AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

Anthropic

Claude 3.7 Sonnet

v3.7 · frontier · Released February 24, 2025

Use with Caution

Updated August 26, 2026

Claude shared chats containing sensitive personal and health data were indexed by Google, creating an unresolved data exposure concern for enterprise deployments. Until Anthropic confirms remediation and revised data handling controls, the model cannot retain a GREEN designation.

Enterprise guidance

Claude 3.7 Sonnet is Anthropic's primary enterprise-ready model and the recommended continuity option for organizations whose workflows depended on Fable 5 or Mythos 5. The API does not use your prompts to train models by default. For regulated industries, use Claude for Enterprise or AWS Bedrock, which include data processing agreements, HIPAA Business Associate Agreements, and zero data retention.

Data handling

Default data retention

Transient for API (no persistent storage of prompts for training); Enterprise: zero by default

Zero-retention available

Yes

Via: Claude for Enterprise; AWS Bedrock; Google Cloud Vertex AI

API data used for training

No

Anthropic does not train on API customer data by default. Claude.ai free tier: Anthropic may use conversations to improve models unless opted out in settings.

GDPR Data Processing Agreement

Available

HIPAA Business Associate Agreement

Available

Claude for Enterprise; AWS Bedrock

Data residency options

US (default); EU available via AWS Bedrock eu-west regions

Vendor compliance certifications

SOC 2 Type IIISO 27001HIPAA (Claude for Enterprise / AWS Bedrock)GDPR compliant

Key use restrictions

  • No CSAM or sexual content involving minors
  • No content facilitating mass casualty weapons (biological, chemical, nuclear, radiological)
  • No tools designed for non-consensual surveillance or stalkerware
  • No content designed to undermine legitimate AI oversight mechanisms
  • No cyberweapons intended to cause significant damage to critical systems

Safety documentation

Model card published
System card published
Red-team report published

Claude Model Specification published and regularly updated. Constitutional AI methodology published in peer-reviewed research. Responsible Scaling Policy (RSP) published with safety commitments. Extensive safety research papers and alignment work publicly available.

Safety documentation →

Related governance resources

Governance controls

Playbook guides

Status history

August 26, 2026· green to yellow

The confirmed indexing of Claude shared chats by Google, including sensitive personal and health data, constitutes an unresolved data residency and exposure concern under the YELLOW criteria. No government action is required for this threshold; the exposure event itself is sufficient to trigger the flag.

← All tracked models