
Claude Fable 5 Just Dropped. Here Is What the Fine Print Says About Your Data.
When Anthropic released Claude Fable 5 today, I did what I always do with a new model launch. I went straight to the terms of service and privacy policy.
What I found is something that every lawyer building AI agents right now needs to read carefully before they write another line of code or onboard another client.
What Fable 5 Is
Claude Fable 5 is said to be “the most capable AI model” Anthropic has ever released to the public. It is a Mythos-class model, meaning it shares the same underlying architecture as Claude Mythos 5, a model that was previously restricted to a small number of vetted organizations through Project Glasswing due to its advanced capabilities in areas like cybersecurity and biological research.
Fable 5 makes those capabilities broadly available, but with safety classifiers layered on top. If you ask it something related to cybersecurity exploits, biological weapons, or model distillation, the classifiers either block the response or route it to a less capable model (Claude Opus 4.8). Anthropic’s early data suggests that more than 95% of sessions run entirely on Fable 5 without any fallback.
The model itself is genuinely impressive. State of the art on nearly every tested benchmark, with standout performance in software engineering, knowledge work, vision, and agentic tasks. But I did not open the terms of service to look at benchmarks. I wanted to know what they are doing with our and our clients’ data.
The Data Retention Requirement
Claude Fable 5 requires mandatory 30-day data retention. Every prompt you send and every output the model generates is retained by Anthropic for 30 days. During that period, Anthropic runs active safety classifiers through your content. These are separate AI systems designed to detect misuse patterns, including jailbreak attempts, distillation campaigns, and state-sponsored attacks.
Every other Claude model available through the API, including Opus 4.8, Sonnet 4.6, and Haiku 4.5, can operate under Zero Data Retention (ZDR) agreements. Fable 5 cannot. If your organization previously had a ZDR agreement with Anthropic, that agreement does not apply to Fable 5 traffic. This is a policy change that overrides existing enterprise commitments for this specific model class.
This policy applies to both first-party surfaces (claude.ai, Claude Code) and third-party platforms (AWS Bedrock, Google Cloud Agent Platform, Microsoft Foundry). There is no platform where you can run Fable 5 without data retention.
Before the alarm bells drown out everything else, there is a meaningful nuance here that the hot takes are missing.
If you are using Claude through the consumer plans (Free, Pro, or Max), Anthropic already retains your inputs and outputs for 30 days under the existing terms. That is not new, and the Fable 5 policy does not change anything for consumer users.
The change specifically impacts enterprise and API customers who had negotiated Zero Data Retention agreements. Those organizations were operating under the understanding that their data would not be stored at all. For Fable 5, and for future Mythos-class models, that understanding now has a mandatory exception.
Anthropic’s Access to Your Data
According to Anthropic’s published documentation and technical white paper, the retained data will not be used to train new models or for any non-safety purpose. Anthropic employees will have access to the data, though. But they can only access conversations that get flagged for potential serious harm. Access is restricted to a small set of approved reviewers using scoped tooling that prevents export, copying, or downloading. Every instance of human access is recorded in what they call a “tamper-proof” log. The data is automatically deleted after 30 days, similar to the consumer level accounts, with exceptions for active safety investigations or legal requirements. Eligible organizations can add customer-managed encryption keys and access transparency audit logs.
But there is a legal issue with this new program that has me very concerned for my fellow attorneys and their clients.
I have written previously about the intersection of AI tools and attorney-client privilege (see that article), most recently after Judge Rakoff’s ruling in United States v. Heppner in the Southern District of New York. In that piece, I argued that the court got it wrong when it held that using a consumer AI platform waived privilege and work product protection. My position is that AI platforms should be treated the same way we treat every other technology tool in legal practice.
We use Gmail to communicate with clients. We use Google Workspace and Microsoft Office to draft documents. We run research queries through Lexis and Westlaw. Every one of those platforms collects data, uses it to improve algorithms, and could theoretically be compelled to produce records. Yet no court has ever suggested that using Westlaw waives work product protection over your research strategy. The Michigan court got this right in Warner v. Gilbarco, holding that AI tools are tools, not persons, and that waiver requires disclosure to an adversary, not merely using software.
I have been making that argument because I believe lawyers should be using AI. It makes us more efficient, more thorough, and in many cases more effective for our clients. And as long as the AI platform is processing inputs through automated systems and returning outputs without any human being ever seeing the content, the analogy to other technology tools holds up.
Fable 5 complicates my own argument in a way that could be catastrophic to lawyers and their clients.
Anthropic’s terms for this model disclose that human reviewers can and do access flagged conversations. They have built what they call “controls” around that access: scoped viewers, no export, tamper-proof logs, a small number of approved reviewers. But the access exists. Anthropic is telling you, in writing, that humans at their company may review the content you run through this model.
That is where my concern starts. When I argued that AI platforms function like Westlaw or Google Docs, a key part of that argument was that no human outside the attorney-client relationship ever sees the content. The data passes through automated systems and comes back, just like with gmail or Outlook or Lexis/Westlaw. Nobody lays eyes on it. Fable 5 is different. If a human being at Anthropic can review a flagged conversation that contains privileged client communications, that is third-party disclosure. And voluntary disclosure to a third party remains one of the most established ways to waive attorney-client privilege.
The question a court will ask is whether the attorney took reasonable steps to maintain confidentiality. If the attorney voluntarily used a platform whose own terms of service say that human employees may review the content, the answer to that question gets uncomfortable. It does not matter that the review is limited to flagged content or that the reviewers use restricted tooling. What matters is that the attorney chose a platform that disclosed, upfront, that third-party human review was part of the arrangement. That is a voluntary choice, and a court evaluating privilege is going to examine it closely.
I wrote in my Heppner analysis that the protection should depend on the substance of the attorney’s thinking, not the medium used to develop it. I still believe that. But Fable 5 moves the medium from a purely automated system into something that includes human review, and that distinction is going to matter to judges who are already skeptical about AI and privilege.
The same concern applies to work product. If a lawyer is using Fable 5 to draft motions, analyze case law, develop litigation strategy, or prepare for depositions, all of that content is being retained on Anthropic’s servers for 30 days and is subject to potential human review.
Work product protection can be waived by disclosure to any third party in a way that substantially increases the risk that an adversary will obtain it. A lawyer running work product through a platform that retains it for 30 days and subjects it to human review is creating exactly that kind of exposure. And unlike privilege, which can sometimes be clawed back through quick action and a court order, work product waiver can be harder to unwind once material has been disclosed and retained on a third-party system.
While I hold fast to my position that AI tools should be treated like other technology tools for privilege purposes, Fable 5’s data retention and human review policy creates a scenario that undermines the basis of my position. And if you are a lawyer using this specific model for client work, you need to understand the risk before you use this model.
The Broader Agent Builder Problem
This analysis applies to lawyers specifically, but the underlying issue hits anyone with a confidentiality obligation. If you are building agents for clients, those agents interact with business systems. They read emails, process documents, analyze financials, draft communications. An agent built on Fable 5 means that every piece of data it touches gets retained on Anthropic’s infrastructure for 30 days while safety classifiers and, potentially, human reviewers scan through it.
If you are building for clients, remember whose data is actually being retained. Your clients’ business strategies, their operational details, their proprietary code, their sensitive communications, all sitting on someone else’s infrastructure for 30 days.
Anthropic could handle every byte of that data with perfect care, and it would not matter if your client agreements, your confidentiality obligations, and your data processing terms do not allow for this kind of third-party retention and active processing. For many practitioners and service providers, the answer is going to be no, at least not without updating those agreements first.
Practical Steps
If you are building agents or tools on Claude, check which model you are actually deploying. Opus 4.8, Sonnet, and Haiku still operate under ZDR if you have that agreement in place. Nothing changes for those models.
If you are a lawyer, or if you build tools for lawyers, do not run privileged communications or work product through Fable 5 until you have a clear answer on how this retention policy interacts with your privilege obligations in your jurisdiction. That answer may vary by state, by court, and by the nature of the engagement. Get it before you deploy. And that likely means you need to wait for judicial guidance before you know how this will be interpreted by the courts.
If you want to use Fable 5 for client work in any industry, read the full retention policy before you deploy. Anthropic has published a detailed help center article explaining the policy, and a technical white paper on their Trust Center covering the security architecture around retained data. Both are linked at the bottom of this article.
Review your client agreements. Does your confidentiality clause permit third-party data processing with 30-day retention and potential human review? Does your data processing agreement account for this? If not, you either need to update those agreements with appropriate disclosures or select a different model for that client work.
One more thing, and I will keep saying this until I am blue in the face: read the terms and privacy policy every time, and always review updates to those documents. The landscape is changing fast, and what was true for the model you used last month may not be true for that same model today.
You are going to see a lot of hype in the coming days telling you to build agents on the newest, shiniest model, which right now is Fable 5, but they are are rarely reading the terms of service or privacy policy before they post. That is your job. And your clients and the state bar are trusting you to do it.
Sources and Further Reading
Anthropic Terms of Service: https://www.anthropic.com/terms
Anthropic Privacy Policy: https://www.anthropic.com/legal/privacy
Data Retention for Mythos-Class Models: https://support.claude.com/en/articles/15425996-data-retention-practices-for-mythos-class-models
Fable 5 Model Switching FAQ: https://support.claude.com/en/articles/15363606-why-claude-switched-models-in-your-conversation-with-fable-5
Anthropic Blog – Claude Fable 5 and Claude Mythos 5: https://www.anthropic.com/news/claude-fable-5-mythos-5
Harvey AI – Fable 5 Availability: https://www.harvey.ai/blog/fable-5-now-available-in-harvey
About the Author
Jessica Eaves Mathews is the founder of Leverage Legal Group. She writes and speaks about the legal and operational risks of building with AI, with a focus on the terms, policies, and infrastructure decisions that most practitioners overlook.
Website: www.leveragelegalgroup.com
LinkedIn: linkedin.com/in/jessicaeavesmathews
Substack: jessicaeavesmathews.substack.com


