Why are Palantir, Nvidia and Booz Allen restricting their own AI use?
Palantir, Nvidia and Booz Allen Hamilton have restricted staff from using Anthropic's AI models on sensitive work because of new data-retention terms introduced in June 2026.
Three companies that sell, build or run on AI just told their own people to be careful with it. According to a report from The Information, carried by Reuters and Yahoo Finance, Palantir has pushed Anthropic for an "irrevocable zero-data-retention commitment" before rolling its models out more broadly inside Palantir's software. Nvidia keeps Anthropic's models away from sensitive internal work and leans on its own Nemotron models instead. Booz Allen Hamilton has told staff not to run Anthropic's commercial model on cybersecurity projects that touch client data.
None of these companies are new to AI. Palantir builds data platforms for governments and defense contractors. Nvidia makes the chips the entire industry runs on. Booz Allen does classified consulting work for federal agencies. If anyone had reason to trust a frontier AI lab's data handling, it would be them. They don't, not fully, and that's the story.
What did Anthropic actually change in June 2026?
Anthropic changed its data policy in June 2026, letting the company keep customer usage logs for 30 days by default.
In June, Anthropic updated its data policy. Under the new terms, Anthropic can keep a customer's usage logs for 30 days by default. If its safety systems flag an interaction, that window stretches to two years. Anthropic still doesn't train its models on customer data by default, and neither does OpenAI. Both collect some anonymized metadata for product improvement unless a customer opts out. But retention and training are two different promises, and the retention promise just got longer.
That distinction matters more than it sounds. A vendor can honestly say "we don't train on your data" while also keeping a two-year log of every prompt your team sent it, tied to your account, sitting on their servers. For a defense contractor or a chipmaker with trade secrets, that's not a hypothetical. It's the exact thing their legal teams get paid to worry about.
Is "zero data retention" the guarantee it sounds like?
Zero data retention is not a single setting. It is a negotiated contract term whose coverage depends on the model, surface and feature involved.
Here's the part vendors don't put on the pricing page. Zero data retention isn't a switch you flip. It's a contract term, and contract terms have scope. Coverage depends on which model you called, which surface you called it through and which specific feature you used. A ZDR agreement that covers the API often doesn't cover the chat interface your employees actually open every day. Some endpoints are excluded outright. Getting the term at all usually requires a qualifying use case and a sales team's sign-off, not a checkbox in your admin settings.
| Question | Why it matters |
|---|---|
| Which model does this ZDR term cover? | A retention exception for one model version doesn't carry over automatically when the vendor upgrades. |
| Which surface: API, chat app or embedded tool? | Your team likely uses the chat interface, not the raw API. Confirm coverage matches actual usage. |
| What counts as "flagged" and extends retention? | Anthropic's two-year window applies when its safety systems flag something. Ask what triggers that. |
| Who can verify the policy besides the vendor? | A written promise is not an audit. Ask if there's a third-party attestation or contractual audit right. |
Picture an IT manager at a 200-person engineering firm renewing an AI subscription this quarter. The vendor's sales page says "zero data retention available." The manager assumes that covers everything the team does in the product. It doesn't. It covers one API tier the team never touches, because everyone works through the built-in chat panel instead. The firm finds this out during a security review, not before signing. That gap is the whole story in miniature.
Nexairi Dispatch
Get the next AI move before it turns into a workflow problem.
Join the free newsletter for concise AI news, practical checklists, and the decisions practitioners need to make next.
Free. No spam. You will also get the Nexairi Dispatch.
What is Anthropic doing about it?
Anthropic's fix is Enterprise Frontier Safeguards, letting enterprise customers store their own activity logs under encryption keys they control instead of Anthropic.
Anthropic's answer is a program called Enterprise Frontier Safeguards. It lets enterprise customers store their own activity data in their own cloud account, using storage like Amazon S3, Azure Blob Storage or Google Cloud Storage, encrypted with keys the customer controls rather than Anthropic. The idea: instead of trusting Anthropic to hold and eventually delete your logs, you hold them yourself. Anthropic says the rollout is happening in phases, with broader availability planned for fall 2026.
That's a real structural fix, not a policy tweak. If your company holds the encryption keys, Anthropic's own retention policy stops being the thing standing between your data and the outside world. But it's also new, it's not fully available yet and it shifts real infrastructure work onto the customer. A small firm without a cloud security team isn't going to stand up its own encrypted S3 bucket for chat logs by Tuesday.
How does this compare to other AI vendors?
Palantir and Nvidia built an alternative: a joint platform that runs Nvidia's open Nemotron models on a company's own infrastructure instead of an outside AI lab.
Palantir and Nvidia aren't just complaining. They recently launched a joint platform that pairs Palantir's software with Nvidia's own Nemotron models, which are open and can run inside a company's own environment. The pitch is straightforward: skip sending sensitive data to an outside frontier lab at all. Run a capable model on your own infrastructure instead, and you don't have to read anyone else's retention policy.
That approach trades some raw capability for control. Nemotron models generally trail the top frontier models on hard benchmarks. For a defense contractor handling classified or proprietary data, that trade can be worth it. For a marketing team drafting blog outlines, it usually isn't. The right answer depends on what's actually flowing through the model, and that's a question most companies haven't asked with any precision.
What this means for you
The three companies restricting Anthropic here aren't AI skeptics. They're AI infrastructure companies with more leverage and more legal staff than almost anyone else buying these tools, and they still didn't take the marketing page at face value. That's worth sitting with if your own AI rollout ran on a shorter checklist. This doesn't mean frontier models are unsafe to use. It means "we don't train on your data" and "zero data retention" are two separate claims, and the second one has fine print most buyers never read before typing something they'd rather not explain later.
What should your business check before its next AI vendor renewal?
Before renewing an AI contract, get the data-retention scope in writing by model and by surface, and ask how the policy can be verified.
Ask what specifically triggers extended retention, not just whether the vendor offers it. Ask whether you can verify the policy independently rather than taking the vendor's word for it. If the answer is vague, that vagueness is itself useful information. It tells you the contract term exists mostly for the sales conversation, not for your actual risk.
None of this means panic or a wholesale switch to smaller in-house models. It means treating data retention terms the way Palantir's legal team apparently already does: as a specific, negotiable clause worth reading before your most sensitive workflow depends on it. The companies building this technology just told you, with their own internal policies, exactly how seriously to take that clause.
Sources
Related Articles on Nexairi
Jim Smart is the founder and editor in chief of Nexairi. A Business Intelligence Developer with experience building data systems for Verizon, U.S. Army operations, and enterprise finance teams, Jim spent years turning complex data into decisions that executives could act on — dashboards, forecasting models, and automation pipelines across telecom and government contracting. He founded Nexairi to apply that same clarity to AI: making emerging technology understandable and actionable for the operators, accountants, and business owners who need it most. Jim holds GenAI certifications from the University of South Florida Bellini College of AI and completed Springboard's Data Science Career Track.

