OpenAI vs Anthropic: The Enterprise AI Data War | 2026

OpenAI vs Anthropic: The Enterprise AI War Is Now About Trust, Data, and Control

TL;DR — In a single week in August 2026, the two leading AI labs rewrote their enterprise data policies in opposite directions — and in doing so revealed that the enterprise AI war has moved past the models to a fight over trust, data custody, and control. On August 19, OpenAI previewed “Private Safety Processing,” a system that scans customer interactions for safety risks while preserving Zero Data Retention — its pitch to business customers is essentially “we hold nothing.” One day later, Anthropic signaled a reversal of its own: business customers using its most powerful Fable 5 and Mythos 5 models will keep the mandatory 30-day data retention, but can now store that data on their own cloud infrastructure rather than Anthropic’s — a pitch of “you hold it yourself.” Both moves followed weeks of public pressure from Palantir CEO Alex Karp, who spent the summer accusing frontier labs of using enterprise data to eventually compete with the very businesses paying for their models. The competitive backdrop makes the timing sharper: Reuters and Bloomberg reported that Anthropic’s annualized revenue run rate topped $65 billion at the end of July — ahead of OpenAI’s roughly $40 billion, and up sevenfold from $9 billion a year earlier — driven overwhelmingly by enterprise adoption of Claude Code. This guide unpacks the two data postures, the financial inversion behind them, the Karp catalyst, and what it all means for how you actually buy enterprise AI now.

Anthropic and OpenAI both rewrote their data policies in one week — in opposite directions. Data, control, and custody are the new battleground.

The Revenue Inversion Behind the Sudden Urgency

To understand why both labs moved on data policy in the same week, you have to start with the money — because the commercial balance between them has just inverted.

Annualized run rate is a projection from recent sales, not audited revenue — and the two firms may measure differently.

The numbers, confirmed across Bloomberg, Reuters, CNBC, and Axios reporting in August 2026:

Anthropic’s annualized revenue run rate hit $65 billion at the end of July, up from $47 billion in May and just $9 billion at the end of 2025 — a sevenfold increase in seven months. OpenAI, meanwhile, reached roughly $40 billion, doubling from $20 billion at the end of 2025. On these reported figures, the challenger has passed the incumbent on revenue for the first time, having crossed over around April 2026.

Three caveats keep this honest, and they matter:

Run rate is not audited revenue. It’s a projection that extrapolates a short period — often a single month — across a full year. In a fast-growing market, that flatters the books. Both companies disclosed these figures through investor updates, not audited financials.

The two firms may measure differently. Anthropic reports revenue from cloud resellers (AWS, Google, Microsoft) on a gross basis — counting total end-customer spend as revenue and booking partner payouts as expenses — which inflates its top line relative to net-reporting peers. Direct comparison is imperfect.

OpenAI still leads where Anthropic doesn’t. OpenAI dominates consumer reach, with ChatGPT the first generative AI service to reach a billion weekly active users. Anthropic’s lead is specifically in enterprise and, above all, in coding.

That last point is the engine of the whole story. Anthropic generated more than $11.5 billion in preliminary Q2 revenue — its first quarter of positive adjusted operating income — with roughly 80-85% of revenue coming from enterprise API usage, and Claude Code alone contributing around $8 billion. By one market estimate, Anthropic holds roughly 54% of the enterprise AI-coding market to OpenAI’s ~21%. Anthropic is also preparing a fall 2026 IPO at a $965 billion valuation, which raises the stakes on every enterprise-trust signal it sends.

Here’s why that financial context explains the data-policy week: when your business is overwhelmingly enterprise, and enterprise buyers are suddenly asking hard questions about data, your data policy becomes a revenue-critical product feature. Anthropic admitted this directly, as we’ll see. The models have largely converged on capability; the differentiation is moving to trust.

The next enterprise AI winner may not be the company with the smartest model. It may be the company CIOs trust most with their data.


OpenAI’s “We Hold Nothing” vs Anthropic’s “You Hold It Yourself”: Two Data Postures a Day Apart

The clearest way to understand the shift is to look at exactly what each lab announced, because the two approaches are genuinely different — and neither is strictly better.

Neither is strictly better. The choice is now “we hold nothing” versus “you hold it yourself.”

OpenAI — “we hold nothing.” On August 19, OpenAI began testing Private Safety Processing, a mechanism that automatically scans customer model interactions for safety risks without breaking Zero Data Retention (ZDR) commitments. The problem it solves is real: as OpenAI’s Head of Product Policy Aleah Houze explained, risks increasingly emerge not from a single prompt-response pair but across multiple interactions over time — someone might probe a software weakness in one conversation and return to it later. Private Safety Processing uses automated agents to watch for those patterns and returns only a narrow “safety signal” to OpenAI, without exposing the underlying prompts or responses to OpenAI personnel. Customer data can stay on customer-controlled infrastructure, or sit with OpenAI under customer-controlled encryption keys. OpenAI is testing it with companies including Databricks and Microsoft, with a broader rollout and technical white paper due in September.

Anthropic — “you hold it yourself.” On August 20, a day later, Reuters and Bloomberg reported that Anthropic plans to let enterprise customers keep greater control of their data. The 30-day retention requirement for its most capable Fable 5 and Mythos 5 models — and future frontier models — stays in place, but businesses will be able to store that data on their own cloud infrastructure instead of Anthropic’s. Anthropic itself would no longer hold the data. Head of Claude Code Boris Cherny confirmed the change publicly, with rollout targeted for fall 2026. Crucially, Anthropic says this was built over months in coordination with more than 100 customers in regulated industries, including Salesforce — so it’s not literally a same-week reaction, even though the sequencing invites that reading.

The key distinction is custody, not duration. OpenAI removes the data entirely, which is cleaner for privacy and leaves less for an investigator to work with. Anthropic keeps a 30-day window but places it under the customer’s own key management and jurisdiction. For a regulated enterprise, “no data exists” and “the data exists but only I can access it, in my own cloud, under my own law” are meaningfully different propositions — and which one is preferable depends entirely on the buyer’s regulatory regime and threat model.

The two postures line up cleanly side by side:

OpenAIAnthropic
Core approachZero Data Retention30-day retention
Data custodyMinimize or eliminate retained dataCustomer-controlled infrastructure
Main promise“We hold nothing”“You hold it yourself”
Security logicReduce the data that existsPreserve a forensic window under customer control
Best fitPrivacy-first environmentsAudit- and compliance-heavy environments
Key trade-offLess retained context for investigationData still exists for 30 days

The distinction isn’t simply privacy versus security — it’s primarily about who holds custody.

One more honest detail worth surfacing: Anthropic conceded internally, in a report cited by Bloomberg, that the original retention policy would “be unpopular with customers who have come to expect zero retention, and pose real risks to our business success (especially if competitors do not follow).” That’s an unusually candid admission that this is as much a commercial defense as a safety measure — and it tells you exactly how seriously Anthropic takes the enterprise-trust threat.


How the 30-Day Retention Fight Started

To understand why Anthropic was on the back foot here, you have to go back to June — when it made a move that handed its critics a gift.

When Anthropic launched its Mythos-class models in June 2026 — Claude Mythos 5 and its public-facing counterpart Claude Fable 5 — it did something unusual. Unlike other Claude models, which could operate under Zero Data Retention agreements, Anthropic required that prompts and outputs from these top models be retained for 30 days “for trust and safety purposes,” with no opt-out available to enterprise customers. The stated rationale was defensible on its own terms: attackers rarely reveal their intent in a single conversation, so a longer retention window gives safety teams room to spot emerging cyberattacks that weaponize the models for malicious code or coordinated abuse. Anthropic committed that the data wouldn’t be used for training and would be deleted after 30 days in almost all cases (with an exception of up to two years for content flagged by trust-and-safety classifiers as violating usage policy).

But the timing and the no-opt-out clause made it a lightning rod. For enterprises that had specifically negotiated ZDR to protect sensitive data, this was a downgrade imposed on the most capable models — exactly the ones they most wanted to use for high-value work. The policy became the concrete example critics needed.

It’s worth noting the parallel consumer controversy, because it compounds the trust narrative. In late August 2025 — a year earlier — Anthropic had changed its consumer terms (Claude Free, Pro, and Max) to train on user chats by default unless users opted out, extending data retention to five years for those who didn’t. Business customers were exempt from that change, but the pattern — a company progressively asking for more data access — fed a broader perception that Anthropic’s data appetite was growing. The June enterprise retention rule landed in that context.


The Catalyst: A Rival CEO Said the Quiet Part Loudly

The single most important actor in this story built neither model. Palantir CEO Alex Karp spent the summer forcing the data question onto the agenda — and both labs moved within weeks.

A third party forced the data question onto the agenda — and both labs moved within weeks.

Karp’s argument, pressed through television appearances, a Palantir shareholder letter invoking “Marxist” undertones in the AI business, and a white paper laying out defensive steps for organizations, was blunt: frontier AI labs are using the data, intellectual property, and expertise of their enterprise customers to eventually compete with those same customers. Feed your proprietary workflows and domain knowledge into a frontier model, the argument goes, and you may be training your future competitor.

Anthropic’s June retention policy gave that argument fresh, concrete ammunition. Here was a lab requiring — with no opt-out — that enterprise prompts and outputs be retained on its own servers, precisely for the most capable models. Whatever the genuine safety rationale, it looked, to a skeptical enterprise buyer primed by Karp’s campaign, like exactly the data-accumulation behavior he was warning about.

Then the sequence: OpenAI moved first on August 19 with Private Safety Processing, and Anthropic followed within a day. The neat interpretation — one lab reacting to the other in real time — is too simple, because Anthropic had reportedly been building its system for months with over 100 customers. But the deeper point stands regardless of who moved first: a rival CEO with no model of his own was able to move the data policies of both leading labs, because the accusation landed on enterprises that were already quietly asking the same question. Karp didn’t manufacture the concern. He amplified one that enterprise procurement teams were already voicing, and gave it a memorable frame.

That’s the real lesson about where power sits in enterprise AI now. The labs compete on models, but the terms of competition are increasingly set by what enterprise buyers — and the vendors who serve them, like Palantir — will tolerate on data.


Neither Approach Is a Clean Win

It would be easy to frame this as “OpenAI’s approach is more private, therefore better.” The reality is more balanced, and enterprise buyers should resist the simple version.

Zero retention is the cleanest possible privacy story — if the data doesn’t exist, it can’t be breached, subpoenaed, or misused. But it also means less for a legitimate investigator to work with, including the enterprise’s own security team if something goes wrong. Anthropic’s 30-day window, held under the customer’s own cloud and keys, may actually be the stronger compliance posture for a regulated bank or government-adjacent buyer that needs an audit trail under its own control. Data residency and jurisdiction can matter as much as existence.

Both retain a human-review exception, and this is where buyers should read carefully. Anthropic states that by default no Anthropic personnel can read retained conversations, with review occurring only through a controlled access path when content is flagged. OpenAI’s Private Safety Processing similarly returns limited safety signals without exposing underlying content. The precise trigger, access path, and audit trail for that human review is the detail that actually determines your exposure — not the headline claim. These are two legitimate, genuinely different answers to the same tension, and the right choice is buyer-specific: a privacy-maximizing startup and a heavily regulated bank should reach opposite conclusions, and neither would be wrong.


What This Means for Your AI Procurement

The strategic takeaway is that the enterprise AI decision has permanently changed shape. The data terms now sit alongside the benchmarks as a first-order procurement question.

The data terms now matter as much as the benchmarks — seven questions to ask before you sign.

1. Ask where your data physically lives. “Is it retained?” is no longer sufficient. The questions now are: retained by whom, in whose cloud, under whose encryption keys, subject to whose law? Get the answers in writing, in the contract, not the marketing page.

2. Map retention to your regulatory regime. Finance, healthcare, and public-sector rules may push you toward one posture or the other, and they are not equivalent. Determine whether “no data exists” or “data exists under my exclusive control” better satisfies your specific obligations before you let the vendor frame the choice.

3. Read the human-review exception carefully. Both labs allow human access when content is flagged. Understand the exact trigger, the access path, who can see what, and what audit trail exists. This is where the real residual risk lives, and it’s buried below the headline claims.

4. Separate the model decision from the data-terms decision. The vendor with the best benchmark for your workload may not be the one with the best data posture for your compliance needs. Multi-model routing — already standard practice for cost optimization — lets you avoid forcing a single choice, using different vendors for different sensitivity tiers.

5. Weigh the “competes with you” risk honestly. Karp’s warning is self-interested — Palantir sells an alternative — but it isn’t baseless. Assess whether your AI vendor builds products in your vertical, and factor that into what proprietary data and workflows you’re willing to expose.

6. Treat run-rate leadership as a stability signal, not gospel. Anthropic’s $65 billion run rate, first positive operating income, and imminent IPO genuinely suggest commercial durability, which matters when you’re betting a workflow on a vendor. But remember these are unaudited, gross-basis figures that differ from OpenAI’s measurement. Don’t over-read a single number in either direction.

7. Revisit your terms every quarter. The most important lesson of this week: both policies changed under competitive pressure in a matter of days. Whatever data posture your vendor offers today is not a permanent commitment. Build periodic review into your vendor governance, because the terms will keep moving as the competition does.

This ties directly to the governance findings enterprise leaders have absorbed all year — McKinsey’s AI trust research and Deloitte’s tech-leadership study both concluded that the constraint on enterprise AI is organizational readiness and governance, not model capability. This week is that thesis made concrete: the deals are now won and lost on trust, data custody, and control.


Frequently Asked Questions

What changed in Anthropic’s data retention policy?

Anthropic plans to let enterprise customers keep the mandatory 30-day data retention for its most capable models (Fable 5, Mythos 5, and future frontier models) on their own cloud infrastructure rather than on Anthropic’s servers. The 30-day duration doesn’t change — only the custody does. Anthropic itself would no longer hold the data. The change, confirmed by Anthropic’s Boris Cherny, is targeted for rollout in fall 2026 and was developed with over 100 regulated-industry customers including Salesforce.

What is OpenAI’s Private Safety Processing?

Announced August 19, 2026, Private Safety Processing is a system that lets OpenAI scan enterprise customer interactions for safety risks while preserving Zero Data Retention. Automated agents watch for misuse patterns across multiple sessions and return only a narrow “safety signal” to OpenAI, without exposing the underlying prompts or responses to OpenAI staff. Customer data can stay on customer-controlled infrastructure or sit with OpenAI under customer-controlled encryption keys. A broader rollout and white paper are due in September 2026.

How are the two approaches different?

OpenAI’s approach is “we hold nothing” — it preserves Zero Data Retention, so no customer data is kept. Anthropic’s is “you hold it yourself” — it keeps a 30-day retention window but under the customer’s own cloud, keys, and jurisdiction. OpenAI’s is cleaner for pure privacy; Anthropic’s provides a forensic/audit window under customer control. The distinction is custody, not duration, and neither is strictly better — the right choice depends on the buyer’s regulatory needs.

Why did both companies change their policies in the same week?

Both moves followed a summer campaign by Palantir CEO Alex Karp, who accused frontier labs of using enterprise data to eventually compete with their own customers. Anthropic’s June 2026 mandatory-retention policy gave that argument concrete ammunition. OpenAI announced first on August 19; Anthropic followed August 20. Anthropic had reportedly been building its system for months, so it wasn’t purely a same-week reaction, but the competitive pressure clearly shaped the timing.

Is Anthropic really bigger than OpenAI now?

On reported annualized revenue run rate, yes: Anthropic hit $65 billion at the end of July 2026 versus OpenAI’s roughly $40 billion. But run rate is an unaudited projection, the two firms may measure differently (Anthropic reports cloud-reseller revenue on a gross basis, inflating its top line), and OpenAI still leads decisively in consumer reach with over a billion weekly ChatGPT users. Anthropic’s lead is concentrated in enterprise and especially coding, where it holds an estimated 54% of the AI-coding market.

What was the 30-day retention controversy?

When Anthropic launched its Mythos-class models (Mythos 5 and Fable 5) in June 2026, it required prompts and outputs to be retained for 30 days for trust-and-safety purposes, with no opt-out — a break from the Zero Data Retention agreements available on other Claude models. Enterprises that had negotiated ZDR to protect sensitive data saw this as a downgrade on exactly the models they most wanted to use, making it a focal point for criticism.

Does this affect consumer users of Claude or ChatGPT?

No. Both the OpenAI Private Safety Processing system and Anthropic’s customer-cloud retention change are aimed at enterprise and API customers, not consumer subscription users. OpenAI’s ZDR controls don’t apply to Free, Plus, Go, and Pro consumer users, whose existing data settings are unchanged. (Separately, Anthropic’s consumer terms changed in 2025 to train on user chats by default unless users opt out — a distinct issue from this enterprise data-custody story.)

Who is Alex Karp and why does his opinion matter here?

Alex Karp is the CEO of Palantir, a data-analytics company that sells to enterprises and governments. His view matters because Palantir competes for the same enterprise data budgets and positions itself as an alternative that doesn’t repurpose customer data. His summer 2026 campaign — TV appearances, a shareholder letter, and a white paper — crystallized an anxiety enterprise buyers were already feeling, and appears to have influenced how both frontier labs framed their data policies.

Should I choose OpenAI or Anthropic based on these policies?

Neither policy alone should decide it. Map the data posture to your regulatory regime (regulated industries may prefer Anthropic’s customer-controlled audit window; privacy-maximizing organizations may prefer OpenAI’s zero retention), read the human-review exceptions carefully, and consider separating the model choice from the data-terms choice via multi-model routing. The best model for your workload and the best data posture for your compliance may point to different vendors.

What’s the bigger trend here?

The competition has shifted from model capability to data custody and control, echoing McKinsey’s and Deloitte’s 2026 finding that governance, not model quality, is the real constraint on enterprise AI. Expect retention terms and “will you compete with us” assurances to become as central to deals as benchmarks and price.


Final Take

The week both labs rewrote their data policies is the clearest signal yet that enterprise AI has entered a new phase. For three years the competition was about capability — whose model scored higher, coded better, reasoned further. That race hasn’t ended, but it has commoditized enough that it’s no longer where enterprise deals are decided.

What makes this episode revealing is that the decisive pressure came from outside the labs entirely. A rival CEO with no frontier model of his own, articulating a fear enterprise buyers were already harboring, moved the data policies of both leading AI companies within weeks. That’s less a story about OpenAI versus Anthropic than about power shifting toward the enterprise buyer — and toward whoever can most credibly speak to that buyer’s anxieties about data, competition, and control.

For tech leaders, that’s a more comfortable position than the “which model is best” framing suggests. The vendors are competing for your trust now, and changing binding terms in days to win it. The benchmark that wins the demo is no longer the thing that wins the deal — which is a competition the enterprise buyer is finally positioned to win.


Published August 2026 · The AI & Tech Society · digitalstrategy-ai.com

Sources: Reuters, Bloomberg, CNBC, Axios, and TechCrunch reporting on Anthropic’s data-retention policy change and $65 billion revenue run rate (August 17-21, 2026); The Register, Axios, PYMNTS, and The Decoder on OpenAI’s Private Safety Processing; officechai and multiple outlets on Alex Karp’s campaign against frontier labs; Sacra and valueaddvc for enterprise market-share and Claude Code revenue estimates; Anthropic’s Privacy Center and internal report language as quoted by Bloomberg. Revenue run-rate figures are unaudited projections that the two companies may calculate differently; Anthropic reports cloud-reseller revenue on a gross basis. Enterprise market-share percentages are third-party estimates. The customer-cloud retention change was reported via unnamed sources and confirmed by Anthropic’s Boris Cherny; product documentation had not yet been updated at publication. This article is analysis, not legal or procurement advice. Verified August 2026.


Discover more from The Tech Society

Subscribe to get the latest posts sent to your email.

Leave a Reply