cd /news/ai-policy/which-ai-agent-features-fall-outside… · home topics ai-policy article
[ARTICLE · art-124287] src=digitalapplied.com ↗ pub= topic=ai-policy verified=true sentiment=· neutral

Which AI Agent Features Fall Outside Zero Data Retention

A procurement census of 31 AI agent feature and delivery-surface combinations across Anthropic, OpenAI, Google, and AWS, read on September 9, 2026, finds that zero-data-retention (ZDR) eligibility varies by feature, with Anthropic's Messages feature conditionally eligible for ZDR while Files and Batch are not, and many contract and deletion paths remain unknown. The analysis urges buyers to evaluate retention and eligibility at the feature level rather than relying on broad provider labels.

read14 min views2 publishedSep 8, 2026
Which AI Agent Features Fall Outside Zero Data Retention
Image: Digitalapplied (auto-discovered)

A model can support a zero-data-retention arrangement while the agent feature around it stores sessions, files or memories. The purchase decision therefore belongs at the feature level. Start with the workflow you intend to run, identify every place it creates persistent state, and check each against the applicable provider arrangement.

This census records 31 feature and delivery-surface combinations across Anthropic, OpenAI, Google and AWS. It separates what provider documentation states from what remains unknown. It is a procurement reference, not a legal opinion or a certification that any deployment meets its obligations.

  1. 01A provider label is too broad.Messages, files, hosted sessions and tools can have different eligibility.
  2. 02State and abuse monitoring differ.Disabling response storage does not establish that every copy or log disappears.
  3. 03Deletion may require several operations.Session history, uploaded files and derived memories can have separate lifecycles.
  4. 04Unknown is a useful result.Ask the provider for a feature-specific answer instead of inferring it from a nearby service.

01 — Practical decisionRetention and eligibility by feature #

ZDR means zero data retention under the provider’s defined arrangement. BAA means a HIPAA business associate agreement; DPA means a data processing agreement, with Google’s CDPA label retained where documented. Eligibility does not establish that your organization has executed the required agreement.

Read the contract and deletion fields separately even where they share a column. “Conditional” requires the applicable account, model and feature settings. “Unknown” means the inspected source does not establish the field; it does not mean the provider has no agreement or deletion mechanism. Source letters resolve directly to provider pages.

Provider documentation linked in every cell, read September 9, 2026. This sample is not an exhaustive product inventory or a vendor ranking.
Provider / feature ZDR eligibility Retention window Contract and deletion path
--- --- --- ---
Anthropic / Messages Source · Sep 9, 2026 Conditional A · Sep 9, 2026 No conversation-content storage by default; exceptions below A · Sep 9, 2026 Contract: HIPAA eligible; DPA unknownA · Sep 9, 2026Delete: UnknownA · Sep 9, 2026
Anthropic / Files Source · Sep 9, 2026 No A · Sep 9, 2026 Until deletion or configured expiry A · Sep 9, 2026 Contract: BAA no; DPA unknownA · Sep 9, 2026Delete: Separate file deletionM · Sep 9, 2026
Anthropic / Batch Source · Sep 9, 2026 No A · Sep 9, 2026 29 days A · Sep 9, 2026 Contract: BAA no; DPA unknownA · Sep 9, 2026Delete: Account representativeA · Sep 9, 2026
Anthropic / Web search, no dynamic filtering Source · Sep 9, 2026 Conditional A · Sep 9, 2026 Response handling A · Sep 9, 2026 Contract: HIPAA eligible; DPA unknownA · Sep 9, 2026Delete: UnknownA · Sep 9, 2026
Anthropic / Web fetch, no dynamic filtering Source · Sep 9, 2026 Conditional A · Sep 9, 2026 Response handling; publisher policies separate A · Sep 9, 2026 Contract: BAA no; DPA unknownA · Sep 9, 2026Delete: UnknownA · Sep 9, 2026
Anthropic / MCP connector Source · Sep 9, 2026 No A · Sep 9, 2026 Standard policy A · Sep 9, 2026 Contract: BAA no; DPA unknownA · Sep 9, 2026Delete: Account representativeA · Sep 9, 2026
Anthropic / MCP tunnels Source · Sep 9, 2026 No A · Sep 9, 2026 Unknown T · Sep 9, 2026 Contract: BAA no; DPA unknownA · Sep 9, 2026Delete: Archive tunnel; remove local credentials; data erasure unknownT · Sep 9, 2026
Anthropic / Managed Agents sessions Source · Sep 9, 2026 No M · Sep 9, 2026 Stored session history/state/output M · Sep 9, 2026 Contract: BAA no; DPA unknownM · Sep 9, 2026Delete: Delete session; uploaded files separatelyM · Sep 9, 2026
Anthropic / Scheduled deployments Source · Sep 9, 2026 No: Managed Agents sub-feature A · Sep 9, 2026 Session data persists; run-record TTL unknown A · Sep 9, 2026S · Sep 9, 2026 Contract: BAA no; DPA unknownA · Sep 9, 2026Delete: Archive stops schedule; delete sessions/files separately; record erasure unknownS · Sep 9, 2026M · Sep 9, 2026
OpenAI API / Chat Completions Source · Sep 9, 2026 Conditional O · Sep 9, 2026 No ordinary state; abuse logs up to 30 days by default; exceptions apply O · Sep 9, 2026 Contract: BAA conditional; DPA unknownH · Sep 9, 2026Delete: UnknownO · Sep 9, 2026
OpenAI API / Responses foreground Source · Sep 9, 2026 Conditional; store=false under ZDR O · Sep 9, 2026 Default stored response ≥30 days O · Sep 9, 2026 Contract: BAA conditional; DPA unknownH · Sep 9, 2026Delete: Unknown in inspected pageO · Sep 9, 2026
OpenAI API / Responses background Source · Sep 9, 2026 Permitted from ZDR projects; temporary storage B · Sep 9, 2026 Roughly 10 minutes with store=false B · Sep 9, 2026 Contract: Responses BAA conditional; DPA unknownH · Sep 9, 2026Delete: Automatic after temporary polling periodB · Sep 9, 2026
OpenAI API / Conversations Source · Sep 9, 2026 No O · Sep 9, 2026 Until deletion O · Sep 9, 2026 Contract: UnknownH · Sep 9, 2026Delete: Deletion required; exact operation not checkedO · Sep 9, 2026
OpenAI API / Files Source · Sep 9, 2026 No O · Sep 9, 2026 Until deletion/expiry O · Sep 9, 2026 Contract: BAA conditional; DPA unknownH · Sep 9, 2026Delete: API/dashboard; expires_afterO · Sep 9, 2026
OpenAI API / Batch Source · Sep 9, 2026 No O · Sep 9, 2026 Until deletion O · Sep 9, 2026 Contract: BAA conditional; DPA unknownH · Sep 9, 2026Delete: Unknown in inspected pageO · Sep 9, 2026
OpenAI API / Live web search Source · Sep 9, 2026 Tool-specific classification unknown O · Sep 9, 2026 Tool-specific window unknown O · Sep 9, 2026 Contract: BAA no; DPA unknownO · Sep 9, 2026Delete: UnknownO · Sep 9, 2026
OpenAI API / Cache-only web search Source · Sep 9, 2026 ZDR setup required for BAA path O · Sep 9, 2026 Tool-specific window unknown O · Sep 9, 2026 Contract: BAA conditional; DPA unknownO · Sep 9, 2026Delete: UnknownO · Sep 9, 2026
OpenAI API / Remote MCP Source · Sep 9, 2026 Third-party boundary O · Sep 9, 2026 MCP operator policy O · Sep 9, 2026 Contract: Third-party agreement unknownO · Sep 9, 2026Delete: MCP operator; exact path unknownO · Sep 9, 2026
OpenAI / Codex cloud Source · Sep 9, 2026 Unknown C · Sep 9, 2026 Unknown numeric window C · Sep 9, 2026 Contract: BAA no; DPA unknownH · Sep 9, 2026Delete: UnknownC · Sep 9, 2026
Google Cloud / Plain model inference Source · Sep 9, 2026 Conditional configuration and model G · Sep 9, 2026 Abuse/Advanced AI exceptions; inspect contract G · Sep 9, 2026 Contract: CDPA referenced; BAA unknownG · Sep 9, 2026Delete: UnknownG · Sep 9, 2026
Google Cloud / Search grounding Source · Sep 9, 2026 No for this feature G · Sep 9, 2026 Derived query/context logs ≤3 days G · Sep 9, 2026 Contract: CDPA referenced; BAA unknownG · Sep 9, 2026Delete: Logging cannot be disabledG · Sep 9, 2026
Google Cloud / Maps grounding Source · Sep 9, 2026 No for this feature G · Sep 9, 2026 Prompts/context/output 30 days G · Sep 9, 2026 Contract: CDPA referenced; BAA unknownG · Sep 9, 2026Delete: Logging cannot be disabledG · Sep 9, 2026
Google Cloud / Live session resumption Source · Sep 9, 2026 Disable resumption for ZDR G · Sep 9, 2026 Cached inputs/outputs ≤24 hours G · Sep 9, 2026 Contract: CDPA referenced; BAA unknownG · Sep 9, 2026Delete: Exact deletion operation unknownG · Sep 9, 2026
Google Cloud / Managed Agents preview Source · Sep 9, 2026 Unknown; confidential-data use prohibited V · Sep 9, 2026 Unknown numeric window V · Sep 9, 2026 Contract: Pre-GA restrictions; BAA/DPA unknownV · Sep 9, 2026Delete: Project deletion documented; individual record erasure unknownV · Sep 9, 2026
Gemini Developer API / Stored interactions (paid) Source · Sep 9, 2026 Unknown program eligibility; stored state I · Sep 9, 2026 55 days; configurable 7/14/28/55 I · Sep 9, 2026 Contract: BAA/DPA unknownI · Sep 9, 2026Delete: interactions.delete or AI Studio; expiryI · Sep 9, 2026
Gemini Developer API / Stateless interactions Source · Sep 9, 2026 Unknown program eligibility; store=false supported I · Sep 9, 2026 Interaction storage disabled; other retention unknown I · Sep 9, 2026 Contract: BAA/DPA unknownI · Sep 9, 2026Delete: No stored interaction; other deletion unknownI · Sep 9, 2026
Gemini Developer API / Background interactions Source · Sep 9, 2026 store=false incompatible I · Sep 9, 2026 Stored interactions follow tier policy I · Sep 9, 2026 Contract: BAA/DPA unknownI · Sep 9, 2026Delete: interactions.delete or AI Studio; expiryI · Sep 9, 2026
Gemini Developer API / Files Source · Sep 9, 2026 Unknown program eligibility; file storage required F · Sep 9, 2026 48 hours F · Sep 9, 2026 Contract: BAA/DPA unknownF · Sep 9, 2026Delete: files.delete or automatic expiryF · Sep 9, 2026
AWS AgentCore / Runtime sessions Source · Sep 9, 2026 Unknown D · Sep 9, 2026 Data window unknown; microVM lifetime is separate R · Sep 9, 2026 Contract: Service HIPAA eligible; BAA/DPA terms unknownK · Sep 9, 2026Delete: Timeout terminates instance; session can resumeR · Sep 9, 2026
AWS AgentCore / Short-term memory Source · Sep 9, 2026 Unknown program eligibility; persistent events W · Sep 9, 2026 Configured event retention ≤365 days W · Sep 9, 2026 Contract: Service HIPAA eligible; BAA/DPA terms unknownK · Sep 9, 2026Delete: DeleteEvent; derived long-term memory survivesE · Sep 9, 2026
AWS AgentCore / Long-term memory Source · Sep 9, 2026 Unknown D · Sep 9, 2026 Unknown numeric window W · Sep 9, 2026 Contract: Service HIPAA eligible; BAA/DPA terms unknownK · Sep 9, 2026Delete: DeleteMemoryRecord separatelyL · Sep 9, 2026

02 — Practical decisionRead the conditions before using an eligible feature #

Anthropic’s eligibility documentation adds model-specific exceptions: Fable 5/5.1 and Mythos 5/5.1 require 30-day retention without express authorization. Search/fetch dynamic filtering is excluded from the eligible path. Flagged content may be retained up to two years, with legal exceptions. A feature-level yes cannot override those conditions.

OpenAI’s HIPAA guidance requires an executed BAA and Modified Retention for covered API use unless specified otherwise. Codex cloud is excluded. The API data-controls page separately conditions the cache-only web-search BAA path on supported non-preview tooling, disabled external web access and ZDR at organization and project level.

These details change how a procurement question should be phrased. Ask whether the exact model, endpoint, tools and settings are covered by the proposed agreement. A response about the general API may be accurate while leaving the intended hosted feature unanswered.

Our Astra–Fable comparison covers model selection. Use this feature census as a separate filter before running an evaluation with confidential material.

03 — Practical decisionWhat stateful agents cost the reviewer #

Persistent state can be useful: it lets work resume, keeps files available and avoids asking the user to repeat context. The review cost is identifying which resources exist, who can access them, how long they remain and which operation removes them. That work is part of choosing the runtime.

Claude Managed Agents documentation says the stateful service is outside current ZDR and HIPAA BAA eligibility. Session deletion and uploaded-file deletion are separate. The question for a buyer is whether that persistence fits an acceptable arrangement, not whether persistence is automatically disqualifying.

The current OpenAI background-mode guide permits requests from ZDR projects with store=false while retaining temporary polling data for roughly ten minutes. That is a specific documented exception to a literal expectation of no storage. Quote the behavior when assessing it rather than relying on an older blanket description of background mode.

Google’s managed-agent preview guide restricts confidential input and commercial/production use. General cloud data-governance statements do not remove those preview restrictions. Our Google managed-agent analysis provides product context; the current feature terms decide the allowed use.

04 — Practical decisionFollow deletion through the derived data #

Draw a simple resource list for a representative task: input request, session, uploaded file, tool result, memory, trace and export. Identify the owner and deletion operation for each. A request to delete the session should not be treated as proof that the other resources were removed.

AWS short-term event deletion documentation says deleting an event does not remove derived long-term memory. The latter has a separate DeleteMemoryRecord operation. Similarly, runtime lifecycle limits describe instance lifetime, not a universal data-retention promise. A stopped process and erased data are different outcomes.

Include destinations outside the runtime. A remote tool may receive information under its own policy, and an exported trace may remain in your observability system. The provider’s deletion operation cannot establish what your own retained export contains. Keep the data-flow map narrow enough that an engineer can verify it.

Our agent runtime and sandbox matrix helps identify execution boundaries. Add storage and deletion ownership to that runtime decision before calling the workflow ready for sensitive work.

05 — Practical decisionTurn unknown cells into precise provider questions #

An unknown cell should produce a question with a subject and a requested answer. For example: does this feature retain session content after an explicit delete request, and what documented window applies to primary copies and backups? Avoid asking whether the whole platform is compliant; that invites an answer too broad to settle the deployment.

Attach the model ID, region, feature name and enabled tools to the question. Ask which contract covers the service and whether an eligibility exception requires approval. Request a source or written commitment that can be retained with the deployment record.

For implementation, test the operations available to you using non-sensitive sample data: create the resource, find it, delete it and confirm the visible result. Such a test can establish that the control works in your application. It cannot independently establish deletion of provider backups or other internal copies; those require the provider’s documented commitment. Keep the census at the same URL and re-check it when the provider changes a feature or your workflow adds a new destination. A table read today is evidence for today’s decision, not a permanent certification. Our Claude Managed Agents update guide illustrates how runtime features can change the scope of an earlier review.

This is a documentation comparison, not a hands-on performance test.

  • As-of date
  • September 9, 2026. Published September 8 as an editorial backfill; collection happened the following day.
  • Scope
  • Purposive census of 31 feature/surface rows across four providers, researched from 18 provider documentation pages. Each cell includes its source and read date. Conditional is not default eligibility; unknown is not a negative finding. Contract columns record documentation statements, not a signed agreement or legal assessment.
  • Refresh
  • Review after provider policy or model changes. Unknown marks information the cited documentation does not state.

06 — Next stepWhat to do next #

Choose the complete data path, not the model label.

Filter the intended workflow by feature eligibility, retention behavior, contract and deletion path. Resolve consequential unknowns with the provider and preserve the answer with the deployment configuration. Stateful features can be a deliberate choice when their handling fits the requirement; a broad privacy label alone cannot establish that fit.

Our AI transformation services help teams define a useful pilot, evaluate its results and turn the findings into an implementation decision.

── more in #ai-policy 4 stories · sorted by recency
── more on @anthropic 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/which-ai-agent-featu…] indexed:0 read:14min 2026-09-08 ·