How to keep your data safe with Claude Cowork
…and the one risk your license won’t fix.

1.Introduction
Claude Cowork is quickly becoming one of the fastest-growing AI tools for enterprise work. Companies are using it to help individual employees become more efficient and to automate increasingly complex workflows across entire teams. But getting work done means sharing data with the AI, and for many organizations, the compliance and privacy implications of doing so remain unclear.
Some companies accept the risks and move ahead with organization-wide adoption, unaware of the legal liability they may be creating. Others take the opposite approach, limiting adoption as much as possible while competitors capture the productivity gains that come with broader AI use. Regardless of where your organization falls, one thing is clear: understanding what is actually safe, and what isn’t, can mean the difference between avoiding a costly legal mistake and falling behind the competition.
This article separates perception from reality by mapping the risks to your data. We’ll cover what looks dangerous but isn’t, what is genuinely risky but often overlooked, how different Anthropic licensing tiers do (and don’t) protect you, and how to mitigate these risks through infrastructure, governance, and employee training. Finally, we’ll examine a risk many organizations overlook: cross-contamination, where one client’s data unintentionally makes its way into work for another client through connected tools such as Google Drive. Unlike the risks that can be addressed by purchasing the right license, this one requires operational discipline, clear processes, and ongoing oversight.
2.Claude Cowork in practice
Claude Cowork is Anthropic’s collaborative AI workspace for getting real work done. While a traditional AI chat interface can answer questions, summarize documents, and generate content, Cowork is designed to execute multi-step tasks that span documents, tools, and business workflows. It allows individuals and teams to automate meaningful work with little or no engineering support.
Cowork provides several capabilities that make it a powerful enterprise tool:
- Skills: Reusable instructions that teach Claude how to perform recurring tasks.
- Artifacts: Interactive documents, applications, dashboards, and other outputs that Claude creates and updates.
- Integrations: Connections to systems such as Google Drive, Slack, email, calendars, and the web that allow Claude to retrieve information and take actions on your behalf.
- Projects: Dedicated workspaces that organize conversations, files, instructions, and context around a specific initiative.
- Scheduled Tasks: Workflows that run automatically on a schedule.
At its simplest, Cowork makes one person faster, but its real value emerges when tasks connect into workflows that span a whole team. Imagine a marketing agency onboarding a new client. Cowork reads the creative brief, creates the project workspace, retrieves historical performance data, drafts the client presentation, and notifies the account manager when everything is ready for review. A process that once took several people over multiple days becomes a largely automated workflow with a human serving as the final approver.
Anthropic is not alone. OpenAI and Google offer similar enterprise workflow capabilities through ChatGPT and Gemini. While the platforms differ in implementation, they are converging on the same model: AI systems that reach into your data to automate tasks. And that same reach is exactly what puts your data at risk.
3.Know the risks
Data doesn’t become a liability all at once. With Cowork, it follows a predictable path: it starts with the data you share, moves through the way it enters the system, and ends with the ways it can expose your organization. Understanding that path, and where you still have control over it, is the key to using Cowork safely.
The infographic below traces that path.
The last stage covers the mechanism by which data becomes a liability, and model training is by far the one that gets the most attention. It is often the main reason teams fear sharing data with AI, but it’s also the one that tends to be overstated.
Here’s how training actually works. A language model learns statistical patterns by predicting the data it is trained on. It doesn’t store information like a database does. However, because modern Large Language Models (LLMs) contain billions of parameters, they have enough capacity to memorize some of the data they see during training. While it’s unlikely that a model will faithfully reproduce your conversations or documents, there is no way to rule that possibility out completely.
As we’ll see, commercial licenses don’t train on your data by default. That means organizations on a commercial plan are already protected, with one important exception we’ll cover shortly.
In practice, retention and access are the bigger risks, and the ones most often overlooked. Retention is how long your data remains with the provider. Because retention varies by license, it matters most when a contract or regulation requires data to be deleted: you can remove it from your own systems, but not always from the provider’s, or on your own schedule. Access is who can reach your data once it’s in, both within your organization and, when tools are connected to shared drives, across different clients. Retention is largely addressed by choosing the right license. Access isn’t.
4.How licenses protect your data
Protecting your data starts with choosing the right AI license, but it doesn’t end there. Each Anthropic plan offers different protections, controls, and limitations. Understanding those differences helps you see which risks your license already covers, and which ones you’ll still have to address yourself.
The biggest distinction is between consumer and commercial licenses.
Consumer plans (Free / Pro / Max)
Consumer plans offer the least protection: by default, conversations may be used to train Anthropic’s models and retained for up to five years. Both can be switched off in the privacy settings, which stops future training and cuts retention to 30 days. For personal use that’s usually enough. For company data, consumer plans are the wrong choice.
Claude Team
Claude Team is the entry point for commercial use, and a significant step up from consumer plans. It provides:
- Model training off by default
- 30-day data retention
- Shared workspace and central admin
- Google and Microsoft SSO
- Basic admin and audit controls
For many small companies, Team covers everyday business use.
Claude Enterprise
Enterprise builds on Team with the controls larger organizations expect:
- SSO with any identity provider
- SCIM provisioning, so access is granted and revoked automatically as people join and leave
- Role-based permissions for admin, sharing, and connections
- Full audit logs
- Compliance API for company-wide audit and usage data
- Custom data retention policies
These controls make it practical to deploy securely across thousands of employees.
HIPAA-ready Enterprise
Organizations handling Protected Health Information (PHI) need a HIPAA-ready Enterprise configuration. It isn’t a separate plan; it’s Enterprise with a Business Associate Agreement (BAA) and additional safeguards needed to support HIPAA compliance. It’s arranged through Anthropic’s sales team rather than self-serve, and an administrator activates it.
Claude API
The API is a separate product with its own terms: not an app your team logs into, but a developer interface your own software builds on. Like the commercial plans, it doesn’t train on your data by default, and because you control the architecture, it offers the tightest grip on security, retention, and governance. It’s the usual choice for customer-facing applications.
Two important exceptions
While this covers most of it, there are a couple of really important exceptions you should be aware of:
- Claude Cowork is not covered under Anthropic’s BAA in any configuration. If your organization handles PHI, that work has to happen in HIPAA-ready Chat or the API, never in Cowork, regardless of plan.
- Feedback button: When a user clicks the thumbs up or thumbs down button to submit feedback, Anthropic may retain the associated conversation and use it to improve future models. This creates a narrow exception to the normal commercial data-handling policies. Organizations that prohibit this behavior can disable feedback collection.
The take-home lesson: know your plan and its protections and limitations, and be aware of the exceptions, because the system wasn’t built with simplicity as a goal.
5.Cross-contamination
There is one additional risk that isn’t covered by any Anthropic license. It has nothing to do with model training, retention policies, or enterprise security features. Instead, it comes down to how AI is deployed inside your organization: cross-contamination.
Cross-contamination occurs when data from one customer unintentionally makes its way into work being performed for another customer. Unlike model training or retention, this is not a provider problem. It is an access and governance problem.
The risk becomes most apparent when Claude is connected to shared data sources such as Google Drive, SharePoint, Slack, or other enterprise systems. Smaller companies often lack the infrastructure to properly isolate customer data, while larger organizations face the complexity of managing access across thousands of files, folders, and integrations.
To make this concrete, imagine a consulting company that connects Claude to Google Drive, where multiple client folders are stored. An employee creates a Claude Project for Client A and asks Claude to prepare a quarterly business review. The catch is that the connector inherits the permissions of the account it’s connected to, and nothing inside Claude limits it to Client A’s folder. If that account can see Clients B and C, so can Claude, and it may fold their information into Client A’s report without anyone noticing.
Nothing was hacked. Nothing was leaked through model training. The AI simply had access to more information than it should have.
This type of mistake can create serious legal and reputational consequences, especially when client confidentiality agreements are involved.
Mitigating cross-contamination requires both technical controls and organizational discipline. Some companies avoid broad integrations with shared storage altogether. Others invest in finer-grained access controls or train employees on how to structure projects and permissions safely. The principle is the same: AI should only access the information it actually needs.
Cross-contamination is one of the least discussed risks in enterprise AI, which makes it particularly dangerous. Organizations cannot protect themselves from a problem they do not know exists.
6.AI risk matrix: what your license covers
To summarize everything we’ve covered, the matrix below maps the major risks against Anthropic’s license tiers.
Risk × license tier
| Risk | Free / Pro / Max | Team | Enterprise | Enterprise (HIPAA-ready) |
|---|---|---|---|---|
| Model training | Trains by default | No training* | No training* | No training |
| Retention control | Up to 5 years | Fixed (30 days) | Custom | Custom |
| Access & governance | None | Basic | Full | Full |
| Regulated data (PHI) | No | No | Not until activated | PHI under BAA** |
| Cross-contamination | Your setup | Your setup | Your setup | Your setup |
* Unless a user submits feedback. Workspace owners can disable this behavior.
** HIPAA-ready coverage excludes Claude Cowork.
The colors show the relative level of risk for each category. Most risks change as you move between license tiers, but cross-contamination does not. It remains your responsibility at every level because it is not a licensing problem. It is a problem of access, process, and infrastructure.
Once you understand where the risks remain, there are three primary ways to mitigate them.
1. Discipline
The first lever is people. Employee training, documented policies, and periodic audits help make safe AI usage part of normal operations. It is the fastest and least expensive control to implement, but also the weakest. People make mistakes, training fades, and manual processes do not scale.
Discipline is essential, but it should not be your only defense.
2. Configuration
The second lever is using the controls your platform already provides. Disabling model training, managing feedback settings, setting retention policies, limiting integrations, and configuring permissions correctly eliminate many common risks.
If your current license lacks the controls you need, upgrading may be less expensive than relying on training alone.
3. Infrastructure
The strongest control is designing systems that enforce the desired behavior automatically. For example, an MCP server could expose only customer-specific data to an AI agent, preventing cross-contamination regardless of the prompt. A well-designed data architecture can isolate customer information before it reaches Claude.
Infrastructure requires more investment upfront, but it provides the most reliable and scalable protection.
Effective AI governance uses all three levers. Smaller organizations may rely more on discipline and configuration, while larger or regulated organizations often invest in infrastructure to automate enforcement. The right balance depends on your size, resources, and the sensitivity of your data.
The goal isn’t to use every lever. It’s to match the lever to the risk, and the risk to what your data is worth.
7.Conclusion
Tools like Claude Cowork can bring tremendous value to organizations of every size, but that value comes with risk. When companies don’t understand those risks or how to mitigate them, they typically fall into one of two traps: they move too slowly and miss the benefits of AI, or they move too quickly and create unnecessary exposure.
Those are not the only options. Once you understand what data you are sharing, how it enters the system, and what protections apply, you no longer have to choose between moving fast and staying safe. You can do both.
As these tools evolve and become embedded in more business processes, the governance challenges will only become more complex. The specific licenses, settings, and exceptions will change over time. The principles will not.
Know what data you are sharing. Understand the obligations it carries. Then apply the right combination of discipline, configuration, and infrastructure to manage the risks. That is what keeps your data safe today, and what will keep it safe as AI continues to evolve.