you also want Fable 5, those two requirements currently point at different products. Teams building RAG for regulated industries should check this before the architecture hardens.

OpenAI Is Selling the Opposite Bet

OpenAI's answer is to keep ZDR and move the safety analysis rather than the data. Private Safety Processing, previewed August 19, runs automated cross-conversation abuse detection while customer content stays on customer-controlled infrastructure or under customer-controlled encryption keys; when something trips, only a narrowly scoped signal describing activity type and severity leaves — not the content. "We're seeing with more capable frontier models that often risks are emerging not just by looking at one single prompt and response pair, but when you look over time at multiple interactions," said Aleah Houze, OpenAI's head of product policy. Microsoft and Databricks are the named early testers, with a technical white paper and broader rollout due in September 2026.

Do not book this as a free win. It is a preview with no published paper yet, and Computerworld's reporting puts real caveats around it. OpenAI's own estimate of the monitoring overhead is "roughly 20% of the inference compute being monitored, though the cost varies substantially" — a vendor figure, not an independent measurement. Brian Levine of FormerGov notes that "zero is never quite zero because CSAM-flagged content is still retained for legal reporting." Jason Andersen of Moor Insights & Strategy read the timing as "a little bit of pragmatic theater as they move into an IPO." OpenAI's published ZDR documentation already carries its own exclusions — Assistants endpoints, /v1/threads, vector stores and /v1/videos are not ZDR-eligible, and image and file inputs may still be retained for CSAM detection. If you are still on Assistants, that overlaps with the August 26 shutdown you are already migrating off.

And note the governance question PSP creates rather than answers. A derived safety signal about your traffic is still processing of data derived from your users' inputs, leaving your tenancy, triggering an enforcement decision against your account. Your DPA has to cover that, and somebody in your org has to own the phone when an OpenAI safety inquiry arrives.

The Case Anthropic Is Making, Stated Fairly

Anthropic's reasoning is specific and not unreasonable. "Some attacks only become visible across multiple requests," the policy says. "Best-of-N jailbreaking, for example, sends hundreds of slight variations of a prompt in the hope that one will work… Larger patterns of misuse, such as state-sponsored espionage or data extortion campaigns, only surface when our safeguards classifiers can zoom out across many requests." Single-request filtering genuinely cannot see that shape. The controls around the logs are also stronger than "we keep your prompts": by default no Anthropic personnel can read retained conversations, human review runs only through a controlled access path triggered by an automated flag, and "every instance of access is recorded in a tamper-proof log that reviewers cannot suppress or modify."

The counterweight is that one of the most sophisticated buyers on earth looked at this and paused. In June, Microsoft launched Fable 5 to customers on Foundry and GitHub Copilot while withholding it from its own employees' internal model catalog pending a legal review focused on protecting customer and confidential data. Microsoft is also one of the two named early testers of OpenAI's zero-retention alternative. That is not a company that thinks the question is settled — and it is the same posture Anthropic's export-control episode should have taught buyers, when access to both models was suspended globally on June 12 and not restored until July 1. Availability on a frontier tier is a policy variable, not a platform guarantee. We made a related argument about not inheriting a lab's own assurance work.

What to Do Before Your Next Renewal

This Week:

  1. Query the actual state rather than asking the platform team. On Bedrock, GET /v1/data_retention at account scope and GET /v1/organization/projects/{project_id} for each project; on the Claude API, open every workspace's Privacy controls tab. Write down which workspaces have retention on and who flipped them.
  2. Grep your customer-facing artifacts — MSAs, security questionnaires, trust-center pages, sales decks — for the literal string "zero data retention" and any "we do not retain" promise. That is your exposure list, and it is almost certainly longer than your ZDR workspace list.
  3. Decide whether Fable 5 goes on the approved list at all. If the answer is no, enforce it rather than documenting it: AWS publishes a bedrock-mantle:DataRetentionMode condition key, so a Service Control Policy denying any mode other than none makes the frontier tier structurally unreachable org-wide.

This Month:

  1. Update your Article 30 record of processing for the workspaces where retention is now on. The retention period is 30 days with a documented exception of up to two years for flagged content — put both numbers in, not just the friendly one.
  2. Map processor and subprocessor per purchase route. Bedrock and Google Cloud Agent Platform put the cloud provider in the processor seat; the Claude API, Claude Platform on AWS and Foundry put Anthropic there. Your disclosure list and your SCC modules differ accordingly.
  3. Kill cross-region inference on covered models, or accept in writing that retained prompts land in the destination region. Pick one. Teams that already fought this on European inference endpoints know how long it takes to unwind later.

Before Renewal:

  1. Ask both vendors the same three questions in writing: what is the maximum retention for flagged content, who can read it under what trigger, and what is the deletion evidence I can hand an auditor. Compare the answers side by side, not the marketing.
  2. If you need a genuine ZDR exception on Bedrock, start now — AWS routes it per-account and per-model through the model provider, and Anthropic controls the decision for Claude.
  3. Get the AWS and Anthropic statements reconciled on paper. Anthropic says retained data "stays in AWS"; AWS says your data "will leave AWS's data and security boundary." Both can be technically true and they will read very differently to a regulator.

The Bottom Line

Every previous frontier upgrade was a performance and price decision. This one is a legal-basis decision, and it runs the wrong way through your org chart — the person who can unlock the model is an admin with a console toggle, and the person who owns the consequence is a DPO who will find out later. The industry has now produced two answers to the same safety problem: Anthropic moves your data to the analysis, OpenAI moves the analysis to your data. Neither is free, both need a DPA change, and only one of them is honest in its name.

Check what you promised your customers before you decide which bet you are making. "Zero" was doing a lot of work in that sentence.

Continue Reading

Share:

Frequently Asked Questions

Can I use Claude Fable 5 with a zero-data-retention agreement?

No. Anthropic designates Claude Fable 5 and Claude Mythos 5 as Covered Models requiring 30-day retention of prompts and outputs, and they are not available under ZDR on any platform. On the Claude API a request from a workspace without retention returns a 400 invalid_request_error. You can enable 30-day retention for a single workspace and leave the rest of the organization on ZDR.

Does buying Claude through AWS Bedrock or Microsoft Foundry avoid the retention requirement?

No. On Bedrock, Fable 5 and Mythos 5 only accept the provider_data_share retention mode; under 'none' or 'default' the model reports status 'unavailable'. On Microsoft Foundry both models are offered only on Anthropic-hosted infrastructure, and Microsoft warns data may be processed outside your selected Azure region. A ZDR Foundry customer needs a separate Azure Subscription.

How long does Anthropic actually keep the data?

Thirty days is the standard retention for Covered Model prompts and outputs, after which data is deleted automatically. But Anthropic's API documentation states that even with ZDR or HIPAA arrangements in place, if a chat or session is flagged by its automated trust and safety systems it may retain inputs and outputs for up to two years.

What is OpenAI's Private Safety Processing?

It is a preview announced on 19 August 2026 that runs automated cross-conversation abuse detection while keeping zero data retention. Customer content stays on customer-controlled infrastructure or under customer-controlled encryption keys, and only a narrowly scoped signal describing activity type and severity leaves. A technical white paper and broader rollout are due in September 2026.

Who is my data processor for Claude Fable 5?

It depends on the purchase route. Anthropic's documentation says Anthropic is the data processor on the Claude API, Claude Platform on AWS and Claude in Microsoft Foundry, while on Amazon Bedrock and Google Cloud's Agent Platform the cloud provider is the processor. That changes which subprocessors you disclose and which SCC module applies.

Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe

Latest Articles

View All →