Anthropic

Enterprise Frontier Safeguards: Building Trust Through Customer-Controlled Monitoring

Anthropic's new Enterprise Frontier Safeguards lets regulated enterprises use frontier models while keeping monitoring data in their own cloud accounts, with no Anthropic human review.

Enterprise Frontier Safeguards: Building Trust Through Customer-Controlled Monitoring — article cover
On this page6 SECTIONS
  1. The core tension: frontier capability vs. data custody
  2. What changes under EFS
  3. Why customers asked for this design
  4. Rollout and platform support
  5. What this means for product builders
  6. Sources

The core tension: frontier capability vs. data custody

Anthropic announced Enterprise Frontier Safeguards (EFS) on September 1, 2026, as a way to resolve a dilemma that has slowed adoption of its most capable models in regulated industries. Mythos-class models like Claude Fable 5.1 bring a step change in intelligence and agentic behavior, but that also raises the stakes for misuse—including fraud, sophisticated cyberattacks, and autonomous destructive behavior. Detecting those patterns requires monitoring traffic across sessions and accounts over time, which historically meant Anthropic would retain enterprise data for 30 days.

That retention policy was never about training on customer data. Anthropic states it has never trained on enterprise data without explicit permission and never will. But for many enterprises—especially banks, healthcare providers, and law firms—the mere fact that data lived outside their control created compliance friction. EFS is the result of designing around that constraint rather than asking customers to accept it.

What changes under EFS

The architectural shift is straightforward: activity data used for safety monitoring is stored in the customer’s own cloud account—Amazon S3, Azure Blob Storage, or Google Cloud Storage—under the customer’s encryption keys, access policies, and audit logging. Anthropic’s automated systems analyze a rolling window of that traffic for signals of serious misuse, such as attempts to develop offensive cyber or biological capabilities or signs of stolen credentials. When a pattern needs attention, the flag goes directly to the customer’s security team. No Anthropic employee reviews the data.

This split—Anthropic operates the detection, the customer keeps custody of the data—was shaped by more than 100 customers across financial services, healthcare, manufacturing, telecom, law, retail, and the public sector. The collaboration included the Analysis and Resilience Center for Systemic Risk (ARC), whose members include chief information security officers from Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo. Leaders from Comcast, KPMG, Mastercard, Salesforce, Visa, and others also provided input.

Why customers asked for this design

Three concerns came up repeatedly in those conversations. First, adding another “trusted data vendor” is expensive: enterprises must notify their own customers, update contracts, and meet internal storage and auditing requirements. Second, many regulated firms operate under rules that tightly govern who may see privileged legal material, non-public information, or drug-safety reports. Their own teams are already trained and cleared for that review work—so the person looking at a flag should be one of their own. Third, automated monitoring is useful, but a human reviewer still adds value by confirming real misuse and clearing false positives. EFS addresses all three by keeping data in customer-controlled infrastructure and routing flags to the customer’s team.

Rollout and platform support

EFS will roll out in phases starting later this fall. To smooth the transition, eligible customers will receive zero data retention (ZDR) on Fable 5 and Fable 5.1 until EFS is ready. The solution will be supported on Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google’s Agent Platform, and Microsoft Foundry.

What this means for product builders

For teams building on frontier models in regulated spaces, EFS removes a structural blocker. The pattern is worth studying even if you’re not an Anthropic customer: separate the detection layer from the data custody layer, and let the customer’s own security team own the review loop. That’s not just a compliance checkbox—it’s what lets organizations deploy AI in parts of the business they previously couldn’t touch. As one service partner quoted in the announcement put it, the safeguards “allow us to apply AI in parts of the business that we wouldn’t have been able to before.”

EFS is not a universal answer. It requires customers to operate their own storage and review workflows, which adds operational overhead. But for enterprises that already have those capabilities, it converts a hard privacy tradeoff into an architecture decision.

Sources

AI-assisted summary compiled from the sources above, reviewed by a human before publishing.

FOUND_THIS_USEFUL?

Support more practical AI articles, tutorials, and build notes.

BUY_ME_A_COFFEE
SHAREXEMAIL