Anthropic Data Fears Prompt Nvidia, Palantir and Booz Allen to Restrict Model Use

As paranoia rises over whether Anthropic or OpenAI could learn from their customers’ intellectual property, large firms involved in sensitive corporate work, such as Palantir Technologies, Nvidia and Booz Allen Hamilton, have started demanding new guarantees or reducing or eliminating use of the AI firms’ most advanced models.

Anthropic is facing pushback over a June policy change for its flagship Fable model that gave it the right to retain customer data to ensure the model isn’t used in malicious ways. Changes related to the policy this month have left some customers unsatisfied. At the same time, OpenAI is defending itself against claims that it may have trained its model with a user’s data to help it achieve a major mathematical breakthrough.

Microsoft is already leveraging the fears to try to lure OpenAI and Anthropic clients to its own AI offerings, according to people involved in the effort. It also has aggressively pitched its own isolated cloud environments for customers worried about privacy; it recently offered one large client a system that would run AI models on privately managed servers that don’t send data to any external AI provider, costing millions of dollars over multiple years, an option the customer is still considering.

OpenAI and Anthropic say that by default, they don’t train their models on the information companies with enterprise contracts feed to the models or the information the models produce—unless customers opt in to such sharing. (Individual users must manually opt out of such data sharing.) Still, both OpenAI and Anthropic collect some metadata from corporate customers.

It isn’t clear what the metadata are, though corporate customers say OpenAI’s terms of service imply that they include anonymized data about how customers’ employees are using the software. OpenAI says the metadata are “de-identified,” meaning they don’t include information that identifies the customer. And while OpenAI says it collects such metadata “to better understand how our services are used,” an OpenAI spokesperson clarified such metadata is not used to improve the company’s models.

OpenAI uses de-identified to improve its models, including those that solved the Navier-Stokes math problem, Chief Research Officer Mark Chen said in an X post Tuesday. However, an OpenAI spokesperson said on Sunday that Chen was referring to data customers opted to share with OpenAI, and that, after investigating, OpenAI determined that no data from the researchers working on the Navier-Stokes problem in the past two years was used to improve its models.

Anthropic uses aggregated, anonymized data about how customers use its products, such as what features they rely on and which ones work better or worse than others, to improve the products. But it says it doesn’t use the metadata to train its models.

‘Blank Spot in Our Radar’

Some customers say the AI companies’ disclosures around these policies aren’t clear enough, and they are seeking more detailed explanations.

Telecommunications operator C Spire, for instance, maintains strict agreements with both OpenAI and Anthropic not to train new models on its data, but its contracts permit both labs to collect technical usage data. C Spire interpreted that term as data about what applications the models connected with to automate tasks, how often the company used the models, and possibly what work the models were doing behind the scenes between generating responses. However, an OpenAI official said the company does not train on the “chains of thought” models produce as they work on the answers.

C Spire Chief AI Officer Fernando Higuera said he’s trying to understand more about what data the AI labs are collecting. “I wouldn’t say it’s a red flag for OpenAI and Anthropic to capture that; it’s more of a blank spot in our radar,” Higuera said.

Corporate concerns about giving away proprietary information to Anthropic and OpenAI aren’t new, and their revenue has still grown rapidly. The two firms offer the best-performing models for automating white-collar work and research, according to a variety of evaluations, making them hard to ignore for businesses that want to automate customer service, legal work and other tasks—or to develop and sell AI apps that perform such work.

But Anthropic and OpenAI are now selling their own applications and features that also target such work, and they say they want to help develop drugs and other real-world products, potentially threatening the businesses of some of their biggest customers in the process.

Palantir has led the public charge to warn businesses not to work with Anthropic and OpenAI directly, though its warnings are self-serving: It wants businesses to use its own AI-related services as a buffer to protect their intellectual property from Anthropic. The leaders of Microsoft, Salesforce and other firms that compete with Anthropic and OpenAI in selling AI applications to businesses have made similar public comments, saying customers should access the leading AI models through them instead of buying directly from the model providers.

Anthropic historically had given some business customers guarantees around zero data retention, ensuring the company didn’t store their data and use it to improve new AI models. But when Anthropic launched Fable in June, it changed course, stating that it needed to retain logs of how customers were using the model on a rolling 30-day basis to “help us defend against complex and novel attacks.”

OpenAI similarly said it would retain some logs from customers using its GPT-5.6-Cyber models for safety reasons, but in August it gave customers the option to store such logs on their own servers.

Following customer blowback, and OpenAI’s announcement of the self-storage option, Anthropic this month introduced a similar program, which will begin rolling out in phases this fall, allowing eligible firms to store data related to their use of Fable within their own servers. Anthropic said it had developed the new system in collaboration with more than 100 customers, but others had to request access to it, and it retained a provision stating that the company can eliminate such an option at any time.

"We worry a little bit that [Fable] might be learning from some of our code," said Chief Technology Officer Bill Vass. “So when we're concerned about intellectual property in a very small number of cases, we're not using Anthropic in those cases.”

That’s a problem for Palantir, which provides Anthropic’s models to customers through its software for building customer AI applications. In what became a laborious process, Palantir executives convinced Anthropic to agree to make irrevocable ZDR guarantees across all models, according to a person familiar with the discussions.

Palantir’s Spicy Booklet

The June policy shift reignited those negotiations, and Palantir won’t make Fable available through its own software to clients until Anthropic provides ZDR assurances it can’t later revoke, a person familiar with the situation said. (Palantir customers who want to buy Fable directly from Anthropic can still do so.)

Palantir CEO Alex Karp said during a customer event last week that enterprises are tired of AI labs “abusing” them, and the company produced a booklet given to every attendee of the event, titled: “How to Avoid Transferring Your Alpha to a Hosted Model Provider.” The booklet advises Palantir customers how to negotiate ZDR with providers. (Palantir and some other OpenAI customers say they have gotten access to its GPT-6 Astra model with zero data retention, so Palantir is providing that model to customers.)

Nvidia, meanwhile, is only using Fable for tasks that involve less sensitive business data, such as those related to open-source software projects, because Anthropic hasn’t provided irrevocable ZDR-related guarantees.

“As a company, you know, we believe ZDR should be on by default,” said Justin Boitano, Nvidia’s vice president of enterprise AI.

For sensitive internal projects, such as AI-driven supply chain monitoring, Nvidia uses its proprietary Nemotron models. (Nvidia has invested in Anthropic, which is also a major user of Nvidia hardware to develop models.)

Defense contractor Booz Allen Hamilton has a similar point of view. Though it was one of the earliest users of Anthropic’s Mythos, which it used to examine its systems for potential cybersecurity vulnerabilities, the company has barred its employees from using the commercially available version of the model, Fable, in work involving the proprietary cybersecurity software it provides customers, due to Fable’s data retention policies.

Air-Gapped Servers

Meanwhile, an executive of a large U.S. utility said their organization abandoned plans to test Fable for running core power infrastructure serving millions of American households, after Anthropic refused to guarantee a nonrevocable ZDR contract. The utility still uses Anthropic for tasks related to finance and human resources, such as employee onboarding, this person said.

Some customers, such as Novo Nordisk, a global pharmaceutical leader, have long used Anthropic’s Claude to analyze public documentation and draft generic materials but enforce a strict ban against feeding proprietary data to such a model.

Similarly, aerospace giant Northrop Grumman has long opted to run open-source AI models on its own air-gapped servers (which don’t connect to the internet) for tasks like AI coding, rather than trust OpenAI and Anthropic, according to someone with knowledge of the situation.

Some teams within Northrop have used models from providers like Poolside and Luminary on the company’s own servers, turning to open-source AI models from Nvidia on air-gapped servers for internal tasks like generating and editing software code or aiding scientific research, this person said. The company has been hiring AI researchers from other firms to help with the effort, including former Microsoft AI researchers Fahad Khan and Praveen Palanisamy, who now help lead Northrop’s internal AI efforts.

A Northrop Grumman spokesperson said in a statement that “each AI use case is assessed for potential risk,” and that the company secures its AI use through “a robust security framework, monitoring, and even our infrastructure.”

This story has been updated to include additional comments from OpenAI.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论