메뉴
HN
Hacker News 49일 전

앤스로픽, 신형 AI 모델 데이터 30일 의무 보관

IMP
8/10
핵심 요약

앤스로픽이 고성능 신규 모델인 '클로드 미토스(Mythos) 5'와 '페이블(Fable) 5'에 대해 안전성 및 악용 방지를 목적으로 프롬프트 및 출력 데이터를 30일간 의무적으로 보관하는 정책을 도입했습니다. 이번 조치는 기존에 데이터를 저장하지 않던(ZDR) 기업 및 플랫폼(API 등) 고객에게만 해당되며, 일반 소비자 요금제 사용자에게는 변화가 없습니다.

번역된 본문

미토스(Mythos) 등급 모델을 안전하게 배포하기 위해, 우리는 안전성 업무의 일환으로 제한적인 데이터 보관 및 검토를 의무화하고 있습니다. 이 모델들이 제공되는 모든 플랫폼에서 신뢰 및 안전(Trust and Safety) 목적을 위해 미토스 등급 모델에 입력된 프롬프트와 생성된 출력물은 30일 동안 보관됩니다. 이 정책은 미토스 등급 모델과 향후 유사한 기능을 가진 '적용 대상 모델(covered models)'로 지정될 모델들에 적용됩니다. 다른 모든 모델을 사용하시는 경우에는 기존 이용 약관이 그대로 유지되며 이번 변화의 영향을 받지 않습니다. 아래에 설명된 이 정책은 2026년 6월 9일부터 시행됩니다. 보관된 데이터에 대한 위협 모델 및 관련 개인 정보 보호 통제에 대한 자세한 내용은 저희 트러스트 센터(Trust Center)의 관련 기술 백서를 참조하십시오.

적용 대상 저희 웹, 데스크톱 및 모바일 앱(Claude.ai 및 Claude Code 포함)의 개인용 요금제(Claude Free, Pro, Max)는 이미 안전을 위해 입출력 데이터를 보관하고 있으므로 이번 업데이트의 영향을 받지 않습니다. 개인용 요금제의 데이터 보관 방식에 대해 더 자세히 알아보세요. 이번 변경은 Claude Console에서 제로 데이터 보관(ZDR)을 설정한 조직, Claude Enterprise에서 ZDR을 사용하여 Claude Code를 사용하는 조직, 또는 AWS Bedrock, Google Cloud Agent Platform, Microsoft Foundry를 통해 ZDR 상태에서 Claude에 액세스하는 조직에만 적용됩니다. 이 문서의 나머지 부분은 이러한 조직에만 해당됩니다.

도입 배경 Claude 미토스 5는 모델 기능이 크게 향상되었으며, 그중 일부는 유익한 목적과 악의적인 목적 모두에 사용될 수 있습니다. Claude 페이블 5는 Claude 미토스 5와 동일한 기본 모델을 공유하지만, 특히 사이버 및 생물학적 분야에서 추가적인 안전 장치를 갖추고 있습니다. 이러한 안전 장치 덕분에 우리는 이 지능을 더 광범위하게 공유할 수 있지만, 이 등급의 모델에서 악용 패턴을 찾을 수 있도록 보수적인 접근 방식을 취하고 있습니다. 일부 공격은 여러 요청에 걸쳐서만 식별할 수 있습니다. 예를 들어, 'Best-of-N 탈옥(jailbreaking)'은 하나의 프롬프트가 작동하기를 희망하여 수백 개의 미묘하게 다른 변형을 보냅니다. 국가 후원 첩보 활동이나 데이터 갈취 캠페인과 같은 대규모 악용 패턴은 우리의 안전 분류기가 여러 요청을 전체적으로 살펴볼 때만 드러납니다. 이러한 위협을 탐지하려면 프롬프트와 출력을 일시적으로 보관하여 개별적으로 분석하는 대신 함께 분석할 수 있어야 합니다.

데이터 보호 방법 심각한 잠재적 위해로 플래그가 지정되거나 고객의 서면 요청이 있는 경우가 아니면 Anthropic 직원은 고객의 대화에 액세스할 수 없습니다. 이러한 검토는 데이터 내보내기, 복사 또는 다운로드를 방지하는 도구를 통해서만 소수의 승인된 검토자가 수행할 수 있습니다. 모든 액세스 인스턴스는 검토자가 억제하거나 수정할 수 없는 변조 방지 로그에 기록됩니다. 30일이 지나면 안전 조사의 일환이거나 법적으로 보관이 요구되는 드문 경우를 제외하고 데이터는 자동으로 삭제됩니다. 해당되는 조직은 고객 관리 암호화 키(CMEK)를 추가하고 액세스 투명성 감사 로그를 확인할 수도 있습니다. Anthropic은 고객 데이터의 보안, 기밀성 및 무결성을 보호하기 위해 설계된 기술 및 조직적 조치를 포함하는 문서화된 정보 보안 프로그램을 유지하고 있습니다. 위험 기반 프로그램은 알려진 위협 모델과 예상되는 위협 모델을 방어하기 위해 구축되고 발전하며 정기적으로 테스트됩니다. 자세한 내용은 트러스트 센터의 기술 백서를 참조하십시오.

구성 필요 사항 이번 변경은 앞서 언급한 Claude Console에서 ZDR을 설정한 조직, Enterprise에서 ZDR과 함께 Claude Code를 사용하는 조직, 또는 AWS Bedrock, Google Cloud Agent Platform, Microsoft Foundry를 통해 ZDR 설정으로 Claude에 액세스하는 조직에만 적용됩니다. 다른 모든 조직의 경우 변경 사항이 없으며 구성할 필요가 없습니다. 이 섹션의 나머지 부분은 현재 데이터를 보관하지 않고 Claude에 액세스하여 지정된 모델을 사용할 때 데이터 보관을 설정해야 하는 조직을 위한 것입니다.

원문 보기
원문 보기 (영어)
To ensure we’re responsibly deploying Mythos-class models, we are requiring limited data retention and review as part of our safety work. Prompts submitted to, and outputs generated by, Mythos-class models are retained for 30 days for trust and safety purposes, on every platform where these models are offered. This applies to Mythos-class models and future models with similar capabilities that we designate as covered models . For all other models, everything you use is unaffected and stays under the current terms. This policy, described below, goes into effect on June 9, 2026. For more information on the threat model for retained data and associated privacy controls, please see the corresponding technical white paper on our Trust Center. Who this applies to Consumer plans (Claude Free, Pro, and Max) across our web, desktop, and mobile apps—including Claude.ai and Claude Code—are unaffected by this update, since we already retain inputs and outputs for safety purposes on these surfaces. Learn more about how we retain data for consumer plans. This change only applies to organizations that have set up workspaces with zero data retention (ZDR) in Claude Console, use Claude Code with ZDR in Claude Enterprise, or access Claude through AWS Bedrock, Google Cloud Agent Platform, or Microsoft Foundry with ZDR. The rest of this article applies only to these organizations. Why we’re doing this Claude Mythos 5 represents a substantial increase in model capabilities, some of which can be used for both benign and malicious purposes. Claude Fable 5 shares the same underlying model as Claude Mythos 5, but with additional safeguards, particularly in the cyber and bio domains. While these safeguards allow us to share this intelligence more broadly, we are taking a conservative approach that allows us to look for patterns of misuse with this class of model. Some attacks only become visible across multiple requests. Best-of-N jailbreaking , for example, sends hundreds of slight variations of a prompt in the hope that one will work. Larger patterns of misuse, such as state-sponsored espionage or data extortion campaigns , only surface when our safeguards classifiers can zoom out across many requests. Detecting these threats requires temporarily retaining prompts and outputs so they can be analyzed together, rather than one at a time. How we protect your data Anthropic employees cannot access your conversations unless they are flagged for potential serious harm or upon a customer’s written request. These reviews can only be performed by a small set of approved reviewers through tooling that prevents export, copying, or downloading. Every instance of access is recorded in a tamper-proof log that reviewers cannot suppress or modify. After 30 days, the data is deleted automatically, except in the rare cases where it's part of a safety investigation or we're legally required to keep it. Eligible organizations also have the option to add customer-managed encryption keys and access transparency audit logs. Anthropic maintains a documented information security program with technical and organizational measures that are designed to protect the security, confidentiality, and integrity of customer data. Our risk-based program is built for and evolves to defend against known and anticipated threat models and is tested regularly. For more information, see the technical white paper in our Trust Center. What, if anything, do I need to configure? This change only applies to organizations that have set up workspaces with zero data retention (ZDR) in Claude Console, use Claude Code with ZDR in Claude Enterprise, or access Claude through AWS Bedrock, Google Cloud Agent Platform, or Microsoft Foundry with ZDR. For all other organizations, there is no change and there's nothing to configure. The rest of this section is for organizations that access Claude without data retention today and need to set up data retention in order to use designated models when they become available. If your developers use the Claude API Directly from Anthropic through Claude Platform: Turn on retention for the workspaces where you want to use covered models in the developer console ( Workspace > Manage > Privacy Controls ). Your other ZDR-enabled workspaces keep ZDR. Refer to the Anthropic Trust Center for documentation . Through Claude Platform on AWS: Retention works the same way as the direct Claude API. It's configured at the workspace level, and retained data is handled by Anthropic under the same controls. Through Amazon Bedrock: Retention will need to be enabled to access your new covered model, and retained data stays in your AWS environment. When models become available, onboarding details will be shared. Through Google Cloud's Agent Platform: Retention will need to be enabled for your new covered model, and retained data stays in your GCP environment. When models become available, onboarding details will be shared. Through Claude in Azure Foundry: Retention is configured for each Azure Subscription. If you have Zero Data Retention configured, then you will need to create and use a separate Azure Subscription to access these models. If your team uses Claude Code Through the Anthropic API: Claude Code’s data handling practices are governed by the workspace it operates in. If that workspace has retention enabled, Claude Code can use designated models. For developers who sign in directly, enable retention at your organization’s Claude Code workspace. Through Amazon Bedrock or Google Cloud Agent Platform: Claude Code uses your cloud credentials, so it follows your cloud environment's retention setting. Retention must be enabled in your cloud environment, and retained data stays in your provider's environment. The same applies to Cowork accessed through Amazon Bedrock or Google Cloud’s Agent Platform. Through Claude Enterprise with ZDR: We're releasing controls in the admin console so your Primary Owner can change the retention setting directly. If you'd rather not touch your production org yet, we can help you set up a separate sandbox org. If your team uses Claude chat or Cowork through Claude for Enterprise These surfaces already operate with standard retention, so you'll have access to the new models as they become available. Related Articles Business Associate Agreements (BAA) for Commercial Customers Public Sector FAQs Use Claude for Microsoft 365 with third-party platforms Real-time cyber safeguards on Claude Covered Models