OpenAI is preparing a new round of customer privacy protections that — According to TechCrunch — are explicitly built to close the trust gap that Anthropic has spent roughly two years widening with enterprise buyers. It's unusual for a lab to frame a policy update as catching up to a named rival rather than simply "strengthening security" — and that framing alone signals where the competitive pressure in enterprise AI sales now sits.
For most of the last three years, OpenAI and Anthropic competed primarily on model capability: benchmark scores, context windows, coding performance. That race hasn't stopped, but a second, quieter one has been running alongside it inside procurement departments, where security and legal teams decide whether an AI vendor even makes it onto a shortlist. Anthropic has leaned hard into that second race, building its enterprise pitch around data-handling guarantees rather than raw model scores. OpenAI's move suggests it no longer wants to concede that ground by default.
The timing matters too. OpenAI's flagship consumer product has spent much of the past year entangled in litigation over how long it retains user data — including a widely reported court order compelling it to preserve chat logs that users had explicitly deleted, over its own objections. Whatever the new protections specifically cover, they arrive against that backdrop, which makes privacy a live commercial liability for OpenAI in a way it simply isn't for a smaller, enterprise-first competitor like Anthropic.
Why privacy became a deciding factor, not a footnote
Two years ago, most companies adopting large language models were running pilots: small teams, small budgets, low-stakes use cases. That's no longer true. As AI spend has shifted from experimentation to production — powering customer support, internal tooling, and increasingly regulated workflows in finance and healthcare — the buyers signing the contracts have changed too. Security reviewers, compliance officers, and legal counsel are now standard participants in AI vendor selection, and their questions are consistent: Is our data used to train your models? How long is it retained? Who are your subprocessors? Can we get a signed data processing agreement?
Anthropic built its enterprise offering to answer those questions cleanly from the start — no training on API or business-tier data by default, configurable retention windows, and compliance certifications aimed at regulated industries. That consistency became a sales argument in its own right, independent of which model scored higher on any given benchmark.
What "one-upping" Anthropic actually requires
The categories that matter in this contest aren't secret — they're the same handful of clauses every enterprise security questionnaire asks about:
- Whether customer inputs and outputs are used for model training, and whether that's opt-out or opt-off by default
- How long data is retained, and whether customers can shorten or zero out that window
- Audit logging and visibility into who accessed what data, and when
- Formal compliance certifications (SOC 2, ISO 27001, HIPAA support) that procurement teams can check off without a custom legal review
- Contractual guarantees — a signed DPA, not just a blog post — that survive a change in company policy
Matching Anthropic on paper is one thing; matching it in a signed contract that a Fortune 500 legal team will actually accept is another. That's the harder bar OpenAI has to clear, and it's the one that will determine whether this move changes actual deal outcomes rather than just the marketing copy.
What this means for teams choosing a vendor
For engineering and procurement teams currently picking between OpenAI and Anthropic — or re-evaluating an existing contract — the practical move is to stop treating privacy terms as boilerplate and start treating them as a comparison table:
- Ask both vendors for their current default training-data policy in writing, not just what's on the marketing page
- Compare retention windows for both API logs and any fine-tuning or evaluation data
- Check whether zero-data-retention agreements are available for regulated use cases, and at what tier
- Confirm compliance certifications are current, not aspirational — "in progress" is not the same as "certified"
None of this requires waiting for either company's next announcement — most of it can be requested from a sales engineer this week.
AiiN's takeaway
The more interesting story here isn't the specific protections OpenAI is adding — it's that data privacy has become a feature lab-to-lab, marketed and iterated on the same way context-window size or tool-calling was a year ago. That's a healthy shift for buyers: it means vendors are competing to give up leverage over customer data, rather than treating privacy as a compliance checkbox handled once and forgotten.
In our estimation, this pressure is likely to spread beyond the OpenAI–Anthropic rivalry — expect Google, Microsoft, and other frontier vendors to publish comparable commitments within the next few quarters, turning data-handling guarantees into a standard line on every AI procurement scorecard rather than a differentiator any single lab can hold for long.