Argues that Bedrock was never about being a better API — it was a compliance wrapper sold on the promise that data never leaves AWS. By carving out Mythos-class models from that guarantee, Anthropic punched a hole in the wrapper at exactly the size of the models customers actually want to use.
Submitted the AWS announcement with a direct quote highlighting that opting into data retention means data leaves AWS's security boundary. The framing of the submission — and its rapid climb to 400+ points — signals this is being read as a material breach of the original Bedrock promise.
Notes that OpenAI's enterprise tier and Google's Vertex both offer zero-retention on their top models, while Anthropic-via-Bedrock used to as well. After this change, Anthropic's highest-capability tier is uniquely incompatible with strict zero-retention compliance terms — a painful irony for shops that picked Anthropic for its safety posture.
Anthropic's official rationale is that single-exchange review cannot catch coordinated abuse patterns that only become visible across days of traffic. 30-day retention on Mythos-class models is framed as a safety mechanism proportional to the capability uplift these models provide.
Points out that while the policy is technically opt-in, the only way to opt out is to not use Mythos-class models at all. For any customer who needs the top-tier capability, retention is functionally mandatory — the choice is illusory.
Anthropic and AWS quietly changed the deal on Bedrock. For Fable 5, Mythos 5, and future Mythos-class models, Anthropic will require 30-day retention for all traffic — and the retained data leaves AWS's data and security boundary to be inspected by Anthropic for misuse patterns.
The announcement landed on the AWS blog and immediately hit the top of Hacker News, where 400+ upvotes piled on within hours. The mechanism is opt-in on paper — you can decline retention — but only by declining the model. If you want Mythos-class capability on Bedrock, retention is the price of entry.
Anthropic's stated reason is misuse detection: single-exchange review misses coordinated abuse patterns that only surface across days of traffic. Fair enough as a safety argument. The problem is what it does to the contract Bedrock customers thought they were signing.
For two years, the pitch for running Claude through Bedrock instead of calling Anthropic's API directly was simple and singular: the data never leaves AWS. That sentence sold the integration to every regulated-industry CTO who couldn't get a third-party LLM through procurement. Bedrock wasn't a better API — it was a compliance wrapper.
That wrapper just developed a hole, and it's exactly the size of the models people actually want to use.
The community reaction on HN was a mix of resignation and irritation. The top comment thread zeroed in on the asymmetry: OpenAI's enterprise tier offers zero-retention; Google's Vertex offers zero-retention on Gemini; Anthropic-via-Bedrock used to offer zero-retention on Claude. Now the highest-capability Anthropic tier is the only one of the three that *can't* be deployed under strict zero-retention terms. For shops that picked Anthropic specifically because they trusted the safety posture, the irony of being forced into more data sharing in the name of safety is not subtle.
The second thing worth noting: this is not just a Bedrock change. It's a precedent. Bedrock's whole architectural premise — that hyperscalers can hold the data boundary while pure-play AI labs hold the weights — bends as soon as the labs need traffic visibility for safety tooling. Expect Azure OpenAI and Vertex to face the same pressure when their providers ship next-generation models with similar safety requirements. The clean separation between "compute provider" and "model provider" was always a billing fiction; this is the first time it's a data-flow fiction too.
There's also the timing. Fable 5 shipped less than a day before this announcement, with reasoning gains and benchmark wins that will absolutely make their way into RFPs. Procurement teams will see "Claude Fable 5, available on Bedrock" and assume the existing Bedrock terms apply. They don't. The retention policy lives in a footnote on a blog post, not in the model card that ends up in the vendor evaluation deck.
If you built on Bedrock specifically for the data boundary — and you know who you are — you have three options, none of them free.
Option one: stay on the older models. Fable 4 / Mythos 4 and older retain the original zero-retention terms. This works until your product team notices a competitor shipping with the new reasoning tier and the conversation becomes uncomfortable. Realistic timeline: six to nine months before this stops being viable.
Option two: accept retention with mitigations. Strip PII before the call. Tokenize. Run a redaction layer in front of every Bedrock invocation. This is the path most regulated shops will end up on, and it's the one your security team is going to spend Q3 building. The redaction proxy is about to become the most important piece of infrastructure in your AI stack, and almost nobody has one in production yet.
Option three: move the workload on-prem or to a smaller open model. Llama 4 and DeepSeek's recent releases are within striking distance of Fable 4 on most internal benchmarks. If your use case is summarization, classification, or structured extraction — which is most enterprise use cases — the gap to frontier is now small enough that the compliance math flips.
A fourth, narrower option: Anthropic's direct enterprise tier may negotiate custom retention terms for large customers. If you're spending seven figures, ask. The published terms are not the only terms.
Developers should also audit their Bedrock contracts for the specific language around "AWS data and security boundary." The retention change creates a real possibility that existing BAAs, DPAs, and customer contracts referencing that boundary are now technically out of compliance the moment you upgrade the model ID. That's a legal review, not an engineering one, and it needs to happen before, not after, the model swap PR lands.
The broader story here is that safety and privacy are starting to actively trade off at the frontier, and the labs are choosing safety. That's defensible — coordinated misuse of frontier reasoning models is a real problem — but it ends the era of "pick your cloud, get your data guarantees" as a clean abstraction. The next two years of enterprise AI architecture will be defined by who builds the best redaction, tokenization, and synthetic-data pipelines in front of the model call, because the model call itself is no longer a closed loop. Bet on tooling that assumes your prompts will be read by someone, eventually, and design accordingly.
> For Fable 5, Mythos 5, and future models on Bedrock with similar or higher capability levels, Anthropic will require 30-day retention for all traffic on Mythos-class models. Retaining data for a
→ read on Hacker NewsThis is odd behaviour, and provides some evidence that Anthropic isn't being managed by serious people. With this policy across AWS/GH/Zed/etc, they're taking their massive lead in enterprise/govt sales and handing it to any competitor who can serve a model anywhere nea
This policy applies across all providers. Here is the warning in Cursor: https://i.redd.it/7sfyker2ya6h1.pngNote that Anthropic has committed not to train models on logged data, so I don’t understand some of the concerns here. What exactly is your threat model? That Anthropic would tr
Pretty sure this doesn't work for any regulated enterprise or government client. But AWS knows this, so I am curious why they'd agree to it.
This smells like an advanced version of corporate espionage. Assuming most companies will use their AI in the future, this will be fed directly to an Echelon-like network that will be leaking "interesting info" to friendly parties, like the Boeing vs Airbus scandal that was first widely re
Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.
The root of the problem is that AI-as-a-service is corked, because companies providing it have a hell of an incentive to use all that data to out-compete their competitors, and they can do so in secret. To say nothing of salivating law-enforcement who really, really wants to tap into it. I'm ho