According to media reports, companies like Nvidia, Palantir, and Booz Allen Hamilton have begun to restrict or consider ceasing the use of advanced AI models from Anthropic and OpenAI unless stricter data protection commitments are provided.
Several media outlets cited a report from The Information, stating that these three companies are setting stricter security restrictions on the use of cutting-edge AI models due to concerns about the leakage of sensitive business data and intellectual property.
Palantir has requested Anthropic to provide an irreversible “Zero Data Retention” (ZDR) guarantee before considering deploying Claude on its software platform. It also advised customers not to directly input sensitive intellectual property data into Anthropic or OpenAI’s AI models to avoid potential access by the model suppliers or use for other purposes. Palantir will not open access to related models to customers through its platform until Anthropic provides the required assurances.
Nvidia has restricted Anthropic models to lower sensitivity internal tasks and switched to its AI Nemotron for tasks involving business secrets. Booz Allen Hamilton has directly prohibited employees from using Anthropic’s commercial version Fable model in projects involving proprietary network security or customer data.
This wave of restriction actions is closely related to Anthropic’s adjustment of data retention policies for flagship models like Claude Fable 5 and Mythos 5 in June this year. The policy allows Anthropic to retain customer usage records (including prompts and output content) for up to 30 days, with the possibility of extension for content marked by security classifiers for security investigation or legal retention needs.
Anthropic stated that this policy was originally designed to detect complex attacks across multiple sessions and accounts, emphasizing that this data will not be used for AI training.
However, enterprise customers still consider such risks too high, especially in highly regulated industries such as defense, energy, pharmaceuticals, and cybersecurity.
To alleviate the pressure, Anthropic introduced the “Enterprise Frontier Safeguards Program,” allowing enterprises to store activity data used for security monitoring in their controlled cloud storage such as Amazon S3, Azure Blob, Google Cloud, with encryption keys managed by the customers. Anthropic’s employees will not read any data, but automatic scanning functions will continue.
OpenAI is also facing similar scrutiny. Previously, New York University professor and mathematician Tristan Buckmaster questioned OpenAI’s possible use of its stored Codex data to crack the Navier-Stokes equations.
The Navier-Stokes equations have long been used in studies such as aircraft design, weather forecasting, and blood flow, while the physics community has been exploring their applicability under extreme conditions.
While both AI companies have stated that they will not use customer data for model training by default (unless customers actively opt-in), they still collect anonymized metadata to enhance their products. This poses security concerns for cautious enterprises, leading to an increasing trend of seeking alternative solutions to avoid reliance on external AI suppliers.
Due to concerns about data retention, Nvidia and Palantir announced a partnership on September 10 to jointly launch a solution that combines Palantir software and Nvidia’s open-source Nemotron model. This deployment will first be within Nvidia’s own supply chain system, aiming to keep sensitive data within the customers’ controlled network.
Palantir CEO Alex Karp recently emphasized the importance of “sovereign AI” and “data sovereignty.” He believes that companies should run AI in their own environments to prevent leakage of critical business data to AI vendors.
David Friedberg, CEO of agricultural technology company Ohalo Genetics, mentioned in a podcast that they are transferring a large amount of sensitive data from Claude to local AI models as a precaution against data leakage concerns.
Moreover, some companies in defense, energy, and pharmaceutical industries are shifting towards deploying AI on proprietary servers or offline environments.
This wave of restriction actions reflects a shift in the AI market competition focus from AI performance to control of business secrets and security, aiming to achieve solutions that ensure “data remains in-house.”
(Reference: The Times of India and Reuters)
