Your Company's AI Data Needs More Than a No-Training Promise

Matthew Mbaka · September 15, 2026 · AI

A security professional closes a laptop beside a sealed file and locked data case in a server room.

A company can promise not to train its models on your work and still keep a copy of what you sent. That distinction is now at the centre of a fight between some of the biggest AI buyers and model makers.

Reuters reported on September 14 that Palantir, Nvidia and Booz Allen Hamilton have restricted, or may restrict, access to advanced models unless Anthropic and OpenAI give stronger guarantees about proprietary data. Reuters attributed the details to The Information and people familiar with the discussions. The named companies did not immediately comment to Reuters, so the reported internal policies should not be treated as public contract terms.

No training is only one answer

Model training, service logging and human access are different things.

Reuters said both Anthropic and OpenAI maintain that they do not train on business customer data by default unless the customer opts in. It also reported that Anthropic faced pushback after allowing 30-day retention of usage logs for one model to detect complex attacks. Those statements can both be true. A prompt may be excluded from training while remaining available for security review.

That is why the phrase zero data retention needs a contract and a technical scope. OpenAI's current platform data-controls documentation, for example, says some endpoints or capabilities may retain application state even when Zero Data Retention is enabled. Anthropic also describes zero-retention arrangements and retention controls in its commercial privacy centre. The details depend on the product, account and feature being used.

What a Canadian business should ask before uploading real work

The practical mistake is approving a brand name instead of approving a specific data path. A chat application, an API and the same model sold through a cloud provider can have different logs, administrators and contract terms.

Before confidential material goes in, the buyer should be able to answer these questions:

A zero-retention option can reduce exposure, but it is not a substitute for data classification. Source code, unreleased financial results, health records and client legal files should not be pasted into a tool simply because the sales page says the data is not used for training.

The restriction is the control working

Nvidia reportedly limits Anthropic's models to less sensitive tasks and uses its own models for some internal work. Booz Allen reportedly blocks Anthropic's commercial model for proprietary cybersecurity tasks. Those policies are less dramatic than a company-wide ban. They are examples of matching the tool to the data.

For most organizations, the useful policy will be similarly specific: ordinary drafting may be allowed, protected work may require an approved isolated environment, and a small class of secrets may stay out of external models entirely.

The current dispute is based partly on anonymous sourcing and unresolved negotiations. What it exposes is more durable. Asking only whether a vendor trains on your data leaves too much of the journey unexplained.

Tags: Analysis, Enterprise AI, Data Privacy, Cybersecurity

Read on Mapletechie