Zero Data Retention at OpenAI, Anthropic, and Google: What changed in August and September 2026

Compliance & Data Protection

Image

Dominik Keller

Image

Zero Data Retention (ZDR) means that an AI provider does not save your prompts and the model's responses after processing: neither for abuse monitoring nor for training or support. With the major providers, this commitment is only available upon request, and it always has exceptions. In August and September 2026, OpenAI and Anthropic fundamentally changed their rules on this.

Within two weeks, there were two U-turns. On August 19, 2026, OpenAI announced it would maintain Zero Data Retention even for its most powerful models and redesign safety monitoring so that customer content no longer needs to be stored for it. On September 1, 2026, Anthropic followed suit: The 30-day storage requirement for Mythos and Fable models in place since June is to be replaced by "Enterprise Frontier Safeguards," where monitoring data resides in the customer's cloud account instead of with Anthropic.

For companies in the EU, this raises a new question of which provider makes what commitment, under what conditions, and what actually gets included in the data processing agreement. This article contextualizes the announcements, compares the storage rules of OpenAI, Anthropic, Google, and Microsoft side-by-side, and gives you a checklist for your next provider meeting.

At a Glance

  • OpenAI is maintaining Zero Data Retention for frontier models and introducing "Private Safety Processing": automated systems detect abuse patterns, and staff do not see any content. Rollout starting September 2026, a whitepaper has been announced.

  • Since June 9, 2026, Anthropic has required 30-day storage for Mythos 5, Mythos 5.1, Fable 5, and Fable 5.1, even with existing ZDR contracts. With Enterprise Frontier Safeguards (rollout starting autumn 2026), monitoring data resides in the customer's own cloud account. Until then, eligible customers receive ZDR for Fable 5 and Fable 5.1.

  • With all US providers, ZDR is application- or contract-bound, never standard. Google links the commitment to the paid tier and to turning off a 24-hour cache, Microsoft to approval for "Modified Abuse Monitoring."

  • "No storage" is never absolute: reporting obligations, legal holds, and flagged content remain excluded with all providers.

  • With kontinent.ai, an API key can be restricted to providers with contractually proven ZDR commitments. 9 out of 14 connected providers meet this tier.

Table of Contents

  1. What Zero Data Retention means, and what it does not

  2. What OpenAI announced on August 19, 2026

  3. What Anthropic changed on September 1, 2026

  4. Where Google and Microsoft stand

  5. Comparison Table: Storage rules of the major providers

  6. What this means for GDPR

  7. Checklist: six questions for every provider

  8. How kontinent.ai handles this

  9. Frequently Asked Questions

What Zero Data Retention means, and what it does not

Zero Data Retention describes how your content is handled after the response has been returned. Without ZDR, major providers store prompts and responses for a set period, usually 30 days, to detect abuse. With ZDR, this storage is omitted. In everyday practice, three different commitments are often confused:

Commitment

What it regulates

Typical status without a special agreement

No Training

Whether content is used to train or improve models

Standard for API tiers of the major providers. OpenAI since March 1, 2023, Azure OpenAI contractually, Google only in the paid tier.

Zero Data Retention

Whether content is stored at all after the response

Only upon request. Standard is storage of up to 30 days for abuse monitoring.

Data Residency

Where data is stored and processed

To be booked separately. For OpenAI, EU residency requires ZDR or Modified Abuse Monitoring.

In addition, there is a limitation that appears in every provider's documentation and hardly ever in a sales pitch: ZDR applies to endpoints, not to accounts. State-retaining features store by definition. At OpenAI, this includes Assistants, Threads, and Vector Stores; at Anthropic, Code Execution and the tools built on it; at Google, Grounding with Google Search. Anyone who has ZDR and uses one of these features leaves the agreement for that query, without the API blocking it. Anthropic explicitly states this in its documentation.

What OpenAI announced on August 19, 2026

On August 19, 2026, OpenAI committed to offering Zero Data Retention for upcoming frontier models as well, introducing a new validation process called "Private Safety Processing." The definition of ZDR in the announcement is narrow: OpenAI does not store prompts and responses after processing, staff have no access to customer content, and corporate data is not used for training unless the customer explicitly agrees.

The technical core is Private Safety Processing. Automated systems analyze activity across multiple related queries and, in the event of suspicion, generate a tightly scoped signal that only names the category of suspicion, not the content. As examples, OpenAI mentions repeated testing of safety mechanisms, coordinated activity across multiple accounts, and agents deviating from the user's instruction. OpenAI can take action based on the signal, but staff do not get to see the flagged content. The rollout begins in September 2026, and in parallel, OpenAI plans to publish a whitepaper on the technology.

One exception remains explicitly in place: US law obligates OpenAI to report suspected depictions of child abuse. Images flagged for this are kept by OpenAI, even under ZDR, for manual review and reporting.

In practice, access does not change: ZDR is still only available to "eligible customers" after approval by OpenAI, and the path leads through sales. According to the API documentation, the commitment applies to the Chat Completions, Responses, Embeddings, Audio, Images, and Completions endpoints. Assistants, Threads, and Vector Stores are excluded. If ZDR is active, the store parameter in Chat and Responses calls is always treated as false, even if a request sets it to true. Anyone wanting additional EU data residency via eu.api.openai.com needs, according to the documentation, one of the options: ZDR, Modified Abuse Monitoring, Eyes Off, or Safety Retention, as well as a "Modified Retention Amendment" to the contract.

The takeaway: OpenAI is taking the position that safety monitoring for frontier models does not require storing customer content. This is precisely the question on which Anthropic decided differently in June.

What Anthropic changed on September 1, 2026

On September 1, 2026, Anthropic announced "Enterprise Frontier Safeguards" (EFS), a process designed to combine Zero Data Retention with automated abuse detection, replacing the storage obligation introduced in June. To understand the significance, it is worth looking at the history.

The 30-day rule since June 9, 2026. Anthropic classified Mythos 5, Mythos 5.1, Fable 5, and Fable 5.1 as "Covered Models." According to the Privacy Center, prompts and outputs are stored for 30 days for these models, even if the organization has a ZDR contract. ZDR workspaces had to actively enable storage in order to use the models at all. Human review was limited to content flagged by automated systems and to a small circle of approved reviewers. If violations were detected, Anthropic reserved the right to keep content for up to two years and classification metrics for up to seven years. This rule applied to all channels, including via Amazon Bedrock and Google Cloud, where the stored data remains within the environment of the respective cloud provider.

What EFS changes. In the future, the activity data for monitoring is to reside in the customer's cloud account, such as in Amazon S3, Azure Blob Storage, or Google Cloud Storage, under keys controlled by the customer. The monitoring runs automatically; according to the announcement, a human review by Anthropic is no longer required. If the system detects an unusual pattern, the signal goes to the customer, whose own team evaluates the case. Anthropic charges nothing for EFS; the storage and data costs are incurred with the cloud provider. According to Anthropic, the process was developed with more than 100 customers from finance, healthcare, industry, telecommunications, law, retail, and the public sector. Covered are Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, the Claude Platform on AWS, Google's Agent Platform, and Microsoft Foundry. The rollout will take place in phases starting autumn 2026, and access is managed via an application form.

The transitional rule. Until EFS is available, eligible customers receive ZDR for Fable 5 and Fable 5.1. The announcement does not mention a transitional rule for the Mythos models, and the platform documentation continues to list all four models as Covered Models with a 30-day obligation, "unless explicitly authorized by Anthropic." Anyone wishing to use Claude with ZDR today must therefore still ask and get approval in writing.

The takeaway: Anthropic is not abandoning storage, but relocating it. The data then resides in your cloud account, under your control, in the region you choose. This elegantly solves the residency question, but also shifts the work. As The Register put it on September 2: Customers have to check for themselves whether it worked. Anyone who does not process the signals has effectively turned off the monitoring.

Where Google and Microsoft stand

Google and Microsoft have not changed their rules in recent weeks, but they are the benchmarks against which the two announcements are measured. Both offer ZDR, and both tie it to conditions that you need to know.

Google Vertex AI (Gemini Enterprise Agent Platform). According to Google's documentation, Gemini models keep inputs and outputs in memory for 24 hours by default to speed up responses. The cache is project-isolated and does not reside on storage disks, but it counts as storage. Anyone who wants ZDR must turn off this caching and must not activate Session Resumption, which also retains data for up to 24 hours. Independent of this, under Section 4.3 of the Cloud Terms of Service, Google may log prompts for abuse detection; anyone affected who needs ZDR can request an exception.

Gemini Developer API. The developer API outside of Google Cloud differentiates by tier. In the free tier, Google uses content to improve products, and human reviewers may read inputs and outputs. This is omitted only in the paid tier, and only there can ZDR be requested on a per-project basis. Even then, grounding with Google Search remains stored for 30 days and cannot be turned off; for the Interactions API, store must be explicitly set to false.

Microsoft Azure OpenAI. Azure stores prompts and completions for up to 30 days for abuse monitoring. Human reviewers only see content flagged by the system; for deployments in the European Economic Area, these reviewers are also located in the EEA, according to Microsoft. Storage can be turned off via "Modified Abuse Monitoring," which is only available to "managed customers" upon request. Whether it is active is shown in the JSON view of the resource in the Azure portal: the value ContentLogging: false only appears then. From our own experience: on an MCA Individual contract, approval was unobtainable; in practice, it requires an Enterprise Agreement or MCA-E. The EU Data Zone only regulates the place of processing (any EU member state), not the storage.

Comparison Table: Storage rules of the major providers

The table summarizes the status as of September 3, 2026, based on the linked provider documents. The "Remains despite ZDR" column is the most important, because it is never highlighted on any datasheet.

Provider

Standard without special agreement

ZDR available?

Requirement

Remains despite ZDR

OpenAI API

Abuse monitoring logs up to 30 days; no training since March 2023

Yes, in the future also for frontier models

Approval by OpenAI; only specific endpoints; additional contract addendum for EU residency

CSAM images, legal retention; Assistants, Threads, Vector Stores

Anthropic Claude API

Deletion within 30 days; Covered Models mandatorily 30 days since June 9, 2026

Yes via contract; transition: Fable 5 and 5.1 for eligible customers; EFS starting autumn 2026

Contract via sales; EFS via application form; own cloud account for monitoring data

Flagged content up to 2 years, classification metrics up to 7 years; Code Execution and tools built on it

Google Vertex AI (Gemini)

24-hour cache in memory; prompt logging for abuse detection

Yes

Turn off caching, Session Resumption off, request exception from logging

Grounding with Google Search; files created by you and context caches

Gemini Developer API

Free: usage for product improvement, human review. Paid: limited logs

Only in the paid tier, per project

Approval for the project

Grounding 30 days; Interactions API only with store=false

Azure OpenAI

Up to 30 days for abuse monitoring; reviewers for EEA deployments located in the EEA

Yes ("Modified Abuse Monitoring")

Application; in practice, Enterprise Agreement or MCA-E

Automated real-time checks; access restriction on suspicion

What this means for GDPR

Zero Data Retention is not a statutory obligation, but the storage duration with the provider is one of the points that you, as the data controller, must know, justify, and document. Four sections of the GDPR are directly linked to this:

  • Art. 5(1)(e) (Storage limitation): Personal data may only be stored for as long as necessary for the purpose. A 30-day retention for abuse monitoring is a purpose of the provider, not yours. You must still map it in your record of processing activities.

  • Art. 28(3) (Data processing): The DPA must regulate deletion or return after the end of processing. If ZDR is only a console setting and not in the contract, you have no resilient commitment. With an EU provider in our catalog, ZDR is precisely such an account switch, while the T&Cs continue to grant the provider a broad license to inputs and outputs. What you should look out for in the DPA is listed in the DPA checklist for AI tools.

  • Art. 32 (Security of processing): Data that is not stored cannot leak. ZDR reduces your attack surface and is a legitimate argument in your risk assessment, but only if you know the exceptions.

  • Art. 35 (Data protection impact assessment): For sensitive data or large volumes, the storage duration with the provider is a risk factor that the DPIA must address. This also applies in the event that a provider subsequently changes the rules, as Anthropic did in June.

Two things should be listed separately in the contract: "no training" and "no storage." They are often mentioned in the same breath during sales pitches, but they are different commitments with different exceptions. How you can use the three major providers in a GDPR-compliant manner overall—covering residency, DPAs, and third-country transfers—is described in the article Using OpenAI, Claude, and Gemini in Europe without GDPR risks.

Checklist: six questions for every provider

  1. Is ZDR in the contract or only in the console? A provider can change an account setting, but not a contract unilaterally.

  2. Which models and endpoints does it apply to? Explicitly ask about exceptions for new models (Covered Models), stateful features, and grounding.

  3. What remains stored anyway, and for how long? Flagged content, legal holds, caches, batch inputs. Ask for the specific periods.

  4. Who reviews flagged content, and where is that person located? With Azure in the EEA, with Anthropic a small circle of reviewers, with OpenAI in the future no one. This belongs in your third-country assessment.

  5. How can you verify that it is active? Azure shows ContentLogging: false, Anthropic the storage retention under Settings, Privacy Controls, OpenAI forces store=false. Check this after every contract change.

  6. What happens during the next model change? June 2026 showed that a ZDR commitment can be suspended for a new model. Agree that you will be informed before such a change.

How kontinent.ai handles this

We classify every connected provider into three tiers: full (contractually proven commitment, no storage after response), partial (commitment with documented exceptions), and none. The classification is based on the full text of the contracts, not on marketing pages, and every classification lists its source and verification date. As of today, 9 out of 14 providers meet the full tier. Four are set to "partial": Mistral due to abuse logs, Scaleway due to batch inputs stored for up to 24 hours, AWS Bedrock because certain models are stored for up to 30 days for abuse detection, and Nebius because ZDR there is an account setting without a contract clause. Azure OpenAI is set to "none" because Modified Abuse Monitoring is not available on our contract. The classifications with sources can be viewed in the public provider ranking.

Per API key, you can set two switches: "only providers with Zero Data Retention" and "only providers with training exclusion." A query targeting a provider that does not meet the condition is rejected or, if you have configured fallbacks, redirected to a compliant provider. Which provider actually delivered the response is recorded in every log entry. We ourselves log metadata such as model, token counts, and latency, but no prompts and no responses. What an LLM Gateway should offer beyond this and how Kontinent differs from other EU alternatives to OpenRouter is covered in the linked articles.

If you want to use Claude, GPT, or Gemini with resilient storage commitments from within the EU, join the waiting list.

Frequently Asked Questions

What is Zero Data Retention?

Zero Data Retention is an AI provider's commitment not to store prompts and model responses after processing. Without this commitment, major providers typically keep content for up to 30 days for abuse monitoring. ZDR is only available upon request or via contract with OpenAI, Anthropic, Google, and Microsoft, and always carries exceptions for flagged content and legal obligations.

Is Zero Data Retention mandatory under GDPR?

No. The GDPR does not demand zero storage with the provider, but it requires that you know the storage duration, regulate it in the DPA, and consider it in your risk assessment. ZDR facilitates compliance with Art. 5(1)(e) and Art. 32 because less data resides with the processor. The commitment is only resilient if it is written in the contract.

Does ZDR mean that the provider stores absolutely nothing?

No. All providers retain exceptions: OpenAI preserves flagged child abuse material for statutory reporting, Anthropic stores content for up to two years in the event of violations, Google keeps grounding data for 30 days, and stateful features such as Assistants or Code Execution always store data. ZDR applies to defined endpoints, not universally to the account.

Does ZDR now apply to all models again at Anthropic?

Not yet. Since June 9, 2026, Mythos 5, Mythos 5.1, Fable 5, and Fable 5.1 have required 30-day storage. As a transition until Enterprise Frontier Safeguards are available, eligible customers can request ZDR for Fable 5 and Fable 5.1. Anthropic has not named a transitional rule for the Mythos models. Without explicit approval, it remains at 30 days.

How do I get Zero Data Retention with OpenAI?

Through sales. OpenAI reviews eligibility and enables ZDR for the organization; it then applies to Chat Completions, Responses, Embeddings, Audio, Images, and Completions, not to Assistants, Threads, or Vector Stores. Anyone who also wants EU residency via eu.api.openai.com also needs a Modified Retention Amendment to the contract, according to the documentation.

Is "no training" the same as Zero Data Retention?

No. "No training" means that content is not used to train or improve models; this is standard for API tiers of the major providers. Zero Data Retention means that content is not stored at all after the response; this is not standard anywhere. A provider can commit to one and not the other. Both belong separately in the DPA.

How do I check if ZDR is active with my provider?

With Azure OpenAI, the value ContentLogging: false only appears in the JSON view of the resource if storage has been turned off. With Anthropic, the storage period is listed in the Claude Platform under Settings, Privacy Controls. With OpenAI, under ZDR, the parameter store is forced to false. Recheck this after every contract or model change.

Sources

Status: September 3, 2026 · kontinent.ai. Information according to the linked provider documents; no legal advice.