On September 1, 2026, Anthropic announced Enterprise Frontier Safeguards (EFS), a technical solution designed to reconcile the privacy demands of regulated industries with the safety monitoring required by frontier models. Instead of Anthropic storing multi-day conversation logs on its own servers, EFS moves activity data directly into cloud infrastructure owned and controlled by the customer.
The system was co-designed over several months with more than 100 enterprise customers, including the Analysis and Resilience Center for Systemic Risk (ARC)—a coalition whose members include the chief information security officers of major US financial institutions like Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo.
Confirmed
- Customer cloud storage: Activity logs required for long-horizon misuse detection are stored in the customer’s existing cloud accounts (Amazon S3, Azure Blob Storage, or Google Cloud Storage) under their own access policies and audit logging.
- Customer-managed encryption keys (CMEK): All stored telemetry is encrypted using customer-controlled keys, preventing Anthropic or unauthorized parties from accessing stored records without active permission.
- Automated safety monitoring: Anthropic’s automated safety models inspect rolling windows of traffic for severe misuse—including autonomous cyber exploitation, biological risk development, and credential theft—without human review by Anthropic employees.
- Direct alert routing: When an automated detector flags potential abuse, security signals are sent directly to the customer’s internal security operations team for verification and remediation.
- Platform reach: EFS will deploy across Claude Code, Claude Enterprise, the direct Claude Platform, Amazon Bedrock, Google Agent Platform, and Microsoft Foundry.
- Pricing: Anthropic levies no additional licensing fee for EFS; customers pay standard cloud storage, read/write, and egress costs directly to their cloud infrastructure providers.
- Interim bridge: Eligible enterprise accounts retain Zero Data Retention (ZDR) on Claude Fable 5 and Fable 5.1 until EFS completes phased rollout later this fall.
Unknown
- Exact GA rollout schedule: Anthropic has not published specific deployment dates for individual cloud partners, citing a phased rollout through late autumn.
- Classifier false-positive handling: How automated detection flags interact with privileged legal communications or confidential M&A files when internal security teams investigate alerts.
- Threshold for model cutoff: The operational criteria under which Anthropic might revoke API access if an enterprise fails to remediate critical safety alerts surfaced by automated monitoring.
Why it matters
With the release of Mythos-class models like Fable 5 and 5.1, Anthropic introduced mandatory 30-day data retention to catch multi-session cyber misuse and credential hijacking. That policy created an immediate conflict for Wall Street banks, healthcare providers, and defense contractors whose legal mandates forbid third-party data retention. EFS solves this deadlock by decoupling detection algorithms from data custody: Anthropic provides the detectors, while the customer keeps the storage and the keys.
Our take
EFS is an essential architectural concession to the realities of regulated enterprise IT. Vendor promises of "we don't train on your data" are insufficient for CISOs operating under regulatory scrutiny. By relocating monitoring logs into the customer's cloud perimeter and eliminating vendor human review, Anthropic established a credible blueprint for deploying autonomous frontier agents inside institutions that cannot tolerate data leakage.