Safety

AI-generated text

Anthropic launches Enterprise Frontier Safeguards to let customers keep logs on their cloud infrastructure

Anthropic announced Enterprise Frontier Safeguards (EFS) on September 1, 2026: a system that combines zero data retention privacy with time‑windowed automated misuse detection while keeping activity logs on customer‑controlled cloud infrastructure.

Anthropic launches Enterprise Frontier Safeguards to let customers keep logs on their cloud infrastructure

On September 1, 2026, Anthropic unveiled Enterprise Frontier Safeguards (EFS), a new architecture that combines the privacy promise of zero data retention (ZDR) with automated, pattern‑based misuse detection that operates over time windows. EFS keeps activity logs and monitoring data in cloud infrastructure controlled by the customer rather than in Anthropic’s systems. The product will roll out to customers in phases starting later this fall; eligible customers will continue to receive ZDR on Claude Fable 5 and Claude Fable 5.1 until EFS is available.

Why EFS was created

Anthropic says Mythos‑class models such as Claude Fable 5.1 deliver substantially greater intelligence and agentic capability, which increases both the potential for misuse and the risk of autonomous harmful behavior. Over recent months Anthropic has observed attempted abuses ranging from fraud to sophisticated cyberattacks, including cases that involve theft or misuse of enterprise credentials. Many of the most sophisticated abuse patterns unfold across multiple sessions and accounts and therefore require correlating activity over time to detect.

Because of that, Anthropic introduced a 30‑day data retention policy starting with Fable 5 to enable cross‑session detection. The company emphasizes that this retention was not intended for training on enterprise data; Anthropic states it has never trained on enterprise customers’ data without explicit permission.

Some enterprise customers—especially in regulated industries—found vendor‑side data retention difficult to accept. Anthropic worked with customers to design EFS so organizations can retain the privacy properties of ZDR while still enabling the time‑based monitoring necessary for effective detection.

Who helped build it

Anthropic developed EFS with feedback from more than 100 customers across financial services, healthcare, manufacturing, telecom, legal, retail and the public sector, and with cloud partners Amazon Web Services, Google Cloud and Microsoft Azure. Conversations included a quarter of the Fortune 100, every US global systemically important bank, and nearly every regulated industry vertical.

Participants included the Analysis and Resilience Center for Systemic Risk (ARC), whose membership includes the chief information security officers of major US banks such as Goldman Sachs, Morgan Stanley, Citi, Bank of America and Wells Fargo, and security and product leaders from companies like Comcast, KPMG, Mastercard, Salesforce and Visa.

Key controls and design choices

EFS offers customer‑controlled options that are opt‑in: customer‑owned storage, Customer‑Managed Encryption Keys, and fully automated monitoring with no Anthropic human review required. Those controls are intended to operate the same way whether customers access Claude directly from Anthropic or via cloud partners.

  • Customer‑owned storage: activity logs used for monitoring can be stored in the customer’s own cloud account (for example Amazon S3, Azure Blob Storage, or Google Cloud Storage).
  • Customer‑Managed Encryption Keys: customers can keep data encrypted under keys they control and use their own access policies and audit logging.
  • Automated review only: automated systems analyze a rolling window of traffic for signals of serious misuse (including attempts to develop offensive cyber or biological capabilities and signs of stolen or leaked credentials). When patterns of concern are detected, alerts are sent directly to the customer for their teams to review; Anthropic employees do not perform human review.

Anthropic notes these options do not change model behavior, API pricing, or rate limits. Anthropic will not charge for EFS itself; if customers choose to store data in their own cloud account, their cloud provider bills them for storage, reads/writes and egress in the usual way.

Customer and partner feedback

Several customers and partners that participated in the design emphasized that EFS gives them the control they requested. For example, Matt Chung, Chief Information Security Officer and Head of Technology Risk, said: "Enterprise Frontier Safeguards gives us exactly what we asked for: our logs stay in a Wells‑managed environment under Wells‑managed keys. We keep custody of our data while Anthropic operates the detection." Other security and product leaders from organizations including Stripe, Snowflake, Mastercard and others highlighted that keeping logs in the customer environment while enabling pattern‑based automated safety monitoring allows use of frontier models in regulated and sensitive workloads.

Supported products and platforms

EFS will be supported on Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google’s Agent Platform, and Microsoft Foundry. Anthropic is also working to support third‑party offerings for eligible customers.

Rollout and access

EFS will be introduced to customers in phases with the aim of broad availability later this fall. Interested customers are asked to request access via Anthropic’s sign‑up form. Until EFS is ready, eligible customers will continue to receive zero data retention on Claude Fable 5 and Fable 5.1.

Significance

Enterprise Frontier Safeguards is intended to enable organizations to deploy high‑capability "frontier" models while retaining technical custody of their logs and sensitive activity data. By combining customer‑controlled storage and keys with automated, cross‑session monitoring, Anthropic aims to provide structural controls at the architecture level that address both privacy concerns and the need to detect sophisticated misuse.