Palantir, Nvidia, Booz Allen cut Anthropic, OpenAI use over data retention
Serge Bulaev
Palantir, Nvidia, and Booz Allen have reduced their use of Anthropic and some OpenAI models because of concerns about how long customer data is kept. These companies may want stronger promises from vendors that no customer data will be stored or used for training. Nvidia is moving more work to its own internal models to keep data private. Some clients appear to want strict guarantees before allowing sensitive data to be used with outside AI models. The trend suggests more companies might ask for zero-data-retention rules, but it is unclear how this will affect AI model quality and business in the long run.

Major technology and consulting firms Palantir, Nvidia, and Booz Allen are curtailing their use of Anthropic and select OpenAI models due to significant data retention concerns, according to reports from The Information and Reuters. The firms are demanding stronger contractual guarantees, with Palantir seeking an "irrevocable zero-data-retention" pledge before allowing third-party AI models to process its proprietary data.
Why retention is the flashpoint
Major enterprises are restricting access due to concerns over data privacy and the lack of ironclad contractual guarantees. They are demanding 'irrevocable zero-data-retention' policies from AI vendors to ensure proprietary information is never stored, logged, or used for model training after a prompt is processed.
Palantir's public policies already mandate strict data handling. Its AIP security and privacy guidelines state that when calling external models, prompts and completions are "immediately discarded" and never used for training. Furthermore, its Enrollments and organizations • Retention policies require that sensitive data be deleted once its processing purpose is fulfilled. Sources now indicate Palantir is demanding this standard be codified irreversibly in vendor contracts.
Following Palantir's lead, Nvidia and Booz Allen Hamilton are also pressing vendors for stronger zero-data-retention guarantees, according to Reuters. In response to these privacy concerns, Nvidia is shifting confidential workloads to its proprietary Nemotron models, which are designed for on-premise or isolated cloud deployments to prevent data exposure.
Shifting workloads to internal or aligned models
Nvidia markets its Nemotron Safety models as a secure alternative, offering real-time filtering for jailbreak attempts, toxic content, and inadvertent PII exposure. With features like multilingual moderation and fine-grained policy control, analysts agree these models are well-suited for regulated industries that cannot risk sending raw data to third-party APIs.
As a major federal systems integrator, Booz Allen Hamilton has reportedly curtailed employee access to Anthropic's models. According to Reuters, the move was prompted by concerns that even anonymized prompt metadata could be collected by the vendor to "improve products." This action suggests that clients with classified or export-controlled data are mandating stricter data governance from their contractors.
Early procurement effects
This shift is already visible in enterprise procurement. Industry reports indicate that data residency, retention clauses, and audit rights are becoming increasingly common RFP requirements. Vendor disclosure checklists increasingly demand clarity on:
- Whether customer inputs are ever stored
- The length of any safety or abuse-monitoring retention window
- Use of inputs for model training or fine-tuning
- Subprocessor locations and jurisdictions
- Availability of private or sovereign deployments
This level of scrutiny is compelling AI providers to move away from standard logging policies and toward enterprise tiers that offer contractual, option-based data retention.
Potential market ripple
The stance taken by Palantir, Nvidia, and Booz Allen is a strong market signal, as noted by The Information. Zero-data-retention is quickly becoming a non-negotiable feature for sensitive workloads in defense, chip design, and government consulting. If this trend accelerates, AI providers who depend on prompt logging for model improvement may face significant headwinds, including slower enterprise adoption and increased compliance costs.
In response, Anthropic and OpenAI have stated to Reuters that they do not use customer data for training without an explicit opt-in. However, they acknowledge retaining anonymized telemetry for reliability monitoring - a practice that is becoming a point of contention, with a clear divide between enterprises that accept it and those that do not.
The long-term equilibrium between model performance and absolute data privacy is still developing. Nonetheless, current enterprise procurement behavior demonstrates a clear and measurable pivot toward in-house or tightly-aligned vendor models that come with explicit, contractual zero-data-retention guarantees.
Why are Palantir, Nvidia, and Booz Allen restricting use of Anthropic's AI services?
Data handling concerns and the lack of irrevocable zero-data-retention guarantees are driving these restrictions. According to Reuters reporting from September 14, 2026, Palantir specifically demanded an "irrevocable zero-data-retention" commitment from Anthropic before making its models available through Palantir software. The firms worry that proprietary or sensitive information processed through these services could be retained or used in ways that create compliance and security risks.
Have these companies also limited use of OpenAI models?
Yes. The same Reuters report confirms that Palantir, Nvidia, and Booz Allen Hamilton have curtailed use of some OpenAI models alongside their restrictions on Anthropic. While Anthropic and OpenAI both claim they do not train on customer data by default unless companies opt in, enterprise buyers remain concerned about anonymized metadata collection and the absence of stronger contractual guarantees around data retention.
What specific alternative is Nvidia using for sensitive workloads?
Nvidia is shifting sensitive workloads to its Nemotron models, which offer security-focused capabilities designed for enterprise deployment. According to NVIDIA's documentation, Nemotron Safety models provide real-time protection against harmful content, off-topic drift, and jailbreak attempts, along with fine-grained PII detection and reasoning-based custom policy enforcement. These models are available as NIM microservices with what Nvidia describes as "superior security, privacy, and portability," requiring an NVIDIA AI Enterprise license. This allows Nvidia to maintain greater control over data handling for its most sensitive AI tasks.
How is Palantir approaching data retention with AI vendors?
Palantir is seeking irrevocable zero-data-retention guarantees as a contractual requirement. The company's AIP security documentation states that when using third-party-hosted model services, no customer data in prompts or completions is retained, no customer data is used to retrain models, and providers have no personnel access to prompts or completions. Palantir's broader data lifetime policies emphasize that sensitive data, especially PII, should be deleted as soon as the processing purpose is fulfilled.
What broader impact could these restrictions have on the AI industry?
These developments reflect a fundamental shift in how enterprises evaluate foundation model providers. Industry reports suggest that data residency and privacy concerns are becoming increasingly important for enterprise AI purchases, with vendors lacking clear residency and retention policies being cut from consideration early in procurement cycles. Buyers are increasingly demanding contractual assurances rather than marketing claims, scrutinizing subprocessor disclosure, audit logs, and model provenance. This pressure is driving a preference for in-house or vendor-aligned models for sensitive tasks and pushing the market toward private, sovereign, or regionally isolated deployments rather than public, multi-tenant APIs. The relationship between enterprise buyers and AI vendors is becoming more evidence-based and adversarial, with data governance now treated as a board-level priority.