Anthropic can override zero-data-retention rules

Stani Mihov
Founder & CEO
·

TL;DR
Vendor: Anthropic
Document: Service Specific Terms
Date detected: June 8, 2026
Key change: A new "Covered Models" category allows Anthropic to retain inputs, outputs and usage data for safety review, superseding stricter retention arrangements including zero-data-retention commitments
Anthropic updated its Service Specific Terms with a mechanism that lets it designate certain models as Covered Models and apply special retention rules to them. The same update narrows the previous assurance that marketplace integrations give Anthropic no access to customer environments on AWS Bedrock and Google Vertex.
The change
On June 8, 2026, Anthropic updated its Service Specific Terms with a new effective date. Venpo detected the change the same day.
Inside the revision sits a new contractual category called Covered Models. For any model Anthropic designates as covered, inputs, outputs and related usage data may be retained for safety review. The terms state that this applies even where stricter retention arrangements exist, including reduced-retention and zero-data-retention commitments.
Anthropic's models sit inside a large share of modern SaaS products, both through direct API usage and through cloud marketplaces, so a change to its retention framework reaches far beyond its direct customers.
What changed
Two shifts stand out in the updated document:
a new Covered Models category that allows retention of inputs, outputs and usage data for safety review, superseding stricter retention arrangements
an exception to the assurance that marketplace integrations give Anthropic no access to customer environments on AWS Bedrock and Google Vertex
The same revision also softened the Beta Services language: beta offerings are no longer described as definitely unsuitable for production use, only as possibly unsuitable.
Covered Models can supersede zero-data-retention commitments
Zero-data-retention arrangements have been one of the main mechanisms that allowed security and legal teams to approve AI vendors. The commitment was simple: prompts and outputs are not stored, so the data exposure question largely disappears.
The new Covered Models section changes the structure of that commitment. Anthropic may designate specific models as covered, and for those models it may keep inputs, outputs and other usage-related data for safety review. The terms are explicit that this overrides stricter retention arrangements that would otherwise apply.
The stated purpose is safety review, and the mechanism is written in plain sight in the terms. The practical consequence for customers is still significant: a retention commitment that can be superseded by a vendor-side designation behaves differently from an unconditional one, and any internal approval that relied on the unconditional version is now based on an outdated document.
The cloud marketplace assurance now has an exception
The previous terms stated that Anthropic's marketplace integration does not give it access to customer environments on AWS Bedrock or Google Vertex. That statement is no longer unconditional.
For Covered Models used through a cloud platform, related data may be processed by Anthropic under the applicable data processing terms, and the customer must confirm that arrangement to the marketplace provider. Teams that chose the Bedrock or Vertex route specifically to keep model traffic inside their own cloud boundary will want to re-read this section carefully.
One layer deeper: Databricks added Anthropic as a subprocessor
Two days after the terms update, on June 10, Venpo detected a related change in a different document: Databricks added Anthropic to its subprocessor list for AI-backed services.
This means the new Anthropic terms are relevant even for companies that never signed with Anthropic directly. When a platform vendor routes AI features through Anthropic, the retention framework described above now sits one layer deeper in the stack, where it is even less likely to be reviewed.
Anthropic's own Privacy Policy was updated in the same June 8 revision cycle, including a narrower description of the account-level training opt-out and new data categories for identity verification and study participation.
Why this matters
AI vendors have moved from the edge of the stack to its center in under two years, and their legal documents are changing at a pace that traditional annual vendor reviews were never designed for.
This change is a clear example of why point-in-time approval is not enough. The clause that anchored many security reviews did not disappear; it became conditional. A team that approved Anthropic in January and re-reads the terms next January will have spent months operating on assumptions the contract no longer supports. This is exactly the silent drift covered in our analysis of the hidden risk of vendor legal changes.
Potential impact for SaaS companies
Companies using Anthropic models directly or through cloud platforms may want to review whether:
their security and legal approval of Anthropic relied on zero-data-retention or reduced-retention commitments
any models they use are or become designated as Covered Models, and what retention applies in that case
their Bedrock or Vertex architecture assumptions still hold under the new marketplace exception
platform vendors in their stack, such as Databricks, now route data to Anthropic as a subprocessor
customer-facing privacy documentation and DPAs still accurately describe where AI data can flow
Even where the safety rationale is reasonable, the contractual structure has changed, and that belongs in a review rather than in a discovery during an audit. Structured vendor contract monitoring is what turns a change like this into an internal signal instead of a surprise.
How Venpo detected it
Venpo continuously monitors vendor legal documents and detects changes as soon as they are published. When Anthropic updated its Service Specific Terms, Venpo immediately:
detected the new effective date and the revised sections
identified the Covered Models category and its relationship to existing retention arrangements
flagged the narrowed cloud marketplace assurance as a material shift
connected the June 10 Databricks subprocessor addition to the same vendor
The full redline of the change is public on our live feed: Anthropic Service Specific Terms, June 8, 2026. Building continuous vendor risk monitoring into the compliance stack is what makes this kind of same-day detection possible.
Business outcome
Companies that caught this change early were able to:
re-check which of their AI workloads rely on zero-data-retention commitments before routing more data through them
ask Anthropic directly which models are designated as Covered Models under their agreements
review their Bedrock and Vertex assumptions with their cloud architecture teams
update vendor records to reflect Anthropic appearing as a subprocessor inside platform tools like Databricks
Instead of finding out during a customer security questionnaire or an audit, they had time to adapt on their own schedule.
Key takeaway
The most important clause in an AI vendor contract can change shape without disappearing. A zero-data-retention commitment that can be superseded by a vendor-side designation is a different commitment than the one most teams approved, and the only way to know it changed is to be watching the document when it happens. Venpo detected this change the day it was published and traced it one layer deeper into the stack two days later. A closer look at why scheduled reviews keep missing this kind of shift is in our analysis of manual vs automated vendor monitoring.
The change
On June 8, 2026, Anthropic updated its Service Specific Terms with a new effective date. Venpo detected the change the same day.
Inside the revision sits a new contractual category called Covered Models. For any model Anthropic designates as covered, inputs, outputs and related usage data may be retained for safety review. The terms state that this applies even where stricter retention arrangements exist, including reduced-retention and zero-data-retention commitments.
Anthropic's models sit inside a large share of modern SaaS products, both through direct API usage and through cloud marketplaces, so a change to its retention framework reaches far beyond its direct customers.
What changed
Two shifts stand out in the updated document:
a new Covered Models category that allows retention of inputs, outputs and usage data for safety review, superseding stricter retention arrangements
an exception to the assurance that marketplace integrations give Anthropic no access to customer environments on AWS Bedrock and Google Vertex
The same revision also softened the Beta Services language: beta offerings are no longer described as definitely unsuitable for production use, only as possibly unsuitable.
Covered Models can supersede zero-data-retention commitments
Zero-data-retention arrangements have been one of the main mechanisms that allowed security and legal teams to approve AI vendors. The commitment was simple: prompts and outputs are not stored, so the data exposure question largely disappears.
The new Covered Models section changes the structure of that commitment. Anthropic may designate specific models as covered, and for those models it may keep inputs, outputs and other usage-related data for safety review. The terms are explicit that this overrides stricter retention arrangements that would otherwise apply.
The stated purpose is safety review, and the mechanism is written in plain sight in the terms. The practical consequence for customers is still significant: a retention commitment that can be superseded by a vendor-side designation behaves differently from an unconditional one, and any internal approval that relied on the unconditional version is now based on an outdated document.
The cloud marketplace assurance now has an exception
The previous terms stated that Anthropic's marketplace integration does not give it access to customer environments on AWS Bedrock or Google Vertex. That statement is no longer unconditional.
For Covered Models used through a cloud platform, related data may be processed by Anthropic under the applicable data processing terms, and the customer must confirm that arrangement to the marketplace provider. Teams that chose the Bedrock or Vertex route specifically to keep model traffic inside their own cloud boundary will want to re-read this section carefully.
One layer deeper: Databricks added Anthropic as a subprocessor
Two days after the terms update, on June 10, Venpo detected a related change in a different document: Databricks added Anthropic to its subprocessor list for AI-backed services.
This means the new Anthropic terms are relevant even for companies that never signed with Anthropic directly. When a platform vendor routes AI features through Anthropic, the retention framework described above now sits one layer deeper in the stack, where it is even less likely to be reviewed.
Anthropic's own Privacy Policy was updated in the same June 8 revision cycle, including a narrower description of the account-level training opt-out and new data categories for identity verification and study participation.
Why this matters
AI vendors have moved from the edge of the stack to its center in under two years, and their legal documents are changing at a pace that traditional annual vendor reviews were never designed for.
This change is a clear example of why point-in-time approval is not enough. The clause that anchored many security reviews did not disappear; it became conditional. A team that approved Anthropic in January and re-reads the terms next January will have spent months operating on assumptions the contract no longer supports. This is exactly the silent drift covered in our analysis of the hidden risk of vendor legal changes.
Potential impact for SaaS companies
Companies using Anthropic models directly or through cloud platforms may want to review whether:
their security and legal approval of Anthropic relied on zero-data-retention or reduced-retention commitments
any models they use are or become designated as Covered Models, and what retention applies in that case
their Bedrock or Vertex architecture assumptions still hold under the new marketplace exception
platform vendors in their stack, such as Databricks, now route data to Anthropic as a subprocessor
customer-facing privacy documentation and DPAs still accurately describe where AI data can flow
Even where the safety rationale is reasonable, the contractual structure has changed, and that belongs in a review rather than in a discovery during an audit. Structured vendor contract monitoring is what turns a change like this into an internal signal instead of a surprise.
How Venpo detected it
Venpo continuously monitors vendor legal documents and detects changes as soon as they are published. When Anthropic updated its Service Specific Terms, Venpo immediately:
detected the new effective date and the revised sections
identified the Covered Models category and its relationship to existing retention arrangements
flagged the narrowed cloud marketplace assurance as a material shift
connected the June 10 Databricks subprocessor addition to the same vendor
The full redline of the change is public on our live feed: Anthropic Service Specific Terms, June 8, 2026. Building continuous vendor risk monitoring into the compliance stack is what makes this kind of same-day detection possible.
Business outcome
Companies that caught this change early were able to:
re-check which of their AI workloads rely on zero-data-retention commitments before routing more data through them
ask Anthropic directly which models are designated as Covered Models under their agreements
review their Bedrock and Vertex assumptions with their cloud architecture teams
update vendor records to reflect Anthropic appearing as a subprocessor inside platform tools like Databricks
Instead of finding out during a customer security questionnaire or an audit, they had time to adapt on their own schedule.
Key takeaway
The most important clause in an AI vendor contract can change shape without disappearing. A zero-data-retention commitment that can be superseded by a vendor-side designation is a different commitment than the one most teams approved, and the only way to know it changed is to be watching the document when it happens. Venpo detected this change the day it was published and traced it one layer deeper into the stack two days later. A closer look at why scheduled reviews keep missing this kind of shift is in our analysis of manual vs automated vendor monitoring.
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
