ATAILA Newsroom · Budapest · 2026-09-04

2026-W36

If you have to apply for data residency, it is a feature — not a property.

On 2 September The Register reported on Anthropic's new Enterprise Frontier Safeguards programme, and buried in the detail is the sentence every regulated buyer should read twice: zero data retention is not what you get by default. You apply for it. Without it, the norm for commercial API customers is 30-day retention of inputs and outputs — and it is the customer's job to confirm the setting actually took effect.

The article we are responding to

„Anthropic promises zero data retention – but customers must check it worked”

The Register · 2026-09-02

What the article reports

Anthropic announced Enterprise Frontier Safeguards alongside new high-end models. The programme is presented as combining not storing customer data with detection of model abuse. The details that matter to a European buyer:

opt-in
zero data retention is applied for, not granted by default
30 days
the standard retention of inputs and outputs for commercial API customers without it
on you
confirming the setting was actually applied is the customer's task

There is real safety reasoning behind this, and we are not going to caricature it. Earlier in 2026 Anthropic said it would temporarily retain prompts and outputs of covered models — even for customers holding zero-retention agreements — citing evidence of attempted misuse and the need to correlate events across accounts over time. The company was clear it does not train on enterprise data.

Its own customers still found it hard to live with, particularly in regulated industries. That reaction is the story.

What we think

A safety programme that keeps sensitive prompts inside infrastructure the customer controls is a genuine improvement, and we would rather vendors build it than not. Our disagreement is not with the direction. It is with what it reveals about the default.

A setting can be changed by someone who is not you

When residency is a flag on an account, it can be turned off — by a policy update, an incident response, a change of terms, or an acquisition. None of those require your consent, and you will usually learn about them afterwards. When the workload runs on identified hardware in a named jurisdiction, changing that requires physically moving something.

"Verify it worked" is an audit finding waiting to happen

Handing the customer the job of confirming a privacy control took effect is honest, and it is also an admission: the control is not structural. Anyone who has been through a NIS2 or AI Act readiness review knows how that reads in an evidence pack — we requested it, and we checked a settings page.

Regulated industries were right to push back

The pushback was not unreasonable customers failing to understand safety engineering. It was buyers noticing that "we do not train on your data" and "we do not hold your data" are different promises, and that only the second one survives contact with a regulator asking where the data physically is.

On ATAILA there is no residency application form. The compute is EU-resident end to end, on our hardware or yours, and we can tell you which machine in which datacentre. That is not a tier — it is the only way we sell it.

Where we stand

We are not claiming a frontier model vendor is doing something wrong. We are claiming their architecture forces a choice ours does not: they must reconcile a global service with per-customer promises, so residency becomes a request, an eligibility check and a rollout schedule. We do not have that problem, because we did not start there.

If your data cannot leave the country for legal reasons, the useful test is simple. Ask a supplier where the workload physically runs, and whether the answer changes if they update a policy. If the honest answer is "it is a setting", you have a feature. If it is "that rack, in that building", you have a property.

The original article

„Anthropic promises zero data retention – but customers must check it worked”

The Register · 2026-09-02