As both AI giants compete to win over business customers, the stakes for organisations handling sensitive data — including public bodies here in Kent — are rising.
When a business hands over its internal data to an AI platform, what actually happens to it? That question is becoming one of the defining concerns of enterprise AI adoption — and two of the biggest names in the industry are now openly competing to offer the most reassuring answer.
TechCrunch reported on 19 August 2026 that a clear rivalry is forming between OpenAI and Anthropic over who can provide the strongest privacy protections for enterprise customers. The trigger was OpenAI’s announcement of a new service called Private Safety Processing, which the company describes as an automated system that monitors AI interactions for potential misuse without retaining any of the customer’s data. It’s a direct pitch to business and institutional users who need to know their confidential information isn’t being stored, analysed, or fed back into a model.
What OpenAI Is Actually Offering
OpenAI’s enterprise privacy position rests on several distinct commitments. By default, the company does not train its models on data from organisations using its enterprise products or API. For customers who want an even firmer guarantee, it offers Zero Data Retention API endpoints — meaning inputs and outputs are never logged at all.
Beyond that, OpenAI says business data is encrypted both at rest and in transit, and that enterprise customers using products like ChatGPT Enterprise, ChatGPT Edu, and ChatGPT Team can control how long their data is retained. When a user deletes a chat or closes an account, content is scheduled for permanent deletion within around 30 days, subject to legal or security requirements. API logs are handled on a similar timeline.
Private Safety Processing sits on top of all this. The idea is to give businesses safety monitoring — flagging misuse, checking for policy violations — without the privacy trade-off of having that monitoring process store or expose sensitive data. It’s a meaningful distinction for organisations in regulated industries.
Anthropic’s Position With Claude
Anthropic isn’t standing still. Its enterprise products — Claude Enterprise, Claude for Work, and Claude’s API — carry a clear pledge: enterprise data is never used to train Claude, full stop. Retention is governed by contract, with a default of around 30 days and Zero Data Retention options available for customers who need them. Anthropic’s documentation also includes GDPR-compliant data processing agreements, with rights for EU and EEA users covering access, deletion, and data portability.
But Anthropic has faced scrutiny over its consumer tier. Around August and September 2025, the company shifted its default for ordinary Claude users from an opt-in model to an opt-out one — meaning personal chats could be used for training unless users actively changed their settings. If a consumer user opts out, conversations are held for about 30 days before deletion; if they opt in, data can be retained for up to five years for training and safety purposes. That’s a long time.
Critics have pointed out the gap between how enterprise and consumer users are treated. The burden of protecting privacy, they argue, falls too heavily on individuals who may not realise they need to change a setting.
The Wider Picture
Both companies frame strong enterprise privacy as a selling point rather than a regulatory obligation — though the two aren’t mutually exclusive. UK GDPR requires organisations to have lawful grounds for processing personal data, to minimise what they collect, and to ensure appropriate retention limits. Any UK business or public body using these platforms as a data processor needs a data processing agreement in place, and needs to be confident the provider meets those standards.
Third-party privacy analysts broadly agree that for enterprise and API customers, both OpenAI and Anthropic now offer comparable baseline protections: no training on customer data by default, encryption, configurable retention. The competition, then, is increasingly about the details — and about trust.
That matters. As more organisations integrate generative AI into internal workflows, customer support, and analytics, the volume of sensitive information flowing through these platforms is growing fast.
A Confusing Landscape for Ordinary Users
Here’s where it gets genuinely complicated for everyday people. The same company — OpenAI or Anthropic — can have very different privacy defaults depending on whether you’re using a free personal account or an enterprise deployment at work. A solicitor using Claude Enterprise at the office operates under strict contractual protections. The same person using the free Claude app at home is subject to a different set of defaults entirely.
That’s not necessarily wrong, but it does require people to understand which version they’re using and what it means.
What This Means for Kent Residents
For Kent businesses — from professional services firms in Maidstone to SMEs along the Thames Estuary — that use OpenAI or Anthropic tools through enterprise contracts or API access, these privacy commitments are directly relevant to their legal obligations under UK GDPR. Public bodies such as Kent County Council, Medway Council, and NHS Kent and Medway ICB, which may work with AI suppliers handling sensitive personal data including health and social care records, will need to ensure any provider offers compliant data processing agreements and appropriate retention controls. And for anyone in Kent using the free, consumer versions of ChatGPT or Claude at home, it’s worth checking your privacy settings — the defaults may not be what you’d expect.
Source: @TechCrunch
OpenAI Launches Private Safety Processing to Rival Anthropic on Enterprise Data Privacy Quiz
5 questions