AWS Bedrock and Anthropic Data Retention Policy for Mythos Models
Anthropic Mandates 30-Day Data Retention for Mythos-Class Models
Anthropic now requires a 30-day retention period for all traffic on Mythos-class models—including Fable 5 and Mythos 5—and future models of similar capability levels hosted on AWS Bedrock. This policy change means that once a user opts into data retention to access these models, the data leaves the AWS data and security boundary to be processed by Anthropic.
According to the official announcement, this retention is designed to allow Anthropic to detect patterns of misuse that are not visible in single exchanges. Data is automatically deleted after 30 days, except in cases where the data is part of a safety investigation or is required to be kept for legal reasons.
Impact on Enterprise Security and Compliance
This policy shift creates significant hurdles for regulated industries and government entities that rely on strict data residency and zero-data retention (ZDR) policies. Because data exits the AWS security perimeter, organizations with strict compliance requirements may find these models unusable.
Compliance and Legal Concerns
- Regulated Industries: Users have noted that this requirement is a "non-starter" for government clients and regulated enterprises due to the lack of governance and controls over data leaving the cloud provider's boundary.
- Healthcare (HIPAA): There are concerns regarding HIPAA workloads, as the blanket retention policy may conflict with PHI (Protected Health Information) requirements unless granular controls (such as per-API key retention) are implemented.
- GDPR: Some analysts suggest that Anthropic may now be acting as a GDPR data controller for submitted data, potentially granting data subjects the right to request information about processing under Article 15.
Security Risks
Critics argue that the "legally required" exception to the 30-day deletion rule creates a loophole for permanent data storage, potentially exposing corporate data to government surveillance or national security letters.
Industry Reactions and Alternatives
The announcement has sparked a debate over the trade-off between accessing "frontier" model capabilities and maintaining data privacy.
Shift Toward Self-Hosting and Open Source
Many technical users are reacting by shifting their strategy toward smaller, self-hosted models or open-source alternatives to avoid vendor lock-in and data exfiltration risks. One user noted:
"The whole point of my company using Bedrock is so that we knew our data wasn't being shipped off anywhere. This means we will a) block Mythos-class models at the organisation level and b) further consider using smaller, self-hosted models for our purposes."
Competitive Landscape
Some observers believe this move opens a gap in the enterprise market for competitors who can offer similar capabilities with stricter privacy guarantees. There are also comparisons to other providers, with some users noting that Google Cloud's advanced AI safety addendum similarly requires data retention (up to 60 days).
Summary of Data Flow Changes
| Feature | Previous Bedrock Standard | Mythos-Class Models (New) |
|---|---|---|
| Data Boundary | Stays within AWS | Leaves AWS to Anthropic |
| Retention Period | Often Zero/Configurable | 30 Days (Mandatory) |
| Deletion | Immediate/Per Policy | Automatic after 30 days (with exceptions) |
| Purpose | Inference | Misuse detection and safety investigations |