AI moves fast. A new model is released, a provider changes its terms, a court hands down a ruling — and what was safe to put into a tool yesterday may not be safe today. Whakatūpato flags these developments as they happen: each one dated, sourced, and linked to the tool it affects.
An alert is a heads-up between our full reviews, not a verdict. It never changes a tool’s colour on its own — when a development changes what is safe, we re-review the tool and say so on its profile.
The 30-day retention, explained: what it is for, and our view
Fable 5 is back, and with it the question we have been asked most since 9 June: how worried should you be about the 30-day retention? Start with what the retention is for. Anthropic retains prompts and outputs "for trust and safety purposes", and the purpose is specific: some misuse only shows up across a run of requests, not in any single prompt, so when something trips a safety check, the surrounding 30 days shows whether it is part of a pattern that breaches the usage policy. Nobody reads the retained material by default. Human review happens only on a safety flag, is confined to approved reviewers, and is logged. The data is not used to train models. Material a flag catches can be held for up to two years.
Looked at that way, this is standard cloud practice rather than something exotic. Every provider that hosts your material — the company holding your email, your documents, your practice-management system — reserves the right to look at what it hosts if it suspects the service is being used in breach of its terms, and most hold your material for far longer than 30 days. What is genuinely new about Fable 5 is narrower: a zero-retention arrangement cannot be contracted for this model, so the window cannot be shortened by anyone, however large the customer.
Our view: the retention itself does not put confidentiality, privilege or the Privacy Act in issue. The material is held for you and processed for you, on a no-training footing, with no one reading it by default — the same processor logic as the rest of the cloud you already work in, and the analysis in our privilege guidance applies unchanged. One thing still deserves thought: the flagged-content pathway is the one place human eyes can reach retained material, and a false positive is realistic where your work describes serious conduct, as litigation and investigation work does.
Our framework colours do not move on a bulletin, and the assessments remain made against Opus, Sonnet and Haiku, which keep zero retention on the API and Enterprise. Where a matter genuinely depends on a zero-retention arrangement, the established models remain the conservative answer. For everything else, treat Fable 5 as you would any well-run cloud service: know what the provider can do, and choose what you put in accordingly.
Data retention practices for Mythos-class models — Anthropiclive sourcePerma.cc recordas at 11 June 2026
Export controls on Fable 5 and Mythos 5 lifted (statement, 1 July 2026) — Anthropiclive sourcePerma.cc recordas at 1 July 2026
Fable 5 and Mythos 5: export controls lifted, access restored
On 1 July 2026 Anthropic said the US Department of Commerce had lifted the export controls it imposed on 12 June, and that it would begin restoring access to Claude Fable 5 and the research model Mythos 5. A licence is no longer required to use the models outside the United States. The suspension we reported on 13 June is therefore over: Fable 5 is returning across Anthropic's platforms.
The retention position we flagged on 11 June returns with the model. Fable 5 carries the Mythos-class 30-day retention requirement, which overrides zero-data-retention agreements with no opt-out, so it does not sit behind zero retention the way the established models do. Our framework was assessed against Opus 4.8, Sonnet and Haiku, which continue to support zero retention; do not read those assessments across to Fable 5. Where confidential or privileged work depends on a zero-retention arrangement, remain on the established models until Fable 5 has been cleared for that use.
Export controls on Fable 5 and Mythos 5 lifted (statement, 1 July 2026) — Anthropiclive sourcePerma.cc recordas at 1 July 2026
Anthropic says Trump admin has lifted export controls on Claude Fable 5 and Mythos 5 — CNBClive sourcePerma.cc recordas at 1 July 2026
A consumer Privacy Policy update: connected apps and agentic tasks
On 24 June 2026 Anthropic emailed users to announce an updated Privacy Policy for its consumer plans: Claude Free, Pro and Max. The notice is a study in what these announcements leave out. It does not say when the change takes effect. The policy itself is dated "Effective July 8, 2026". Nor does it say, in any usable way, what changes. It lists headings and refers you to the full document. The one thing it states plainly is scope. The changes affect consumer accounts, not the business plans (Team, Enterprise and the Platform), which run under the Commercial Terms and are untouched.
The substance, once you open the policy, matters more than the email suggests. For the first time in these terms it sets out what a connected, agentic Claude does with your data. It "may send your Inputs, Outputs, and instructions to Third-Party Services to perform actions on your behalf (such as reading files, sending messages, or retrieving information)". Depending on the permissions you grant, some outputs "may result in actions with effects outside the Services, such as sending communications, modifying files, or interacting with third-party services on your behalf". The standing commitments are unchanged. Anthropic says it does not sell your data, Claude remains ad-free, and the control over whether your chats train its models stays with you.
This documents what connected and agentic use already involves. It does not grant a new permission, and it moves no colour on our framework, which assesses what you put into the tool. The connector question sits alongside the grid. We take it up in our guidance note, "When the tool connects to my other apps, where does my data go?" If you are on a consumer plan, read the updated policy in full. You will not get it from the email.
Privacy Policy (consumer plans; effective 8 July 2026) — Anthropiclive sourcePerma.cc recordas at 24 June 2026
Fable 5 and Mythos 5: pulled by US government order
On 12 June 2026, three days after releasing it, Anthropic disabled Claude Fable 5, together with the research model Mythos 5, for every user worldwide. It acted to comply with an export-control directive issued that afternoon by the US Commerce Department on national-security grounds. Existing Fable 5 sessions and any new requests now return an error. The established Claude models (Opus 4.8, Sonnet 4.6 and Haiku 4.5) are unaffected and remain available.
Anthropic says it disagrees with the order, which it traces to "the finding of a narrow potential jailbreak", and that this should not "be cause for recalling a commercial model deployed to hundreds of millions of people". It has pledged to work towards restoring access, but has given no date.
For our readers, two things follow. The retention concern we flagged on 11 June is, for the moment, academic: Fable 5 cannot be used, so nothing can be put into it. And our framework, assessed against the established models, is unaffected and stands. If you moved confidential work onto Opus, Sonnet or Haiku on our earlier note, stay there: they remain available, and zero retention on the API and Enterprise is intact.
Access to Fable 5 and Mythos 5 (statement, 12 June 2026) — Anthropiclive sourcePerma.cc recordas at 13 June 2026
Anthropic disables access to Fable 5 and Mythos 5 to comply with government directive — CNBClive sourcePerma.cc recordas at 13 June 2026
On 9 June 2026 Anthropic released Claude Fable 5, with a data-retention requirement specific to this class of model: prompts and outputs are retained for 30 days "for trust and safety purposes", on every platform that offers it, and the requirement overrides zero-data-retention agreements, with no opt-out. Anthropic states the retained data is not used to train models, access by staff is confined and logged, and consumer plans (Free, Pro and Max) are unaffected.
Our framework was assessed against the established Claude models (Opus, Sonnet and Haiku), which continue to support zero retention; it does not apply to Fable 5. In particular, do not read our API and Enterprise assessments across to Fable 5: where confidential or privileged work depends on a zero-retention arrangement, remain on the established models until Fable 5 has been cleared for that use.
Data retention practices for Mythos-class models — Anthropiclive sourcePerma.cc recordas at 11 June 2026
Claude Fable 5 and Claude Mythos 5 (release announcement, 9 June 2026) — Anthropiclive sourceas at 11 June 2026
AI tools change their data and privacy terms without warning. We monitor the shifts so you don't have to. Subscribe to receive immediate alerts when a change impacts your security or compliance.