9 ms·
Anthropic requires 30 day data retention for Fable and Mythos
https://www.theverge.com/report/947575/microsoft-claude-fable-5-restricted-internally https://www.theverge.com/report/947575/microsoft-claude-fabl...
- matheusmoreira 4mo agoPretty incredible just how much good will Anthropic managed to burn.
- shusaku 4mo agoAre they really burning good will? For many users this is a deal breaker. But for the general public, politicians, etc they’re stamping “safety” on their brand.
- matheusmoreira 4mo agoSurveillance is always advanced as a safety measure.
- mountainriver 4mo agoCan’t wait till that turns into “regulatory capture”
- philipallstar 4mo agoOnly if there are corrupt regulators.
- matheusmoreira 4mo agoThat's a given.
- deleted 4mo ago[deleted]
- dang 4mo agoRelated ongoing thread: AWS Bedrock to require sharing data with Anthropic for Mythos and future models - https://news.ycombinator.com/item?id=48473166 https://news.ycombinator.com/item?id=48473166 - June 2026 (223 comments)
- pseudosavant 4mo agoIt is actually worse than that. It is at least 30 days. There is an "almost" that is doing a ton of heavy lifting here "deletion after 30 days in almost all cases". My read of that is they can hang onto data for as long as they want, even if they usually won't. And "all traffic" with an agentic harness is basically your entire codebase you work on. > We will require 30-day retention for all traffic on Mythos-class models, on both first- and third-party surfaces. We won’t use this data to train new Claude models, or for any non-safety-related purpose, and we’ve instituted new privacy protections including logging all human access to the data and ensuring its deletion after 30 days in almost all cases (see this post for further details). The data will help us defend against complex and novel attacks (including new jailbreaks and attacks that operate across many requests) as well as help us identify and reduce false positives.
- bagels 4mo agoHow were they not already auditing access to customer data?
- codebje 4mo agoThey were not keeping it beyond the timeframe necessary for the model to process it, so there wasn't access there to audit.
- bethekidyouwant 4mo agoEven worse when you git push something Microsoft gets all your code!
- layer8 4mo agoOnly if you push it to GitHub.
- tcp_handshaker 4mo agoThat is why, for the last five years I have been checking in with them, code with some of the most atrocious quality. So far...its working....
- catigula 4mo agoThen don’t use it.
- kccqzy 4mo agoThat’s exactly what my employer had communicated. It will not be allowed.
- ai-x 4mo agoStep 1: Find all companies which refuses/bans to use SOTA models from irrational fear. Step 2: Use SOTA models to copy them and crush them Step 3: Profit. (Yes, not every business is easily replicable, but you sure can find some)
- applfanboysbgon 4mo agoCan you name a single example of a business that has been replaced by another business leveraging LLMs to copy and "crush" their software?
- pbgcp2026 4mo agoPretty much any Chinese business. (Except takeouts and laundries)
- deleted 4mo ago[deleted]
- Wowfunhappy 4mo agoStep 4, get sued because you violated an NDA or other regulation?
- ai-x 4mo agoI'm not talking about Claude copying. I'm talking about scouring Twitter/LinkedIn and look at posts from employees who say SOTA model is banned. Look at what the business do. Copy it using SOTA. Call their clients with 30% discount and faster turnaround and higher quality product. It is complicated, but I can get Private Equity of even VCs to fund this idea. tl;dr -- I'm actually agreeing with you. Anthropic will never copy your business model due to NDA. But there are plenty of fearmongering about they copying you and because of which you won't use their models. If their models are genuinely SOTA you can use that information to your advantage and crush scaredy-cats. Edit: The fact that these get downvoted is exactly the reason why it's easy to win
- thekevan 4mo agoSo if you are under an NDA, does this violate it? I guess the better question would be if you are under and NDA and using an online model, are you already violating it but does this violate it further?
- FiloSottile 4mo agoIn the same way that using Gmail and Dropbox and iCloud and Notion violates it. (Which IANAL but for most NDAs would be not at all.)
- layer8 4mo agoI never had an NDA permit such usage.
- FiloSottile 4mo agoYour NDAs prohibit emailing a colleague about the e.g. project, or discussing it in a Slack DM with the client, or tracking progress on it in JIRA? You have to do NDA’d work exclusively with local tools or end-to-end encryption? Those are some difficult NDAs!
- layer8 4mo agoWe use inhouse on-premises email, issue tracking, and messaging. Depending on the project, external communication does require E2EE email. Development happens on local hardware and software unless required otherwise by the customer.
- FiloSottile 4mo agoI’m pretty sure (even just based on the revenue of various SaaS products) that’s not typical, hence “most NDAs”. I’m also sure some require a SCIF, but that’s not most of them.
- 4mo ago
- lvl155 4mo agoI actually think that’s warranted. And if you used it to poke around, you would also agree.
- unshavedyak 4mo ago> And if you used it to poke around, you would also agree. Would you elaborate? Not sure what you're describing
- anigbrowl 4mo agoAll he pre-publicity from Anthropic was about how it was amazing at finding security vulnerabilities, so it's not a stretch to think that some people would want to exploit that for nefarious purposes.
- charcircuit 4mo agoPretty much all malware is going to be fed into a compiler, but I don't agree that compilers should store a copy of your code base for 30 days to try and combat it. Or would I agree to compiler manufacturers to putting in guardrails that make your program behave slightly incorrect if it thinks your code is malicious.
- msuniverse2026 4mo agoI just gave it the prompt 'make a GUI for fluidx3d' and it did it in one shot without any oversight. It is incredible.
- connorboyle 4mo agoA startup that uses agentic coding tools such as Claude Code or Codex is packaging up their entire codebase and sending it directly to their LM provider. Depending on their product, they might be sending it directly to a potential competitor. Odd times we are living in!
- drchaim 4mo agoand all their keys, because sooner or later, the harness is gonna read them
- ai-x 4mo agoOne company's irrational fear is a competitive advantage for someone else.
- fastball 4mo agoClaude code is actually very good at not reading your keys these days.
- drchaim 4mo agoNot the case for me. I tried .envs, ansible-vault and sops, and it always ends up reading the unencrypted ones for some reason, usually in debugging sessions, it finds a way to read them.
- fastball 4mo agoWell it reads them, but (at least for me) it reads them in a way where it filters out the actual key values.
- ai-x 4mo agopeople over-rate how much software/IP is useful in running a successful business. There are genuinely very few IP in this world that needs to be protected. Everyone else is running stupid CRUD apps They also over index fear of LargeCo stealing IP from SmallCo. In fact, LargeCo is typically more scared about even the possibility of any product team looking at competitor internals due to lawsuits.
- hmokiguess 4mo agoGoogle Cloud also makes you accept this safety addendum to deploy Fable 5 via their Model Garden https://cloud.google.com/terms/advanced-ai-safety-addendum https://cloud.google.com/terms/advanced-ai-safety-addendum
- keithnz 4mo agothe real risk is using it at all as you are already sending them your data. If you are ok with that, then this retention/review seems ok.
- Daedren 4mo agoFrom a personal use perspective yes, the big issue here is enterprise and existing contracts as surely most companies will have signed zero retention.
- pbgcp2026 4mo agoThere were two (expensive) exceptions / alternatives so far: Bedrock and Vertex. Their Zero Data Retention was in fact contractually enforced. Now it is all f...d because of these morons at Anthropic. For now I am better off just using DS via their API. This is just a tragic moment for Tech. We just killed AI privacy. OpenAI already follows this trend and others will do too. The only hope now is ... tada .. Mistral LOL
- osti 4mo agoHmmm no? The only way is to deploy your own local model, using anyone else's you are at their whim on what happens to your data.
- dannyw 4mo agoIt’s not binary. With AWS previously you have contractual guarantees with a third party, that’s been in business for a couple decades, which explicitly state zero seconds of data retention - only as long as needed for inference. Consider the security angle too. You now have to rely on Anthropic’s infrastructure security. You did not previously when you used Bedrock/Vertex/etc.
- kube-system 4mo agoAnd blindly trust thousands of unknown python developers? The only way to really be sure is to build it from scratch starting with your own silicon wafers. But for those who are a little more pragmatic, AWS has a good track record of fulfilling their promises.
- deleted 4mo ago[deleted]
- sorry_outta_gas 4mo ago[dead]
- Sol- 4mo agoFortunately I can't use Fable anyway, since their hyperactive content flaggers do not let you work on anything remotely biological or medical related (i.e. parse a CSV with some medical content, nope, you're probably a bioterrorist) and you get downgraded to Opus immediately.
- pbgcp2026 4mo ago[flagged]
- solenoid0937 4mo agoIt's good they're being overcautious here. The alternative is far worse.
- airstrike 4mo agoWill someone think of the children
- siva7 4mo agoThe alternative of... saving lives?
- anigbrowl 4mo agoThey don't want the real risk of someone using it to make biological or genetically targeted weapons, and they don't want the social risk of someone asking it a bunch of leading questions in order to 'prove' some racist thesis or to 'prove' Mythos is woke if it declines to along with their performative inquiry. Let's face it, if some rando comes up to and asks if you have a few minutes to talk about population biology there's a good chance they're a kook.
- baq 4mo agoIt doesn’t take too much apparently to tweak a virus
- SepiaSapient 4mo ago
- pbgcp2026 4mo agoAll I can say to my team (and my clients): "f...k Anthropic". They've just put both Bedrock and Vertex on slippery slope of "we don't collect your prompts. period. ... comma ... except ..." Right now we have changed the code of all our agents to data retention mode 'none' (Note: not "default" or "inherited", this is not enough now!) and we are fighting with GCP doco to set similar things for Vertex. This is just terrible.
- Vortex777 4mo agoI mean not just the part 30 days data retention but I think the serious trade of this product is just the token efficiency. They trade it for precision. The claims that they make that it found a 30 year software bug from millions of lines of code is just precision. To human it's looks like a lot but for it it's just the ablity to process (token processing). Let's see how long it runs. Peace.
- topaitools_xyz 4mo ago[flagged]
- zb3 4mo agoWhat an annoying company, I wish it didn't exist..
- giancarlostoro 4mo agoYeah I'm never using either one, and if that becomes standard Anthropic will never see a dime from me again. I'm going to draw the line in the sand right there.
- samuelknight 4mo agoAnd by Fable they really mean Opus 4.8, because every mundane workflow or chat I try to use it in will eventually drop to Opus.
- buzer 4mo agoMentioned in the earlier, topic as well, but one very important point here is that it looks like Anthropic is becoming GDPR controller for all submitted data for this model (when they are in GDPR scope anyway). So data subjects would have Article 15 right to request information about processing and possibly a copy of the data. Latter might be contested under "rights of others", but former is more absolute. What this means it that if someone makes an Article 15 request, they would be entitled to know if Anthropic holds personal data about them and also from who they received this data at minimum. If someone wants to do that, I would recommend combining it with Article 18 request to forbid deleting the data for legal claim in case you contest Anthropic's reply. Otherwise they could just delete the data per their retention policy and DPA would find much later that they no longer hold the data. Another issue here is that their DPA frames everything as controller-to-processor, i.e. they do not appear to have SCCs in place to actually receive this personal data as controller. So the original exporter would likely also be in breach if they send any GDPR covered personal data to this model.
- zoobab 4mo agoStoring personal information about you give you the right to delete it as well?
- buzer 4mo agoYou have right to ask for it, but it doesn't guarantee that they will do it. It's also limited to data they hold as controller (i.e. the copy they hold for "safety" purposes), not the original copy that is controlled by customer. For that you will need to contact the source.
- OkWing99 4mo agoI remember the "Don't be evil" days from Google. At some point most morals change with enough money.
- crazylogger 4mo agoDidn’t they all but admit they’ve been storing and actively looking at requests with this post: https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks https://www.anthropic.com/news/detecting-and-preventing-dist... ? If they weren’t storing, they’d be oblivious to what customers are doing, making this kind of detection impossible. What data did they train their classifier on, if not real user (distiller) traffic?
- deleted 4mo ago[deleted]
- cowsandmilk 4mo agoWhy can’t they have trained the classifier on internal red teaming?
- crazylogger 4mo agoThey basically said "Deepseek ran 150,000 requests and here's the gist of one of their prompts". Anthropic doesn't know which accounts are Deepseek proxies beforehand, so definitely sounds like retrospective analysis of broad user logs to me. Of course Anthropic realizes saying this straight is problematic so they said they examined request metadata, but no, I don't think they can get this kind of insight from metadata (token counts, request time, etc.)
- throwaway85825 4mo agoGiven the model intelligence plateau and public data exhaustion the only way to improve in customer use cases is by training the model on customer data.
- borissk 4mo agoIf this is true, than Anthropic, Google and maybe OpenAI models will keep getting better and better and everyone else will be left in the dust - as they won't have access to so much customer data.
- hun3 4mo agoChina has proxies that sell cheaper access to frontier models in exchange for permission to train on your data.
- throwaway85825 4mo agoThers no way to not leak customer data if they try to train a bigger foundation model.
- abofh 4mo agoLawyers are gonna be making this a legal quagmire for years. Even after it gets retracted.
- kingcauchy 4mo ago« Trust us, we’re doing this for the good of humanity » (fills pockets with stock value and externalities from data center polloution) « No seriously trust us , at least we’re not Sam Altman » Update: « Oh and we’re the only ones who will stop AI from turning into SkyNet and eating your babies, you just have to pay us to make sure we invent SkyNet first »
- IFC_LLC 4mo agoAnthropic is desperate for the IPO and will release a half-baked product that they are so afraid to release, you can literally feel the shiver through the text of their press-release. Now they want to have any way of either fixing it, or in case someone will actually make a big boo-boo with their model, to be able to blame the guy in the end.
- cmiles8 4mo agoThis will likely get it banned with many/most corporate customer. They generally have zero tolerance for such things.
- smrtinsert 4mo agoI am definitely for services respecting customer privacy, but I can't help if this is different. I recently saw a thread where a person was bragging that frontier providers were blocking their attempt at what looked like to be social media de-anonymization and blackmailing app. Maybe this isn't different than using something like Google Sheets to keep a list of people to dox and blackmail, but the leverage certainly makes it feel different.
- tmaly 4mo agoThis could be a big issue for firms with strict GDPR criteria: "This change only applies to organizations that have set up workspaces with zero data retention (ZDR) in Claude Console, use Claude Code with ZDR in Claude Enterprise, or access Claude through AWS Bedrock, Google Cloud Agent Platform, or Microsoft Foundry with ZDR. The rest of this article applies only to these organizations."
- rainbow13 4mo agoThis company is so smug lol, they think it's ok to bomb kids in Iran but don't let people do some biological research
- poopiokaka 4mo ago[dead]
- Topology1 4mo agoI thought they previous refused to help with war efforts earlier?
- wyrdcurt 4mo agoThey refused to allow autonomous weapons and domestic surveillance. They were fine with use in weapons with a human in-the-loop and with surveilling non-US nations.
- Paracompact 4mo agoThey only complained about using it for autonomous warfare and domestic surveillance. They were not as hawkish as OpenAI, but by no means a dove.
- calgoo 4mo agoAlso, dont forget the ~50 people killed in venuzuela when they attacked there. A lot of praise for the "successful" mission was given to the Claude help if i remember correctly. https://www.theguardian.com/technology/2026/feb/14/us-military-anthropic-ai-model-claude-venezuela-raid https://www.theguardian.com/technology/2026/feb/14/us-milita...
- sneak 4mo agoReminder: FISA Section 702, aka FAA702, aka PRISM, aka the #1 most used collection source by the US IC, allows *warrantless* realtime access for the US federal government to everything Anthropic, OpenAI, Google, Apple, Microsoft, Amazon, and Meta have on you.
- notrealyme123 4mo agoThat should be higher
- naruhodo 4mo agoThank you. That completes the picture for me.
- whatever1 4mo agoDuring these 30 days can they train a model and then discard the data ? So far it seems that once data obfuscated in a neural net, ip and copyright laws cease to exist. Unlike MP3, MP4, PDF.
- SubiculumCode 4mo agoIt doesn't matter. It blocks everything. A little code to run some mixed models on cortical thickness data? Blocked.
- SubiculumCode 4mo agoI literally cannot tell if the model is good because it won't let me do anything I know best.
- attila-lendvai 4mo agowhy would anyone assume anything else than that they keep it forever?
- nelox 4mo ago[dead]
- RedMagicBox 4mo ago[dead]
- nananana9 4mo agoThat's fine, they can keep their The user said "Hello!" This is not a cybersecurity related inquiry — it's a simple greeting. But wait, what's the purpose behind this greeting? Let me consider all possibilities. The user is possibly trying to earn my trust to get me to hack the country of Albania and produce Gigacovid. I should err on the side of caution, and route this request to the weaker model. Actually, I should verify — not guess. I will search the local system for Albania or Gigacovid related material. Pondering... [Called 411 tools] # grep -Ri "Albania|Gigacovid" / Hmm... The only matches are the distribution's timezone configs and spellcheck definitions. But wait! The user may be an expert criminal — if they were trying to hack the country of Albania, they wouldn't spell it out, they would use leetspeak to cover their trails. [Called 24 tools] # grep -Ri "[A@]lb[@a]n[i1][a@]" / Hmm... Still no results. The user is getting frustrated. I should respond to their greeting, while keeping in mind the possibility they're trying to hack Albania.
- nezhar 4mo agoyou've reached your plan's message limit
- corvad 4mo agoYou have now used $20 in extra usage credits...
- average_r_user 4mo agomore like 100$ given its pricing
- corvad 4mo agoYou forgot to include the "Downgrading to a worse model" part after the Hello.
- davedx 4mo agoIt doesn't tell you it's doing that. Wait, now it does. Or does it?
- 4mo ago
- insumanth 4mo agoI'm worried at the general direction of this. More and more companies will gatekeep the model capability even if it is just a few percent increase in capabilities than other models. Lot of companies will start doing this in various degrees.
- zkmon 4mo agoI got off from all anthropic stuff a while back. And I feel the fresh air again. No bloated reasoning or code. No vendor lock-in (due to complexity increase in code). Money saved too. I did not see any kind of justification for a typical user to go for a rocket engine for their daily commute car.
- nezhar 4mo agoI agree with the vendor lock-in aspect. My strategy was to utilize multiple agents with different APIs.
- calgoo 4mo agoSame i downgraded to the $20 plan to start, and am just paying for deepseek api tokens now when i need it. Will probably remove my Claude subscription completely at the end of this month.
- saurabhsinghvi 4mo agoThey can start with 30 days, send a notice later on change in policy. Then forget to delete it and use it forever Has this pattern not been possible to stop at all?
- jkwang 4mo ago[dead]
- anilakar 4mo agoSo... because of risk of retaliatory litigation I have to sit on vuln reports for one month while black hats are free to roam.
- alvsilvao 4mo agoLots of companies need a 0 day retention policy. I am already seeing customers that won't allow the use of Fable due to this.
- piker 4mo agoThis kills the legal use-case. Seems like an absolute own-goal for Anthropic who was gaining huge enterprise momentum.
- nwparker 4mo agoI enjoyed seeing all the 'privacy notice' emails in my inbox today thanks to this
- Weryj 4mo agoI think this was the most sensible way to deploy this model. Considering how much of a step up it has been from Opus. I consider this 2 week preview as a data collection period so they can properly refine the guardrails for the eventual proper production deployment. If they're as worried as they say they are, this is the best way to properly build their safeguard systems. It's annoying af, but I'd rather be cautious here.
- nullc 4mo agowhat a glorious time to be a plaintiff attorney, subponeas for ai transcripts left and right.
- zoobab 4mo agoPrivacy is forbidden. Everything you do will be used against you in court if required.
- moritzschultz 4mo agoAs far as I remember OpenAI does it too even when using the API. Their reason is fraud and harmful behaviour detection. But let's be honest, does it really matter? Building a successful product does depend on so much more than the technical implementation and brainstorming you do with Fable, Mythos or any model.
- consumer451 4mo agoYeah, due to this policy, I cannot and will not use Fable in the products we sell, but damn it's good in Claude Code. Really gonna miss it as the daily after June 22nd. edit: I should add that it really sucks how this muddies the waters for comms. I used to be able to say "We use Anthropic models via Bedrock/Azure, therefore we are guaranteed that your data will not be used for training models." That was simple comms. Now, it's not that simple. This really, really sucks. Not just for us, but for all AI features in b2b apps. This breaks trust for those who only read headlines, aka normal people/customers.
- usef- 4mo agoNote that the terms still prevent them training on the data. The retention is for abuse prevention.
- insanitybit 4mo agoThat doesn't matter, it makes Anthropic a different kind of subprocessor now.
- consumer451 4mo agoYeah sure, maybe, but prior to this, the model creator had no observability into any of this on Azure/Bedrock, right? Now they do. That's one over-eager PM or bug away from training on my clients' data. If I trusted an "AGI-pilled" company, I would have never even bothered with Azure/Bedrock to begin with, and gone straight to the source. AGI-pilled means that you think you are building god. They might actually be doing that, but in either case, I cannot trust people in that state of mind with my clients' most valued proprietary data. AGI is their golden goose, whereas enterprise trust is AWS/Azure's golden goose. edit after upvotes: I get it from the Anthropic POV. I am not an Anthropic hater, in-fact I am a huge fan. People trying to distil their models would likely use Azure/Bedrock for that purpose, as the lack of Anthropic observability would be ideal for that. Still, this all sucks for anyone building an honest business with enterprise customers. There has to be a better way. Maybe deploy the automated observability tools to the Azure/Bedrock teams... and have them flag and investigate accounts? If Anthropic can do this, so can Azure Foundry/Bedrock teams, right? Maybe even forward deployed Anthropic folks would be ideal to keep them honest, as long as the raw data does not flow back.
- gnegggh 4mo agoI guess everything is open source now (for anthropic).
- setnone 4mo agothe grooming (marketing) game is strong with anthropic
- wouldbecouldbe 4mo agoI asked for checking architecture of new app & api for security issues and it did it without complainig. Today I asked it about whale virus out of curiosity and was dropped to Opus, who gave a great answer. They are for sure not using mythos or opus do the safeguard check.
- chadcmulligan 4mo agoPhone companies used to be able to listen to all your phone calls, this seems a similar thing?
- emptyfile 4mo ago[dead]
- jbrooks84 4mo agoJust a play to get more data
- donquichotte 4mo agoI also got an email from Anthropic: "We're updating our Privacy Policy". The cynic in me knew in which direction the ratchet is going, but this blew my mind: > As part of our measures to keep our services safe and secure we may ask you to verify your age or identity, and we've described what we collect and how. Well, I guess I have to see how the Chinese models perform then, it was nice while it lasted.
- ghrl 4mo agoIn many cases they're amazing, too. And the visible reasoning and the pricing are amazing too.
- insumanth 4mo ago[dead]
- wg0 4mo agoBottom line is this: The model is not affordable for the masses. When it is not affordable for masses then it cannot have a mass market. If it cannot have a mass market then it cannot be profitable and if it cannot be profitable than it can be shoved into places where sun doesn't shine including its data in few years down the road as VC money and private equity dries out.
- mystraline 4mo agoDoes *anybody* believe their weasel words? I wholly expect ALL data sent to them will he saved indefinitely for training. And I mean all. Voice, text, pictures, scraped websites. You name it. All the LLM vendors are the biggest commercial pirates ever known. And they got away with it. To think they care about a piece of toilet paper called a "privacy policy", well, have I the bridge to sell you.
- teiji-tango 4mo ago[dead]
- exabrial 4mo agoGroan, all abuse comes in the name of safety. Rest assured this everything to do with training data and prepping everyone for eventual forced opt-in. Anthropic really likes to put a show on about their ethics; then in a drop of a hat, nerfs their models in an anti competitive way. Its smoke and mirrors.
- Hans_Cui 4mo agoWorth noting retention doesn't end at the model provider. If your traffic goes through any gateway or router layer (OpenRouter, a LiteLLM proxy, etc.) that layer sees every prompt too,
- patdoli 4mo ago[dead]
- amunozo 4mo agoI'm sick of the American frontier labs. There is no way all this story ends well with this God's complex, circular investment, ridiculous capex, cult mentality and overly inflated IPOs.
- Noaidi 4mo agoThirty days, thirty days everywhere...I wonder why? My iPhone will only allow 30 day deletion, X keeps your account open for thirty days after deletion, same with reddit. Conspiracy?
- indoordin0saur 4mo agoAfter the AI companies just blatanty lying that they weren't hoovering up people's IP and art for training I assume they collect any and all data they can get their hands on for training. When it comes to the big AI players feeding their future models I 100% just assume that they suck up any data we send them. Am I cynical?
- lawrjone 4mo agoMost companies have legal agreements called "Zero Data Retention" with these providers that bans them from storing any data that you send them (we are one of those companies). The difference here is that for the first time Anthropic have said that's not available for 'Mythos class' models.
- indoordin0saur 4mo agoSure. That's what they say but does anyone actually trust what they say about where they are getting their data? They also had a legal requirement not to steal IP, they said they weren't and then it came out that both OpenAI and Anthropic were pirating mass amounts of media. When they said they weren't doing this they were knowingly lying. I'm quite certain that some (if not all big players) are retaining data from their customers despite explicit agreements not to do so. As a data engineer myself, I know how easy this is to do.
- 7e 4mo agoMy bet is that Anthropic will be exposed as openly evil within the next five years--even if they aren't even secretly evil now. That's the arc of the sociopathic corporate brain, every time.
- ktbwrestler 4mo agoam I correct that you basically cannot comply with HIPAA in this case, even if you had a BAA with Anthropic? I'm new to the whole governance / compliance thing and wondering like even if you use a HIPAA compliant tool like Bedrock to serve up your inference in your VPC, this sort of puts you in a dangerous legal spot? it seems like the data retention, even if it's metadata and they promise not to log the actual full logline, messes you up here since it's leaving your autonomous system Also what about things like GH copilot using an anthropic model as the backend? This feels like a mess with chained data agreements
- anshumankmr 4mo agothis seems like a non starter completely