Nvidia, Palantir, Booz Allen Restrict Claude Use Over IP Fears
Nvidia, Palantir, and Booz Allen Hamilton have restricted internal use of Anthropic's Claude, citing concerns over sensitive code and IP entering external AI models.

Nvidia, Palantir, and Booz Allen Hamilton have placed restrictions on internal use of Anthropic's Claude AI model, according to reporting by The Information. The companies' concern is that employees working with Claude on coding or office tasks could inadvertently expose proprietary source code, trade secrets, or other sensitive data to an external provider that might store or learn from it. The restrictions highlight a growing tension between the productivity gains of AI coding tools and the data-governance risks they introduce at large enterprises.
What happened
| Detail | Fact |
|---|---|
| Source | The Information |
| Companies restricting Claude | Nvidia, Palantir, Booz Allen Hamilton |
| Nvidia low-sensitivity model | Anthropic’s Fable (open-source tasks only) |
| Nvidia sensitive-project model | Nvidia’s own Nemotron |
| Company allowing Claude freely | Google (all engineers) |
| Report date | 15 September 2026 |
Three major firms have moved to limit or segment their staff’s access to Claude, Anthropic’s flagship AI assistant, over fears about where sensitive internal data ends up. The concern is not theoretical: as AI coding assistants become standard tools, employees routinely paste internal code, architecture diagrams, and business logic into chat interfaces without thinking twice about where that data goes.
Nvidia’s approach is the most detailed on record. The chipmaker allows Claude (specifically Anthropic’s Fable variant) only for tasks involving open-source software, where the code is already public and exposure risk is minimal. For higher-stakes internal work such as supply-chain monitoring, Nvidia routes queries to its own Nemotron model, keeping sensitive data entirely in-house.
Why it matters
These restrictions reflect a broader shift in how enterprises think about third-party AI tools. Early adoption of tools like Claude or GitHub Copilot often happened at the team level, without formal data-handling policies. Now that usage is scaling to thousands of employees, legal and security teams are catching up and drawing lines.
The specific risk is data residency and model training. Companies worry that prompts containing proprietary code or IP could be stored by the provider, reviewed by its staff, or used to fine-tune future model versions. Even if a provider’s terms of service forbid training on customer data, proving it is difficult.
The contrast with Google is worth noting. Google allows all its engineers to use Claude without restriction. That may reflect Google’s ability to negotiate enterprise data-protection agreements at scale, its deeper familiarity with AI vendor contracts, or simply a different internal risk tolerance. It also means Anthropic’s commercial relationship with Google remains intact at a meaningful level.
For businesses evaluating AI integration across their teams, this story is a signal to get ahead of the governance question before usage grows organically and policies become harder to enforce.
How does this compare across companies?
| Company | Claude policy | Alternative for sensitive work |
|---|---|---|
| Nvidia | Allowed for open-source tasks only | Nemotron (own model) |
| Palantir | Restricted internally | Not specified |
| Booz Allen Hamilton | Restricted internally | Not specified |
| Allowed for all engineers | N/A |
Our take
This is a predictable inflection point. AI tools spread fast inside companies because individual developers and analysts find them genuinely useful. Then someone in legal or security asks a simple question: “Where does that data go?” and nobody has a clean answer.
Nvidia’s tiered model is the most practical response we’ve seen: keep the tool for low-risk tasks, build or license a self-hosted alternative for everything sensitive. That strategy only works if you have Nvidia’s resources to develop Nemotron. Most businesses don’t.
For smaller organisations, the realistic options are: negotiating a proper enterprise data agreement with the AI vendor, using a self-hosted open-source model for anything confidential, or simply training staff on what not to paste. None of those is perfect, but all three are better than ignoring the problem until a breach forces the conversation.
We have written before about the less visible costs of running AI at scale. Data governance is another one that rarely shows up in the productivity dashboards but matters enormously once something goes wrong.
What to do about it
- Audit which AI tools your team currently uses and whether any enterprise data-protection agreements are in place with those vendors.
- Classify your data by sensitivity before writing a policy: not all AI use is equal, and a blanket ban is harder to enforce than a tiered approach.
- Evaluate self-hosted or on-premises model options for workflows that involve source code, client data, or regulated information.
- Train staff on what constitutes sensitive data in the context of AI prompts, not just in file storage or email.
- Review the situation again in six months. Vendor data policies and enterprise agreements are changing quickly right now.
The practical takeaway: treat your AI vendor like any other third-party processor of business data, and audit the relationship before usage scales past the point where policy changes become disruptive.
Frequently asked questions
Why are companies banning or restricting Claude?
The main concern is that employees might enter proprietary source code, trade secrets, or other sensitive internal data into Claude, where the provider could potentially access or train on it. Companies like Nvidia, Palantir, and Booz Allen Hamilton have restricted use for this reason.
What model does Nvidia use instead of Claude for sensitive tasks?
Nvidia uses its own Nemotron model for sensitive internal projects such as supply-chain monitoring. It limits Anthropic's Fable variant of Claude to lower-risk work involving open-source software.
Does Google allow employees to use Claude?
Yes. According to The Information's reporting, Google allows all of its engineers to use Anthropic's Claude without restriction.
How can businesses protect sensitive data when using AI coding tools?
Options include negotiating enterprise data agreements with the AI vendor, using self-hosted or on-premises models for confidential work, and training staff on what types of data should not be entered into external AI tools.


