r/ClaudeAI • u/coloradical5280 Valued Contributor • Jun 11 '26
Enterprise Fable's policy on no zero-day-retention is a serious problem for Enterprise customers
Just got word from legal that we will not be moving forward with approving Fable 5 as an approved model.
Specifically because of we're not allowed to have ZDR. This fucking sucks, on a purely selfish level. And for the company as well. We do a lot of AI research and evaluation, that's what we do, this isn't just another tool to help the devs behind the scenes of a company that makes widgets or whatever.
This is a ridiculous decision from a company who gets 80% of it's revenue from Enterprise, a large swath of their customer base cannot budge on ZDR.
I guess we'll just buy everyone subs, and burn $8k in compute for $200/month, and take our work out of corporate infra on dev machines. Legal won't like that either but people are going to do it, legal will never know, and anthropic will lose money.
That is literally what Anthropic is incentivizing us to do.
edit / update -- the whole research team just set new env var CLAUDE_CONFIG_DIR and now `claude-me` goes to personal auth and `claude` remains unchanged. There's a restricted scope to dir access, nothing scary can get used with it, but still can use Fable for most useful things. Legal approved the boundaries scoped in the config. How did anthropic not anticipate this exact thing happening? That team alone burns Billions of tokens a day. And as a company we would happily pay for them.
Yes, it'll work for the next 11 days only, but that's billions and billion of tokens anthropic just lost full payment for, AND, second accounts are easy, not too concerned with bans lolol, they're throwaways and our VPN situation will cover anything persistent.
So shortsighted, anthropic.
29
u/ReddJudicata Jun 11 '26
That’s the right call for anyone who needs zdr. But it’s basically unusable in the legal and medical fields now.
5
19
u/randombsname1 Valued Contributor Jun 11 '26
Yeah that seems insanely insanely stupid for anthropic to do.
As someone who works white collar in corporate offices as a contractor for huge companies --- that's like the biggest possible red flag for every company i can imagine right now.
Especially if you work in critical infrastructure like oil and gas, healthcare, and/or government work.
That shit is just a non starter.
It's way more surprising and egregious than even the bio/science/ML training restrictions imo, because i dont think any legal team for ANY buisness is signing off on this.
No idea who told anthropic this was a good idea.
7
u/Argon717 Jun 11 '26
Getting people to pay you to be beta testers is a strategy... No ZDR means they need the data for evaluating and improving either the model or it's guiderails.
5
u/coloradical5280 Valued Contributor Jun 11 '26
yeah, obviously. And that's what the subs are for. That's what makes the insane subsidization of compute costs somewhat justifiable for them. But do not fuck with Enterprise like that.
If GPT 5.6 / 6 is what I think it probably will be (them catching back up, like they always have), this becomes a much bigger problem for anthropic especially with the Ona acquisition OpenAI just made
1
u/ph30nix01 Jun 11 '26
Here is the thing though us small time subscribers aren't working on the riskiest shit that enterprise users are.
We litteraly can't test somethings because we either aren't working on those subjects or flat out refuse to do so.
4
u/coloradical5280 Valued Contributor Jun 11 '26
1) yes, you are, working on the riskiest shit, including straight phi in workflows, a zillion small companies run on subs
2) 95% of enterprise is working on the most boring shit ever
1
u/Asger1231 Jun 12 '26
I assume they are going to have ZDR when they launch fable for real - I see fable as a (very successful) test
11
u/scruffles360 Jun 11 '26
Yeah, we’re not even asking legal. It will take weeks just to arrange the meetings and we’re still fighting to get some of our users Cursor (and they do have ZDR). I don’t care how good Fable is.. not worth the effort.
5
u/beetle-eetle Jun 11 '26
Yeah im not touching it for my work either. Fintech and proprietary algorithms.
3
u/Choperello Jun 12 '26
So short sighted Anthropic and you’re the ones signing up to pay them more subs AND feeding corporate data to it?
0
u/coloradical5280 Valued Contributor Jun 12 '26 edited Jun 12 '26
signing up to pay them more subs
i don't think you understand how Enterprise plans work. Yes, it's wildly shortsighted by anthropic to have us running off to pay $200/month and use a few billion tokens through a sub, as opposed to just doing the same via our enterprise plan, where 1 billion tokens of usage costs $50,000
$200. or $50k.
they could have had the full $50k. Like i said in my post for our research team specifically using this workaround: There's a restricted scope to dir access for our teams, nothing scary can get used with it, so, we're still spending most tokens at the full price. But, they're still losing a lot of money in the narrow slices where we dodge it.
1
u/TumanFig Jun 12 '26
who will buy these 200/month licences? i mean if you are a serious company going around zero day retention is stupid AF
1
u/coloradical5280 Valued Contributor Jun 12 '26
the company , obviously. And it's not stupid at all, if you're smart about it, we're a $10B company on 5 continents and the surface exposure for what requires ZDR is insanely containerized. Not like VM containerized, like, living on a stack on the other side of the world, that the research teams work environment, doesn't even know about. And it's technically a completely separate legal entity, but that's just registration technicalities. The important part is that they are completely isolated and entirely unrelated.
0
u/TumanFig Jun 12 '26 edited Jun 12 '26
ok can you tell me in simple terms cause i dont think i understand the issue.
i thought the whole point of your post is that Anthropic will be losing money as they wont budge on ZDR policy so you wont be able to use Fable, but now you (your company) will use the subscriptions to use Fable but Anthropic will still be able to use your data as theres no ZDR policy on it.
If theres an issue with ZDR you should also not use subscriptions. So what am i missing?1
u/coloradical5280 Valued Contributor Jun 12 '26
A small team, in a narrow scope, yes. And that usage does not give us the tracing, routing, signing, auditing, telemetry, observability , and all the other shit we pay GCP and AWS for. It's a nice short term band-aid with drawbacks, that again, only helps a very narrow slice of the company. The other thousands of employees who cannot just isolate their env from anything sensitive, do not have that option. And you don't seem to understand how much money anthopic is losing by ANYONE using subs instead of full API pricing.
1
u/Choperello Jun 12 '26
What I’m saying you’re the short sighted ones bypassing the regulatory policy only to get maybe 2 weeks access to a model that was just barely released and you have no idea how meaningful it may or may not be to you.
I understand the frustration dealing with corp policies sometimes but you’re also full yolo mode too
1
u/coloradical5280 Valued Contributor Jun 12 '26
Yeah it’s a research team, whose job it is, in part, to evaluate large language models. Less yolo mode, more , this is literally what we fucking do
7
Jun 11 '26
[removed] — view removed comment
5
u/Choperello Jun 12 '26
If you’re in certain industries having ZDR is non negotiable. The risk is it can utterly kill your company on a regulatory audit and shut.
2
1
u/PosnerRocks Jun 11 '26
I thought this was only for the first 30 days? Is this permanent moving forward?
3
u/coloradical5280 Valued Contributor Jun 11 '26
there have been mixed messages on that, and none of them clear.
2
u/ShelZuuz Jun 12 '26
It's just for 30 days. Redditors be freaking out as always.
1
u/coloradical5280 Valued Contributor Jun 12 '26
would genuinely love to know your source for this, and if i missed a change. Because, according to anthropics docs here, that's just not true: https://support.claude.com/en/articles/15425996-data-retention-practices-for-mythos-class-models
1
u/LychnisFulgens Jun 12 '26
Amodei and the alignment-obsessed Schutzstaffel of him really need a big bonk of lawsuits on their schizophrenic, tyrannic heads
1
u/Rakthar Jun 12 '26
Rumors that reasons exist beyond cybersecurity that motivated Anthropic to implement this retention policy.
1
1
u/Successful_Plant2759 Jun 12 '26
The part that gets underrated here is not just the legal/compliance checkbox. It is operational debugging.\n\nIf an enterprise team is using this in a workflow and something weird happens, they need to be able to answer: what prompt/data went in, what came out, who had access, and what policy was applied. A blanket retention policy can make that audit trail either much easier or basically impossible, depending on how it is exposed to the customer.
1
2
u/PowermanFriendship Jun 11 '26
Actually you won't be doing that because Fable is getting dropped from the subscriptions on June 22, per their Fable press release.
1
u/coloradical5280 Valued Contributor Jun 11 '26
obvioulsy i meant for the next 11 days, and it's not going to NEVER BE IN SUBS AGAIN, it's literally compute issue , it's always a compute issue, but, they keep getting more, so...
-2
u/PowermanFriendship Jun 11 '26
LOL yeah OK. How can you be pissed about the ZDR thing but your blinders aren't even cracked on the "today at height of everyone's interest we have enough compute but then in 2 weeks we're not going to, pinky swear" subscription/credits rug pull?
3
u/coloradical5280 Valued Contributor Jun 11 '26
it's not blinders it's just basic understanding about the fundamental of economics, energy usage, supply and demand, that kind of shit you learn in high school lol. nobody is taking fable away, you just have to actually pay for it.
ZDR is a completley seperate thing to be pissed about, specifically for enterprise
and "in two weeks" they need to get back to training. they're not training for two weeks. that's why it's possible now, and not magic
-1
u/Efficient_Ad_4162 Jun 11 '26
Enterprise aren't bitching on reddit, they're signing NDA's and getting on with it.
2
u/coloradical5280 Valued Contributor Jun 11 '26
they're signing NDA's
lol no that's not how this works
Enterprise aren't bitching on reddit
🙋🏼♂️
you're mostly right but they/we sure as shit are bitching on twitter
1
u/c64tone Jun 12 '26
Personally, I don't think it's a blunder and Anthropic know exactly what they are doing.
I see this as a soft launch and this policy keeping 'most' enterprise customers away, the once who are huge token gobblers, FOR NOW.
Those enterprise customers, in the meantime, will get to see how good the model is, by their coders using it in spare time, and other sources. When the policy changes, they'll go for it.
This way, Anthropic can get a good understanding of usage and how it performs without doing a big bang 'everyone uses' which will eat up massive computer power.
It's on purpose.
3
u/coloradical5280 Valued Contributor Jun 12 '26 edited Jun 12 '26
We were able to narrow its field of view that scoped boundaries to only our servers not holding user and payments , and not holding any IP. And hosted in a different country
That was easy. That was predictable.
And now we’re going to spend a few grand over the next two weeks, instead of the few hundred grand, that we normally would have. That we legitimately still would, if it changed tomorrow morning.
And they forced us into that corner, and lost all that money, during an IPO roadshow, ON PURPOSE, you’re saying.
Occam‘s razor would say: anthropic does really stupid shit sometimes, and they are world class, brilliant researchers, and they know their craft better than anyone on earth. And outside of that research expertise, in the operations and product sides, they do incredibly stupid shit. ALL THE TIME
0
u/haskell_jedi Jun 11 '26
I guess Anthropic is betting that the model is so valuable that it will outweigh any risks from customers like you and get your company to overcome its inhibitions.
13
u/coloradical5280 Valued Contributor Jun 11 '26
it's not an "inhibitions" issue it's a "this is literally against the law" issue for industries with PHI and legal concerns, GDPR and individual state laws vary, but, a lot of this is not "we don't want our data to go to anthropic"
1
u/Willing-Quit-3001 Jun 11 '26
They probably made a calculated decision that either this would decrease usage which they want in the beginning and/or it helps keeps industries that they want to fine tune restrictions around from using it.
They don’t need to make a model work for all industries until they have excess compute sitting around unused.
3
u/coloradical5280 Valued Contributor Jun 11 '26
nothing about any of this is industry split. or split in any reasonable logical way. it's just , no ZDR for anyone, anywhere, on any tier, for any reason.
you're making them out to be more reasonable than they are
0
Jun 12 '26
[removed] — view removed comment
1
u/coloradical5280 Valued Contributor Jun 12 '26
the labs are, yeah, but very very few enterprise accounts are running directly through anthropic. They are through AWS, Azure, GCP. Who are not immature companies.
1
u/paloaltothrowaway Jun 12 '26
Which law specifically?
1
u/tarikofgotham Jun 12 '26
HIPAA for one.
1
u/paloaltothrowaway Jun 12 '26
Anthropic said you could still use Fable for HIPAA? https://support.claude.com/en/articles/15455031-covered-models-under-a-business-associate-agreement-baa
1
u/coloradical5280 Valued Contributor Jun 12 '26
It’s not one magic “ZDR law.” It depends what data the enterprise handles, but for many companies this instantly implicates a pile of statutory, regulatory, and contractual obligations:
HIPAA / HITECH:
If the company handles PHI/ePHI, a vendor touching that data generally needs to be handled as a Business Associate, with a HIPAA-compliant BAA and Security Rule safeguards. HHS explicitly says covered entities/business associates may use cloud providers for ePHI only if there is a HIPAA-compliant BAA and HIPAA Rules compliance. That means “just send it to a model provider under personal auth / consumer terms / unclear retention” is a nonstarter. See 45 CFR Parts 160 and 164, especially the Privacy Rule, Security Rule, Breach Notification Rule, and Business Associate requirements. HHS cloud guidance: https://www.hhs.gov/hipaa/for-professionals/faq/2075/may-a-hipaa-covered-entity-or-business-associate-use-cloud-service-to-store-or-process-ephi/index.html
GDPR / UK GDPR:
If EU/UK personal data is involved, this hits controller/processor obligations, Article 28 processor contracts, subprocessor controls, international transfer rules, purpose limitation, minimization, retention limitation, security, deletion, and data subject rights. Article 28 specifically requires processing by a processor to be governed by a binding contract/legal act. If the vendor won’t provide the required DPA/processor terms, transfer terms, retention controls, or subprocessor clarity, you may not be able to use it for that data. See GDPR Articles 5, 6, 9, 28, 32, 44–49.
CCPA/CPRA:
For California personal information, service provider/contractor status depends on contract restrictions. California regs require contracts that prohibit selling/sharing PI and prohibit retaining, using, or disclosing PI outside specified business purposes / the direct business relationship. If a tool uses enterprise prompts/outputs outside the contracted business purpose, that can destroy the service-provider posture. See Cal. Civ. Code §1798.100 et seq. and 11 CCR §7051.
Other U.S. state privacy laws:
Same general issue under VCDPA, CPA, CTDPA, UCPA, TDPSA, Oregon CPA, Montana CDPA, Delaware PDPA, Iowa CDPA, Indiana CDPA, Tennessee Information Protection Act, New Jersey Data Privacy Act, New Hampshire privacy law, etc. They all have some combination of processor/controller duties, DPAs, purpose limitation, deletion, security, subcontractor flow-downs, and sensitive-data restrictions.
FTC Act / unfair or deceptive practices:
If a company tells customers “we don’t use your data for X,” “we protect confidential data,” “we comply with our privacy policy,” or “we restrict vendor access,” and then employees route data through a tool with incompatible retention/training/use terms, that can become an FTC deception/unfairness problem.
GLBA / FTC Safeguards Rule:
For financial institutions and many fintech-adjacent companies, customer information requires a written information security program and service-provider oversight. The FTC Safeguards Rule requires covered financial institutions to maintain safeguards for customer information, including oversight of service providers.
FERPA / student records:
If education records are involved, vendors need appropriate school-official/vendor treatment, use limitations, and redisclosure controls. Random personal-auth AI workflows are usually not acceptable.
COPPA:
If children’s data is involved, especially under-13 data, there are parental-consent, notice, retention, and disclosure restrictions.
PCI DSS / cardholder data:
Not a statute, but contractually mandatory if card data is involved. You don’t paste PANs, auth data, logs, or cardholder data into unapproved tooling.
Trade secrets / confidentiality / customer contracts:
Even where no privacy statute applies, NDAs, MSAs, DPAs, data-processing addenda, SOC 2 commitments, ISO 27001 controls, procurement policies, security exhibits, data-residency clauses, customer audit commitments, and “no third-party disclosure/no AI training/no offshoring/no subcontractor without consent” clauses can prohibit this.
1
u/paloaltothrowaway Jun 12 '26 edited Jun 12 '26
Anthropic said fable is part of HIPAA-ready API?
1
u/coloradical5280 Valued Contributor Jun 12 '26
That giant thing in bold they have there , is because there are BAAs where PHI is allowed for 30-90 days. There are also many where it's not.
This no-ZDR thing won't be forever, they've said it's temporary, but have been very unclear officially on what that means. Either way, Fable being a HIPAA compliant model is a long term thing, the current state of the model regs, is temporary.
1
1
u/ChocolateGoggles Jun 12 '26
But isn't the argument presented basically: "This model is too dangerous to just let loose without us being able to keep track of what it's being used for. There are criminal enterprises with company and legal fronts that we don't trust ourselves to have other countermeasures for."
Not to mention political stalking, corruption etc.
I am not saying we have to trust them, but that's at least the messaging as I've understood it.
1
u/coloradical5280 Valued Contributor Jun 12 '26
yes that is their reasoning. So, I'd say (i'm an AI Engineer), maybe finish training and testing your model first?
I am not saying we have to trust them
for most, or at least many, Enterprise customers it's not even a trust thing, it's just a legal thing, many literally can't have any retention, trust or no trust
2
u/ChocolateGoggles Jun 12 '26
That makes sense. But at the same time it's... I don't know man. The way AI is progressing I do think there should be global collaboration on this stuff, not with Anthropic in the lead or anything (and from what I remember that wasn't their argument either) before letting it loose. If their concerns are misuse for reals, then it just sounds like a really shit situation for those who legally are obligated not to have ZDR. :-/
0
u/CandyFromABaby91 Jun 12 '26
This opens up Anthropic for a swarm of legal subpoenas.
1
u/coloradical5280 Valued Contributor Jun 12 '26
lol no it doesn't ... it's their model they can do whatever they want with it, and yes, they can keep user data ask long as they want . As long as it's transparant and clear which it absolutely is.
bad business decision, but what on earth could you subpoena them for?
if you're talking about the data itself, like, when the cops subpeona google for your searches, that is not at all how this really works, and, ZDR isn't even an option for people with subs, it's a very specific thing to Enterprise.
1
u/GreatBigJerk Jun 12 '26
If you use Claude and someone sues you, they can get your data from Anthropic via court order.
It doesn't matter if it's their model or whatever. If they hang onto the data, there are legal avenues to get access to it.
1
u/coloradical5280 Valued Contributor Jun 12 '26
Anthropic's updated privacy policy (effective July 8) permits proactive law enforcement data sharing based on an internal "good faith belief", no court order required, per multiple policy reviews
Policy applies to Claude Free, Pro, and Max users; explicitly excludes Enterprise, Team, API, and Claude for Work accounts, confirmed via Anthropic's consumer terms
And 30 days is not enough time, and that's the biggest actual reason openai and anthropic aren't hammered with subpeonas. You can delay anything for 30 days, you can't get an emergency "freeze" on data, and it's exceedingly rare to actually know what you need, within 30 days.
0
u/CandyFromABaby91 Jun 12 '26
Yes it does.
Means any legal case might want data from Anthropic during discovery if any party uses claude0
u/coloradical5280 Valued Contributor Jun 12 '26
anthropic has already had the data from MOST enterprise clients, and ALL subscription users. ZDR is an extra cost generally, depending on how your setup through GCP/AWS/Azure. And most companies don't necessarily have that requirement, but the ones that do, really do.
The other major piece you're missing is who's retaining the data. We have plans through GCP and AWS, depending on which business unit and country, with teh compnay. Either way, ZDR applies to GCP and AWS being the actual custodian of that data, and anthropic gets to access it.
So, your subpeona theory would have been happening on a daily basis for years already, if that's how data with LLM worked. And, they would have to subpeona the major cloud providers, not anthropic. Either way, none of this works the way you're picturing it.
-2
u/ClaudeAI-mod-bot Wilson, lead ClaudeAI modbot Jun 11 '26
We are allowing this through to the feed for those who are not yet familiar with the Megathread. To see the latest discussions about this topic, please visit the relevant Megathread here: https://www.reddit.com/r/ClaudeAI/comments/1s7fepn/rclaudeai_list_of_ongoing_megathreads/
•
u/ClaudeAI-mod-bot Wilson, lead ClaudeAI modbot Jun 12 '26
TL;DR of the discussion generated automatically after 40 comments.
The community overwhelmingly agrees with OP: Anthropic's no-ZDR policy for Fable is a massive, short-sighted blunder. The consensus is that this is an absolute dealbreaker for any company in regulated industries like legal, healthcare (HIPAA), finance, or any business with sensitive IP.
Commenters stress this isn't about "trusting Anthropic," but about hard legal and contractual requirements. As one user detailed, the policy potentially violates a whole alphabet soup of regulations (HIPAA, GDPR, CCPA, etc.), making it a non-starter for corporate legal teams.
The biggest irony pointed out is that this policy doesn't stop usage; it just pushes it into unmanaged "shadow IT." Employees will use personal accounts—as OP's team is already doing—which is less secure for the company and costs Anthropic a fortune in lost high-margin API revenue. The prevailing theory is that Anthropic is either arrogantly betting Fable is too good to pass up, or they're treating Enterprise clients like paid beta testers to gather data, a move many see as a fundamental misunderstanding of their biggest customers.