AWS Bedrock and Anthropic Data Retention Policy for Mythos Models

Anthropic Mandates 30-Day Data Retention for Mythos-Class Models

Anthropic now requires a 30-day retention period for all traffic on Mythos-class models—including Fable 5 and Mythos 5—and future models of similar capability levels hosted on AWS Bedrock. This policy change means that once a user opts into data retention to access these models, the data leaves the AWS data and security boundary to be processed by Anthropic.

According to the official announcement, this retention is designed to allow Anthropic to detect patterns of misuse that are not visible in single exchanges. Data is automatically deleted after 30 days, except in cases where the data is part of a safety investigation or is required to be kept for legal reasons.

Impact on Enterprise Security and Compliance

This policy shift creates significant hurdles for regulated industries and government entities that rely on strict data residency and zero-data retention (ZDR) policies. Because data exits the AWS security perimeter, organizations with strict compliance requirements may find these models unusable.

Compliance and Legal Concerns

  • Regulated Industries: Users have noted that this requirement is a "non-starter" for government clients and regulated enterprises due to the lack of governance and controls over data leaving the cloud provider's boundary.
  • Healthcare (HIPAA): There are concerns regarding HIPAA workloads, as the blanket retention policy may conflict with PHI (Protected Health Information) requirements unless granular controls (such as per-API key retention) are implemented.
  • GDPR: Some analysts suggest that Anthropic may now be acting as a GDPR data controller for submitted data, potentially granting data subjects the right to request information about processing under Article 15.

Security Risks

Critics argue that the "legally required" exception to the 30-day deletion rule creates a loophole for permanent data storage, potentially exposing corporate data to government surveillance or national security letters.

Industry Reactions and Alternatives

The announcement has sparked a debate over the trade-off between accessing "frontier" model capabilities and maintaining data privacy.

Shift Toward Self-Hosting and Open Source

Many technical users are reacting by shifting their strategy toward smaller, self-hosted models or open-source alternatives to avoid vendor lock-in and data exfiltration risks. One user noted:

"The whole point of my company using Bedrock is so that we knew our data wasn't being shipped off anywhere. This means we will a) block Mythos-class models at the organisation level and b) further consider using smaller, self-hosted models for our purposes."

Competitive Landscape

Some observers believe this move opens a gap in the enterprise market for competitors who can offer similar capabilities with stricter privacy guarantees. There are also comparisons to other providers, with some users noting that Google Cloud's advanced AI safety addendum similarly requires data retention (up to 60 days).

Summary of Data Flow Changes

Feature Previous Bedrock Standard Mythos-Class Models (New)
Data Boundary Stays within AWS Leaves AWS to Anthropic
Retention Period Often Zero/Configurable 30 Days (Mandatory)
Deletion Immediate/Per Policy Automatic after 30 days (with exceptions)
Purpose Inference Misuse detection and safety investigations

Sources