Nvidia and Palantir restrict Anthropic's Fable over data retention

Nvidia and Palantir restrict Anthropic's Fable over data retention

Nvidia, defense contractor Booz Allen Hamilton and Palantir are restricting or blocking how they use Anthropic's flagship model Fable for sensitive work, according to a report from The Information. The pushback follows a policy change Anthropic made in June, when it said it would retain usage logs from Fable for 30 days to defend against 'complex and novel attacks.'

Nvidia, despite being an Anthropic investor that also supplies the company with hardware for model development, now limits Fable to less sensitive tasks such as open-source projects. For internal work like AI-powered supply chain monitoring, it runs its own Nemotron models instead. 'As a company, you know, we believe ZDR [Zero Data Retention] should be on by default,' Nvidia's VP of Enterprise AI, Justin Boitano, told The Information.

Booz Allen Hamilton, a defense contractor that was one of the earliest users of a different Anthropic model, Mythos, has banned employees from using Fable for work on proprietary cybersecurity software, according to The Information. 'We worry a little bit that [Fable] might be learning from some of our code,' CTO Bill Vass said.

Palantir is blocking Fable deployment through its own software to customers until Anthropic grants irrevocable zero-data-retention guarantees, The Information reports. CEO Alex Karp said at a customer event that companies are tired of being 'exploited' by AI labs, and the piece notes Karp has voiced this kind of distrust before. Palantir's position is also self-serving, the piece adds, since the company wants customers running AI models through its own, supposedly secure platform rather than going directly to providers.

After the pushback, and after OpenAI's move in August to let GPT-5.6 Cyber customers store security logs on their own servers, Anthropic is rolling out a similar program to select customers this fall.

Even zero data retention leaves gaps. Both OpenAI and Anthropic still collect metadata and technical usage data from enterprise customers, The Information reports. OpenAI calls this data 'de-identified,' meaning it is stripped of information that could be traced back to individual customers; the company says it runs business data through automated classifiers and security tools 'to better understand how our services are used,' producing classifications that are metadata about the business data 'but do not contain any of the business data itself.' Some customers, per The Information, are not sure exactly what that metadata covers and do not think the current transparency is enough.

John Schulman, an OpenAI co-founder who briefly worked at Anthropic and now works at Thinking Machines, recently laid out the range of ways AI companies can train on user data: from direct pretraining on user data, which carries a high risk of reproducing content, to distilling large models into smaller ones, to building reinforcement learning tasks out of 'user traces.' That last approach carries a low risk of reproducing content but can still extract customer IP, ranging from the harmless ('use explicit user feedback in reward model training') to the invasive ('upload user's coding environment and commit history to turn into rl envs'), Schulman said. 'De-identification is weak,' he added: users can be traced back 'with just a small number of bits,' and it does not protect against IP leakage.

AI researcher Sarah Hooker, who previously worked at Cohere and Google DeepMind, points to a similar gap: labs have 'clever synthetic data techniques that can generate distributional equivalent data while preserving privacy.' In other words, a lab does not need to use a customer's original data directly to extract statistical patterns that do the same job. Hooker warns companies, 'If you are a company with IP you have a limited window to build your own intelligence that leverages your IP. Otherwise you are fueling a frontier lab which will encroach on your vertical sooner or later.'

In a follow-up post, Schulman walked that concern back somewhat, saying training on user data is 'exceedingly unlikely' to add much to frontier capability gains, which come mainly from scaling pretraining and reinforcement learning; user data, he said, is more useful for finding failure modes or situations that are hard to replicate with paid annotators. He added that 'model companies vary in how aggressively they train on user data (and uploading repos isn't hypothetical),' a line the piece reads as a likely nod to AI coding tools such as Codex or Cursor, where users connect their code repositories directly to the service. Schulman called for 'stronger norms around disclosing how companies train on user data.'

The trust problem became concrete in the case of mathematician Tristan Buckmaster. He and co-author Levent Alpöge had used AI models, uploading their drafts through OpenAI's Codex, to make progress on the Navier-Stokes equations; shortly after, OpenAI presented its own breakthrough using the same unusual solution path. OpenAI initially said it could not rule out that anonymized data derived from use of its products had contributed to improving its models. After an internal investigation, it updated its post to say that Buckmaster's Codex prompts from the two months before the September 8, 2026 publication 'could not have influenced the system in any way, including through training.'

Key facts

  • Nvidia, Booz Allen Hamilton and Palantir are restricting or blocking use of Anthropic's flagship model Fable for sensitive work, according to a report from The Information.
  • The trigger was Anthropic's June policy change to retain Fable usage logs for 30 days, meant to defend against 'complex and novel attacks.'
  • Palantir is blocking Fable deployment through its own software until Anthropic grants 'irrevocable zero-data-retention guarantees'; Booz Allen Hamilton has banned Fable outright for work on proprietary cybersecurity software.
  • Anthropic is rolling out a program letting select customers keep their own security logs this fall, mirroring OpenAI's August move for GPT-5.6 Cyber customers, though both labs still collect 'de-identified' metadata even under zero data retention.
  • OpenAI's internal investigation concluded that mathematician Tristan Buckmaster's Codex prompts from the two months before a September 8, 2026 publication could not have influenced its models, after initially saying it could not rule that out.

Why it matters

The story shows that enterprise trust in frontier AI models now turns on data-handling terms as much as on capability, and that trust is running short even among an AI lab's own commercial partners. Nvidia is both an investor in Anthropic and its hardware supplier, and it still keeps sensitive internal work like AI-powered supply chain monitoring off Fable after Anthropic's June decision to retain usage logs for 30 days. The same dynamic reaches beyond Anthropic: OpenAI already moved in August to let some customers keep their own security logs, and OpenAI's own Buckmaster case shows the underlying worry, that a lab could learn from a customer's proprietary work, is not merely theoretical.

Who it affects

Enterprises that route sensitive or proprietary work through frontier AI models are drawing the line here. Nvidia keeps AI-powered supply chain monitoring on its own Nemotron models rather than Fable; Booz Allen Hamilton, a defense contractor and an early user of Anthropic's other model, Mythos, has banned staff from using Fable on proprietary cybersecurity software; and Palantir is withholding Fable from the customers it serves through its own platform until Anthropic commits to irrevocable zero-data-retention terms. The same caution applies to anyone connecting a private code repository to an AI coding tool such as Codex or Cursor, per Schulman's remark, and to academic users like Buckmaster and Alpöge, whose own drafts ended up at the center of a dispute over whether OpenAI's models had learned from them.

How to use it

Zero Data Retention is the term enterprises are pushing for: Nvidia's Boitano says it should be on by default, and Palantir is withholding Fable from its platform until Anthropic grants 'irrevocable zero-data-retention guarantees.' What Anthropic has actually rolled out, after the pushback and after OpenAI's August move to let GPT-5.6 Cyber customers store security logs on their own servers, is a similar program reaching select customers this fall. Even that does not fully close the gap: both OpenAI and Anthropic keep collecting 'de-identified' metadata and technical usage data regardless of whether the underlying content is retained, and some enterprise customers say they still do not know exactly what that metadata covers.

How solid is it

Most of the reporting here, Nvidia's, Booz Allen Hamilton's and Palantir's restrictions, and the detail on OpenAI's and Anthropic's metadata practices, is credited to The Information rather than to this outlet's own reporting, though it comes with on-record quotes from Nvidia's Boitano, Booz Allen's Vass and Palantir's Karp. No Anthropic spokesperson or executive is quoted defending the June retention policy or answering the criticism from the three companies directly. The piece also does not say how many companies beyond these three restrict Fable, gives no exact day for the June policy change, and does not name or date the customer event where Karp spoke.

Risks and caveats

John Schulman calls de-identification 'weak': users can be traced back 'with just a small number of bits,' and it does not stop IP leakage even when raw data is not retained. Hooker's caution goes further: synthetic-data techniques can reproduce a dataset's statistical patterns without a lab ever touching the original data, which is why Hooker tells IP-heavy companies they have 'a limited window to build your own intelligence' before 'fueling a frontier lab which will encroach on your vertical sooner or later.' Schulman later softened his own framing, calling training on user data 'exceedingly unlikely' to move frontier capability much, since that mostly comes from scaling pretraining and reinforcement learning; the Buckmaster case, for its part, ended with OpenAI's internal review clearing the specific prompts in question. The source does not say whether Buckmaster and Alpöge accepted that explanation or how the dispute was ultimately resolved, and it is not fully clear which 'publication' the piece's September 8, 2026 date refers to, though it most plausibly points to OpenAI's own Navier-Stokes post described just before it.

“As a company, you know, we believe ZDR [Zero Data Retention] should be on by default”

— Justin Boitano, Nvidia's VP of Enterprise AI