TheoryPractitioner20 min

Training Data Opt-Out

What model training means

AI models like Claude improve over time through a process that includes training on data. At Anthropic, this process involves human review of conversations to assess quality and helpfulness, reinforcement learning from human feedback (RLHF), and fine-tuning cycles that update the model's weights.

For individual users on the Free tier, conversations may be used in this process unless they have opted out. This is disclosed in Anthropic's Terms of Service and privacy policy.

For organisations on Enterprise contracts, this opt-out is on by default. Conversations within your Enterprise organisation are not used to train Anthropic's models. This is a foundational commitment of the Enterprise product tier.

Why this matters

The business reason for opting out is straightforward: your organisation's conversations may contain commercially sensitive, legally privileged or personally identifiable information. If that data were used in model training, there is a (small but non-zero) theoretical risk that information could surface in responses to other users in ways that are not immediately traceable but still constitute a data leak.

More practically, most enterprise legal and compliance teams consider any use of company data for external model training to be a breach of internal data governance policies, regardless of the actual risk level. The opt-out eliminates the question.

How to verify the opt-out

Do not assume the opt-out is active because you are on an Enterprise plan. Verify it explicitly:

  1. Log in to the Admin Console.
  2. Navigate to Privacy & Data.
  3. Look for the Model Training or Training Data Usage section.
  4. Confirm the status shows "Off" or "Not used for training" for your organisation.

Screenshot this screen and save it to your compliance documentation folder. When your DPO or an auditor asks "can you confirm that Anthropic does not use our data for training?", this screenshot plus your contract's DPA is your evidence.

What the opt-out covers

The opt-out applies to:

  • All conversations sent by any member of your organisation on claude.ai
  • Conversations in any Project in your organisation
  • File uploads and attachments

The opt-out does not cover:

  • Public internet data — Anthropic trains on publicly available text; if your employees post public content, that is not affected by your enterprise opt-out
  • Aggregate usage statistics — Anthropic may use aggregate, anonymised statistics (e.g., total message volume, error rates) for service improvement. These do not contain conversation content.
  • Feedback submitted via the thumbs-up/thumbs-down buttons — explicit feedback submissions may be reviewed separately. Consider advising employees not to use these feedback buttons for conversations that contain sensitive information.

Employee awareness

Employees who are used to the consumer version of Claude (or other consumer AI tools) may assume their conversations are being used for training. This assumption can cause one of two problems:

  1. Over-sharing — "if it's going to train on this anyway, I might as well paste in everything"
  2. Under-sharing — "I won't use Claude for anything sensitive because I don't trust what happens to the data"

Both are correctable with clear communication. In your onboarding materials, include a sentence like: "Your conversations in Claude Enterprise are not used by Anthropic to train their AI models. Your data stays private to our organisation."

The opt-out and GDPR

Under GDPR, using personal data (including employee data that appears in conversations) for model training would require a lawful basis, typically consent or legitimate interest. The enterprise opt-out means this question does not arise — the data is not used for training and there is no processing activity to justify.

If your DPA with Anthropic specifies the lawful basis for processing conversation data (typically performance of contract and legitimate interest for service delivery), ensure the DPA explicitly excludes model training as a processing purpose.

Scenario: a compliance audit

A UK insurance company undergoes an ICO compliance audit following a subject access request from a former employee. The auditor asks the DPO to provide evidence of all AI systems that processed the former employee's personal data and the purpose for which that data was processed.

The DPO checks the Claude Enterprise Admin Console: the training opt-out is confirmed active. The DPA with Anthropic lists the processing purposes as "provision of the claude.ai service" with no mention of model training. The DPO provides the screenshot, the DPA extract and the retention policy (30 days, so the former employee's data was deleted per schedule). The auditor is satisfied.

Without the training opt-out verification and the documented DPA, the DPO would have struggled to answer the auditor's question definitively.

Key takeaway

The training opt-out is on by default for Enterprise — but verify it, document it, and communicate it to your employees. It is a simple confirmation that carries significant compliance value.


📖 Official Documentation See this in practice in Anthropic’s live support docs: