{"id":20291,"date":"2026-09-15T09:59:51","date_gmt":"2026-09-15T07:59:51","guid":{"rendered":"https:\/\/haimagazine.com\/uncategorized\/is-the-best-ai-the-one-that-remembers-nothing\/"},"modified":"2026-09-21T12:46:52","modified_gmt":"2026-09-21T10:46:52","slug":"is-the-best-ai-the-one-that-remembers-nothing","status":"publish","type":"post","link":"https:\/\/haimagazine.com\/en\/hai-premium-2\/is-the-best-ai-the-one-that-remembers-nothing\/","title":{"rendered":"\ud83d\udd12 Is the best AI the one that remembers nothing?"},"content":{"rendered":"<p class=\"wp-block-paragraph\">JUntil recently, the most important question when choosing an AI model was: which one is the best? Which is better at writing code, analyzing documents, solving problems and handling increasingly complex tasks?<\/p><p class=\"wp-block-paragraph\">Today, some companies are starting to ask a different question: what exactly happens to the information we give this model?<\/p><p class=\"wp-block-paragraph\">Palantir doesn\u2019t want to make some of Anthropic\u2019s most advanced models available to its customers without additional guarantees about data retention. Nvidia is restricting the use of Claude for more sensitive tasks. Booz Allen Hamilton has prohibited the use of commercial versions of Claude for some of its cybersecurity work. As <a href=\"https:\/\/www.reuters.com\/business\/palantir-nvidia-curb-ai-model-use-over-data-fears-information-reports-2026-09-14\/\" target=\"_blank\" rel=\"noopener\"><mark style=\"background-color:#82D65E\" class=\"has-inline-color has-base-color\">Reuters reported<\/mark><\/a>, the common concern is data security and the protection of intellectual property.<\/p><p class=\"wp-block-paragraph\">This doesn\u2019t mean there\u2019s suddenly a crisis of confidence in artificial intelligence. But it does highlight a problem that will probably become increasingly important as AI advances.<\/p><p class=\"wp-block-paragraph\">Because the more AI can do for a company, the more the company first has to tell it.<\/p><h4 class=\"wp-block-heading\">An AI you can\u2019t show everything<\/h4><p class=\"wp-block-paragraph\">The issue gained prominence after Anthropic changed the rules for its most advanced models. The company introduced a category known as Covered Models. For these models, prompts submitted by business users and the model\u2019s responses are retained for 30 days. The policy also applies to organizations that previously used Zero Data Retention, or ZDR. Under ZDR, the provider doesn\u2019t retain data after processing a request.<\/p><p class=\"wp-block-paragraph\">Anthropic explains in its <mark style=\"background-color:#82D65E\" class=\"has-inline-color has-base-color\"><a href=\"https:\/\/privacy.claude.com\/en\/articles\/15425996-data-retention-practices-for-covered-models\" target=\"_blank\" rel=\"noopener\">Covered Models documentation<\/a><\/mark> that the change applies to organizations using ZDR directly through Claude as well as through selected cloud platforms.<\/p><p class=\"wp-block-paragraph\">For most users, the difference may seem like a technical detail. For a company working with confidential information, however, it\u2019s fundamental.<\/p><p class=\"wp-block-paragraph\">If an employee asks a model to polish an ordinary email, 30-day retention probably won\u2019t be a major concern. But the situation looks very different if a developer submits a piece of code from a product under development, an analyst works with nonpublic financial data or a security specialist gives the model details of a vulnerability that hasn\u2019t yet been discovered by others.<\/p><p class=\"wp-block-paragraph\">A prompt stops being just a question and it becomes part of the company\u2019s documentation.<\/p><p class=\"wp-block-paragraph\">According to Reuters, this is precisely why Nvidia is restricting the use of Anthropic models for more sensitive tasks. Palantir has gone further, seeking a ZDR guarantee from Anthropic that the provider couldn\u2019t later revoke unilaterally. Booz Allen, meanwhile, has banned the use of commercial Claude products for some of its cybersecurity work.<\/p><p class=\"wp-block-paragraph\">Companies aren\u2019t abandoning AI. They\u2019re starting to define what AI isn\u2019t allowed to see.<\/p><h4 class=\"wp-block-heading\">The prompt may be worth more than the answer<\/h4><p class=\"wp-block-paragraph\">During the first few years of the generative AI boom, the discussion around data focused primarily on the risk that an employee might thoughtlessly paste part of a contract, customer data or a confidential document into a public chatbot. That problem hasn\u2019t disappeared, but the scale of AI use has changed.<\/p><p class=\"wp-block-paragraph\">Models are no longer used only to write text or summarize documents. They\u2019re given source code, product designs, research results, financial data, internal procedures and customer information. Increasingly, they\u2019re also connected to other company systems, while AI agents are given access to databases, applications and code repositories.<\/p><p class=\"wp-block-paragraph\">In this setup, the information supplied to the model may be worth far more than its answer. Importantly, storing data isn\u2019t the same as using it to train a model.<\/p><p class=\"wp-block-paragraph\">Anthropic states in its <mark style=\"background-color:#82D65E\" class=\"has-inline-color has-base-color\"><a href=\"https:\/\/privacy.claude.com\/en\/articles\/7996868-is-my-data-used-for-model-training\" target=\"_blank\" rel=\"noopener\">policy for commercial products<\/a><\/mark> that inputs and outputs from Claude for Work, the API and Claude Gov aren\u2019t used for model training by default. That can change if the customer explicitly agrees, including by submitting a conversation as feedback. The distinction matters because public discussions often conflate several different issues.<\/p><p class=\"wp-block-paragraph\">The first is retention: does the provider keep the prompt and response, and if so, for how long? The second is training: can that data later be used to improve models? The third is access: who can see stored content and under what circumstances? And finally, there\u2019s security monitoring: analyzing how models are used to detect abuse.<\/p><p class=\"wp-block-paragraph\">Only when these elements are separated does the real problem become clear.<\/p><h4 class=\"wp-block-heading\">Why does AI want to remember?<\/h4><p class=\"wp-block-paragraph\">The simplest solution would seem obvious: if companies don\u2019t want their data stored, the provider should simply not store it. But from Anthropic\u2019s perspective, that\u2019s precisely where the problem begins.<\/p><p class=\"wp-block-paragraph\">The company argues that serious abuse may become apparent only when security systems analyze a sequence of interactions. Its examples include espionage campaigns and attempts to extort data. A single prompt may look harmless. Only a series of requests reveals what the user is actually trying to do.<\/p><p class=\"wp-block-paragraph\">That\u2019s why Anthropic requires 30-day retention of prompts and responses for Covered Models.<\/p><p class=\"wp-block-paragraph\">According to the company, its employees can\u2019t read these conversations by default. Human access is supposed to occur only through a controlled process, for example when automated security systems flag content as potentially dangerous. Only approved employees can review it, and every instance of access is logged. After 30 days, the data is automatically deleted unless it has been flagged for security reasons or the company is legally required to retain it.<\/p><p class=\"wp-block-paragraph\">From a model security perspective, this makes sense. The problem is that from the customer\u2019s security perspective, the exact opposite approach may make just as much sense.<\/p><h4 class=\"wp-block-heading\">Security versus security<\/h4><p class=\"wp-block-paragraph\">Imagine a company developing technology worth billions of dollars. Its employees want to use the best available model to analyze code. The AI provider says: I need to retain this data for a while because that\u2019s the only way I can detect serious abuse. The customer replies: precisely because this code is so valuable, I don\u2019t want another copy of it to exist outside an environment I control.<\/p><p class=\"wp-block-paragraph\">Both sides are trying to improve security. Just not the same kind of security.<\/p><p class=\"wp-block-paragraph\">Anthropic wants to reduce the risk of its models being used for dangerous purposes. The enterprise wants to protect its intellectual property, trade secrets and customer data from leaving its control. Every additional place where information is stored creates another piece of infrastructure that needs to be secured. Even if the provider promises a very high level of protection, some organizations may follow a simple rule: the most sensitive information shouldn\u2019t be stored outside their own environment at all.<\/p><p class=\"wp-block-paragraph\">And that\u2019s why ZDR may go from an obscure acronym buried in a technology vendor contract to one of the requirements for deploying AI.<\/p><h2 class=\"wp-block-heading\">Memory as a problem, not a feature<\/h2><p class=\"wp-block-paragraph\">The paradox is even greater because AI development is moving in the opposite direction.<\/p><p class=\"wp-block-paragraph\">Models are supposed to remember context, carry out increasingly long tasks, use multiple tools and keep track of successive stages of a process. That\u2019s exactly what allows them to take on more complex work.<\/p><p class=\"wp-block-paragraph\">At the same time, the largest business customers may increasingly expect model providers to remember as little as possible.<\/p><p class=\"wp-block-paragraph\">This isn\u2019t just an Anthropic problem. In August, OpenAI announced expanded access to Zero Data Retention for its most advanced models. The company says that for eligible API customers, prompts and responses aren\u2019t retained after a request has been processed, while business customer data isn\u2019t used for training without explicit consent. <mark style=\"background-color:#82D65E\" class=\"has-inline-color has-base-color\"><a href=\"https:\/\/openai.com\/pl-PL\/index\/offering-zero-data-retention-for-frontier-models\/\" target=\"_blank\" rel=\"noopener\">OpenAI also announced Private Safety Processing<\/a><\/mark>, a mechanism designed to detect dangerous patterns spanning multiple interactions without exposing their content to company employees.<\/p><p class=\"wp-block-paragraph\">It\u2019s an interesting direction because it attempts to reconcile two conflicting requirements: analyzing user behavior over time while allowing enterprises to retain control over their data.<\/p><p class=\"wp-block-paragraph\">A similar problem can be addressed at the infrastructure level. Microsoft states in its <mark style=\"background-color:#82D65E\" class=\"has-inline-color has-base-color\"><a href=\"https:\/\/learn.microsoft.com\/pl-pl\/azure\/foundry\/responsible-ai\/openai\/data-privacy\" target=\"_blank\" rel=\"noopener\">Foundry documentation<\/a><\/mark> that prompts, responses and training data from customers using models hosted on Azure aren\u2019t accessible to the underlying model provider and aren\u2019t used to train models without the customer\u2019s consent. The models themselves are hosted in the Microsoft Azure environment rather than in the infrastructure of their original providers.<\/p><p class=\"wp-block-paragraph\">The AI race is therefore starting to encompass more than model intelligence alone.<\/p><h4 class=\"wp-block-heading\">A benchmark for data security<\/h4><p class=\"wp-block-paragraph\">For several years, models were compared using relatively straightforward criteria. Which one is better at coding? Which has a larger context window? Which makes fewer mistakes? Which is faster and cheaper? For some enterprises, a new set of questions may become just as important: Where is our information processed? How long is it retained? Who can gain access to it? What happens to it once the task is complete? Can the rules be changed later? Can we use our own encryption keys? Does the information remain in an environment controlled by the customer?<\/p><p class=\"wp-block-paragraph\">This could lead to a situation that would have seemed strange not long ago: a company has access to a model that is clearly better in benchmarks but deliberately chooses a slightly weaker one.<\/p><p class=\"wp-block-paragraph\">The reason may have nothing to do with price.<\/p><p class=\"wp-block-paragraph\">The weaker model may operate in an environment where the organization has greater control over its information. That allows the company to safely give it the full set of data required for the task, while the better model might receive only part of that data or might not be usable in that process at all.<\/p><h4 class=\"wp-block-heading\">Not one AI, but several<\/h4><p class=\"wp-block-paragraph\">There\u2019s another consequence.<\/p><p class=\"wp-block-paragraph\">Companies may not end up choosing a single \u201ccompany AI model\u201d in the same way they choose an office suite or messaging platform. A division based on the type of task and the sensitivity of the information seems much more likely.<\/p><p class=\"wp-block-paragraph\">One model might handle routine communication, research and work with public materials. Another might be used by developers. Yet another solution could be reserved for the most confidential data, perhaps in a private cloud or infrastructure under more complete organizational control.<\/p><p class=\"wp-block-paragraph\">In that environment, the question \u201cWhich model is the best?\u201d may become less important. Another question will take its place: <strong>Which model can we show this particular data to?<\/strong><\/p><p class=\"wp-block-paragraph\">This approach may become especially important as AI agents advance. A model that simply answers a question receives a limited piece of information. An agent performing a longer task might read documents, search an inbox, inspect a repository and combine information from several systems.<\/p><p class=\"wp-block-paragraph\">The more autonomy it gets, the more of the organization it can see.<\/p><h4 class=\"wp-block-heading\">The best doesn\u2019t always mean the best for the business<\/h4><p class=\"wp-block-paragraph\">The cases of Palantir, Nvidia and Booz Allen don\u2019t show that enterprises are losing trust in AI, but something more interesting: the criteria for that trust are beginning to change. Model capabilities are growing. At the same time, models are increasingly being used precisely where a company\u2019s most valuable information resides. Code. Customer data. Strategies. New product designs. Research results. The knowledge that gives the company its competitive advantage.<\/p><p class=\"wp-block-paragraph\">That\u2019s why the next stage of AI adoption may not be just about opening more doors to models. Sometimes, companies will have to decide which ones should remain closed.<\/p>","protected":false},"excerpt":{"rendered":"<p>The biggest limitation of AI in business may soon be not its quality, but trust. The more valuable the data companies feed into models, the more important it becomes to ask who stores that data, who can access it and what happens to it afterward.<\/p>\n","protected":false},"author":465,"featured_media":20246,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"rank_math_lock_modified_date":false,"footnotes":""},"categories":[832,796,837],"tags":[],"popular":[],"difficulty-level":[38],"ppma_author":[892],"class_list":["post-20291","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-editors-picks","category-hai-premium-2","category-safety-2","difficulty-level-medium"],"acf":[],"authors":[{"term_id":892,"user_id":465,"is_guest":0,"slug":"kmironczuk","display_name":"Krzysztof Miro\u0144czuk","avatar_url":{"url":"https:\/\/haimagazine.com\/wp-content\/uploads\/2025\/10\/awatar-2.png","url2x":"https:\/\/haimagazine.com\/wp-content\/uploads\/2025\/10\/awatar-2.png"},"first_name":"Krzysztof","last_name":"Miro\u0144czuk","user_url":"","job_title":"","description":"Od lat zajmuj\u0119 si\u0119 nowymi technologiami w biznesie, edukacji i codziennym \u017cyciu. W centrum mojej uwagi pozostaje cz\u0142owiek \u2013 i to, by technologia wyr\u00f3wnywa\u0142a szanse, zamiast tworzy\u0107 bariery."}],"_links":{"self":[{"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/posts\/20291","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/users\/465"}],"replies":[{"embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/comments?post=20291"}],"version-history":[{"count":1,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/posts\/20291\/revisions"}],"predecessor-version":[{"id":20292,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/posts\/20291\/revisions\/20292"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/media\/20246"}],"wp:attachment":[{"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/media?parent=20291"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/categories?post=20291"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/tags?post=20291"},{"taxonomy":"popular","embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/popular?post=20291"},{"taxonomy":"difficulty-level","embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/difficulty-level?post=20291"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/haimagazine.com\/en\/wp-json\/wp\/v2\/ppma_author?post=20291"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}