Anthropic 要求 Fable 和 Mythos 保留 30 天的数据。
Anthropic requires 30 day data retention for Fable and Mythos

原始链接: https://support.claude.com/en/articles/15425996-data-retention-practices-for-mythos-class-models

自 2026 年 6 月 9 日起,Anthropic 将对“Mythos”级模型引入 30 天的数据保留政策,旨在增强安全性并检测网络攻击或间谍活动等复杂的滥用行为。 此政策专门针对目前通过 Claude API、Claude Enterprise、AWS Bedrock、Google Cloud Agent Platform 或 Microsoft Foundry 使用“零数据保留”(ZDR)配置的组织。消费者计划(Claude Free、Pro 和 Max)不受影响,因为它们已启用数据保留以确保安全。 为使用这些高级模型,已启用 ZDR 的组织必须调整设置以开启数据保留。对于 AWS 和 Google Cloud 用户,数据将保留在其各自的云环境中。 Anthropic 强调,仅当数据被标记为涉及严重危害时,才会由一小部分授权审查人员访问。所有访问均有记录,且数据会在 30 天后自动删除(除非涉及安全调查)。组织可通过客户管理的加密和审计日志进一步保护其数据。对于未使用 ZDR 或不打算使用此类新模型的组织,无需采取任何行动。

Anthropic 宣布对其“Mythos 级”模型实施强制性的 30 天数据保留政策,该政策适用于第一方和第三方平台。尽管公司声明这些数据将仅用于安全保障目的(例如识别越狱行为和减少误报),且不会用于训练未来模型,但该政策已在开发者社区引发了广泛关注。 Hacker News 上的批评者指出,公告中的措辞存在歧义,特别是在涉及数据删除时使用的“在几乎所有情况下”这一表述。用户担心这会留下漏洞,导致 Anthropic 可以无限期保留敏感信息,例如代理系统处理的完整代码库。此前,AWS Bedrock 的集成也引发了类似的争议,该集成要求用户与 Anthropic 共享数据以进行模型改进。由于这些新的保留要求,注重隐私的开发者对专有数据可能面临的泄露风险表示不安。
相关文章

原文

To ensure we’re responsibly deploying Mythos-class models, we are requiring limited data retention and review as part of our safety work. Prompts submitted to, and outputs generated by, Mythos-class models are retained for 30 days for trust and safety purposes, on every platform where these models are offered.

This applies to Mythos-class models and future models with similar capabilities that we designate as covered models. For all other models, everything you use is unaffected and stays under the current terms.

This policy, described below, goes into effect on June 9, 2026. For more information on the threat model for retained data and associated privacy controls, please see the corresponding technical white paper on our Trust Center.

Who this applies to

Consumer plans (Claude Free, Pro, and Max) across our web, desktop, and mobile apps—including Claude.ai and Claude Code—are unaffected by this update, since we already retain inputs and outputs for safety purposes on these surfaces. Learn more about how we retain data for consumer plans.

This change only applies to organizations that have set up workspaces with zero data retention (ZDR) in Claude Console, use Claude Code with ZDR in Claude Enterprise, or access Claude through AWS Bedrock, Google Cloud Agent Platform, or Microsoft Foundry with ZDR. The rest of this article applies only to these organizations.

Why we’re doing this

Claude Mythos 5 represents a substantial increase in model capabilities, some of which can be used for both benign and malicious purposes. Claude Fable 5 shares the same underlying model as Claude Mythos 5, but with additional safeguards, particularly in the cyber and bio domains. While these safeguards allow us to share this intelligence more broadly, we are taking a conservative approach that allows us to look for patterns of misuse with this class of model. Some attacks only become visible across multiple requests. Best-of-N jailbreaking, for example, sends hundreds of slight variations of a prompt in the hope that one will work. Larger patterns of misuse, such as state-sponsored espionage or data extortion campaigns, only surface when our safeguards classifiers can zoom out across many requests. Detecting these threats requires temporarily retaining prompts and outputs so they can be analyzed together, rather than one at a time.

How we protect your data

Anthropic employees cannot access your conversations unless they are flagged for potential serious harm or upon a customer’s written request. These reviews can only be performed by a small set of approved reviewers through tooling that prevents export, copying, or downloading. Every instance of access is recorded in a tamper-proof log that reviewers cannot suppress or modify. After 30 days, the data is deleted automatically, except in the rare cases where it's part of a safety investigation or we're legally required to keep it. Eligible organizations also have the option to add customer-managed encryption keys and access transparency audit logs.

Anthropic maintains a documented information security program with technical and organizational measures that are designed to protect the security, confidentiality, and integrity of customer data. Our risk-based program is built for and evolves to defend against known and anticipated threat models and is tested regularly. For more information, see the technical white paper in our Trust Center.

What, if anything, do I need to configure?

This change only applies to organizations that have set up workspaces with zero data retention (ZDR) in Claude Console, use Claude Code with ZDR in Claude Enterprise, or access Claude through AWS Bedrock, Google Cloud Agent Platform, or Microsoft Foundry with ZDR. For all other organizations, there is no change and there's nothing to configure. The rest of this section is for organizations that access Claude without data retention today and need to set up data retention in order to use designated models when they become available.

If your developers use the Claude API

  • Directly from Anthropic through Claude Platform: Turn on retention for the workspaces where you want to use covered models in the developer console (Workspace > Manage > Privacy Controls). Your other ZDR-enabled workspaces keep ZDR. Refer to the Anthropic Trust Center for documentation.

  • Through Claude Platform on AWS: Retention works the same way as the direct Claude API. It's configured at the workspace level, and retained data is handled by Anthropic under the same controls.

  • Through Amazon Bedrock: Retention will need to be enabled to access your new covered model, and retained data stays in your AWS environment. When models become available, onboarding details will be shared.

  • Through Google Cloud's Agent Platform: Retention will need to be enabled for your new covered model, and retained data stays in your GCP environment. When models become available, onboarding details will be shared.

  • Through Claude in Azure Foundry: Retention is configured for each Azure Subscription. If you have Zero Data Retention configured, then you will need to create and use a separate Azure Subscription to access these models.

If your team uses Claude Code

  • Through the Anthropic API: Claude Code’s data handling practices are governed by the workspace it operates in. If that workspace has retention enabled, Claude Code can use designated models. For developers who sign in directly, enable retention at your organization’s Claude Code workspace.

  • Through Amazon Bedrock or Google Cloud Agent Platform: Claude Code uses your cloud credentials, so it follows your cloud environment's retention setting. Retention must be enabled in your cloud environment, and retained data stays in your provider's environment. The same applies to Cowork accessed through Amazon Bedrock or Google Cloud’s Agent Platform.

  • Through Claude Enterprise with ZDR: We're releasing controls in the admin console so your Primary Owner can change the retention setting directly. If you'd rather not touch your production org yet, we can help you set up a separate sandbox org.

If your team uses Claude chat or Cowork through Claude for Enterprise

  • These surfaces already operate with standard retention, so you'll have access to the new models as they become available.

联系我们 contact @ memedata.com