Three items in this issue ran ahead of their sources and have been corrected in place, and one has been withdrawn. This notice is permanent. All four were caught by re-reading the vendors' own pages against what we published.
1. Amazon Bedrock retention. As first published, this issue said the model provider “holds a veto” over retention and that your own account setting was “not the deciding vote.” That is not what AWS publishes. AWS's documentation states that “you always control your retention policy” — an account set to no retention causes the request to be blocked, not overridden — and that “the model provider does not review your content.” The issue also said retention is expressed as one of four modes; AWS names five. Corrected.
2. Mistral stateful exceptions. As first published, this issue implied batch processing sits outside Mistral's retention rule. Mistral's Privacy Policy names the Agents API and the Fine-Tuning API; the word “batch” does not appear. Corrected.
3. “Trains by default” — Mistral and Cohere. The comparison table stated as fact that both train on customer data by default. Neither company publishes that. Mistral's commercial terms make the default product-dependent without naming which products are which; Cohere documents an opt-out control without ever stating what happens if you leave it on. Both rows now report what the sources say and flag the rest as something to confirm in your own agreement.
4. DeepSeek price-change notice — withdrawn, not corrected. The price-notice table carried a row stating that DeepSeek's pricing page sets no notice period. That is a negative claim about another company's terms — the hardest kind to stand behind — and we have not been able to re-retrieve the page to confirm it. The row has been removed rather than left standing. It will return if and when the page has been read and captured.
Your rate card is reviewed by three people before you sign. The terms behind it are reviewed by nobody, and they move without an announcement. This is a weekly read of what the frontier AI vendors publish, what changed, and the question worth asking before you sign.
A client answers a security questionnaire: does your AI provider retain customer data? They read the vendor's trust page, see “zero data retention,” and answer no.
That answer is usually wrong — and not because the vendor lied. A questionnaire has a checkbox. The reality has four separate mechanisms, and answering for one while assuming it covers the others is how a confident answer becomes a false one.
| Mechanism | Why it gets missed |
|---|---|
| Training use | Everyone assumes “no by default” is universal across providers. It is not — see below. |
| Abuse monitoring | Data held so the vendor can investigate misuse. This survives most ZDR arrangements. |
| Operational logging | Data a feature needs in order to work at all. Eligibility is decided per feature, not per account. |
| Sub-processor retention | What the vendor's own vendors keep. The weakest-documented leg across every provider — nobody publishes it. |
| Provider | Trains on API data by default | The exclusion that matters most |
|---|---|---|
| OpenAI | No | Safety-retention override for severe-risk investigations; API inputs and outputs may be securely retained up to 30 days, except for certain endpoints and features listed in OpenAI's platform documentation. |
| Anthropic | No | Covered Models are unavailable under ZDR unless expressly authorized by Anthropic. Flagged sessions held up to two years regardless of arrangement — including under ZDR and under a HIPAA agreement. |
| Google Gemini | No on paid tiers. Free tier and AI Studio usage may be human-reviewed | Search and Maps grounding retain 30 days, with no opt-out. ZDR is applied for per project. |
| Mistral | Terms make the default product-dependent without naming which products; an account-level opt-out control is published. Confirm for your agreement. | Privacy Policy names Agents API and Fine-Tuning API as the stateful exceptions. ZDR is a written request that can be denied. |
| Cohere | Not stated — Cohere documents an opt-out Data Controls toggle but does not publish that it trains by default. Confirm for your agreement. | Usage metadata is never covered. ZDR is enterprise-agreement only. |
| AWS Bedrock | No | Retention is a mode setting — but only for models that permit it. AWS states “you always control your retention policy” — an account set to no retention has the request blocked rather than overridden, and review is carried out by AWS within the AWS boundary. |
⚠ Provider positions verified 8 September 2026 against each provider's own published documentation. Re-verify before any live negotiation — these pages change without announcement, which is the point of this newsletter.
The finding worth your attention
The Covered Models carve-out is a one-line diff. Anthropic designates certain models as Covered Models — currently the Claude Fable and Mythos 5 and 5.1 families. Those carry a 30-day retention requirement and are unavailable under zero data retention unless expressly authorised, even for a customer already holding an org-wide ZDR arrangement.
An engineer swaps a model string in a config file, doing exactly what you would want them to do. Code review does not flag it. The API response does not signal it. The contractual data posture has changed on one line, and the first anyone notices is the next audit.
And eligibility is per feature, not per account. Anthropic's published table: batch jobs retain 29 days · code-execution containers 30 days · Files API content persists until deleted. Mistral's Privacy Policy names two stateful exceptions to its thirty-day rule — the Agents API (input and output kept until you terminate the account) and the Fine-Tuning API (data kept until you delete it or terminate). So a client with a signed ZDR arrangement who turns on an agent framework, starts uploading files, or moves a workload onto batch processing to cut cost has moved data outside the arrangement. Nobody signed anything. Somebody used a feature.
One more structural point on Bedrock. Retention is expressed as one of five named modes rather than in days, and each model declares which modes it allows. AWS states that “you always control your retention policy” — but control and access are not the same thing. If your account is set to no retention and you invoke a model that requires retention, Bedrock blocks the request and returns an error. Your setting holds; the model becomes unavailable to you. AWS also states that review under aws_review is carried out within the AWS boundary and that “the model provider does not review your content.” The practical consequence is a procurement one: a model your team names in a config file may simply not run under the retention posture you signed up to, and nobody will tell you in advance which ones.
Every AI procurement reviews the rate card. Almost none reviews the clause governing what the vendor must do before that rate card changes. The answers diverge far more than the prices do.
| Vendor | Where the clause lives | Stated notice before a price change |
|---|---|---|
| OpenAI | Services Agreement §6.6 | 14 days after posting on the Pricing Page |
| Anthropic | Commercial Terms §H.1 | 30 days after posting, or when the customer otherwise receives notice — whichever is earlier |
| Gemini API Additional Terms | 30 days after posting; new paid services can take effect immediately |
⚠ Clause text pulled live 14 August 2026. Section numbers cited so you can check them yourself. A DeepSeek row was withdrawn on 18 September 2026 — see the corrections notice at the top.
Read the trigger: “after they are posted.” The clock does not start when the vendor tells the customer. It starts when the vendor edits a web page. If nobody on your side is watching that page, a full 30-day notice period can elapse without a single person at your company seeing it.
The same structure governs model deprecation and rate limits at most providers. Three clause families, one root defect: the vendor's obligation is discharged by publishing, not by communicating.
“You told me you have zero data retention. I believe you. Now show me which models, which features, and what the abuse-monitoring team keeps — because the honest answer to that question is a table, and the questionnaire only has a checkbox.”