
Field note · AI Engineering · · 2 min read
Your fallback model needs the same data rules
Picture an employee sending a sensitive document to an AI feature. The approved model is down, so the app tries a backup. An answer comes back and everything looks fine. The backup, though, may keep a copy of a document the approved route had to discard.
The router, the part of the app that picks a model, needs the data rules before it tries a fallback. A successful answer cannot tell you whether the route was allowed.
Check each route, including its exceptions
A provider's name is not enough to decide. Retention depends on your account and the agreement behind it. As of September 24, 2026, two providers described it this way.
- OpenAI (opens in a new tab) describes zero data retention for eligible API customers. Images flagged for potential child sexual abuse material are still kept for review and reporting. Its Private Safety Processing, previewed in August, began rolling out to API customers in phases on September 22.
- Anthropic (opens in a new tab) describes 30-day retention for covered models under its standard arrangement. Its covered-model guidance (opens in a new tab) also describes a temporary zero-retention option for eligible customers using Fable for internal business applications.
Keep a dated record for each route the app can choose. Note what data it may receive and how long and where it is kept, including any exceptions. Tie that record to the exact account and model version you use. Your data-policy owner approves the rules, and the router enforces them.
Test the route that usually sits idle
In a test environment, make the primary route unavailable. Check where the request goes, which rule allowed it, and whether any disallowed service saw the content before the decision. Test the case where no route is acceptable too, and rerun these checks after any routing change.
What happens when the approved route is down?
Primary unavailable
Route A meets the request's data policy but cannot serve it right now.
Check the fallback
Route B keeps content for 30 days, so the app excludes it before sending anything.
Return an unavailable result
If no allowed route is left, say the request cannot be completed. Any exception needs approval before data is sent.
Your own software can keep copies as well, in conversation history or diagnostic logs, so check those separately. A provider's zero-retention setting covers only its side of the arrangement.
Count the test as passed only if disallowed routes never receive the data and the user sees a plain message that the request is unavailable. Keep the rule beside the routing configuration, and recheck the routes when a provider changes its terms.
Written by the Moga principals.
More from AI Engineering
- 2 min read
Review an agent skill like a software dependency
Trace what a shared agent skill can run and access before your team installs it.
- 2 min read
Treat a model upgrade like a permission change
Before switching models, give both the same task on a safe copy and compare what each tries to change.