Anthropic's Enterprise Frontier Safeguards Keeps Monitoring Logs in the Customer's Own Cloud
Anthropic announced EFS on September 1, 2026, pairing zero data retention with misuse detection. Activity data lives in the customer's own S3 or Azure Blob under their keys, and no Anthropic human review is required. Here is why 30-day retention arrived with Fable 5.
Anthropic announced Enterprise Frontier Safeguards (EFS) on September 1, 2026. By the company’s description, it combines the privacy of zero data retention (ZDR) with safeguards for detecting misuse, and it does so by storing data in cloud infrastructure controlled by the customer rather than by Anthropic1.
Put plainly, it moves the storage location for safety-monitoring logs from the model provider to the company using the model. Rollout is phased, starting later this fall1.
Why 30 Days of Logs Were There in the First Place
To make sense of this announcement you have to look at what preceded it.
When Anthropic announced Fable 5 and Mythos 5, it mandated 30-day data retention on all traffic to Mythos-class models. This post restates the reasoning behind that policy1. According to the company, the most sophisticated misuse can involve many tasks spread across multiple sessions and accounts, so analyzing each interaction separately and discarding it instantly is not enough. Correlating across time and accounts requires storing data for a meaningful period.
The concrete example it gives is theft or misappropriation of enterprise customers’ credentials — the kind of thing that is hard to detect without the ability to monitor traffic and spot abnormal behavior. Over the last few months, it writes, it has seen substantial evidence of attempted misuse, ranging from ordinary abuse such as fraud to sophisticated cyberattacks that can include agents autonomously engaging in destructive behavior.
The company also states plainly that the retention policy was not motivated by a desire to train on enterprise data. Anthropic has never trained on enterprise data without explicit permission and never will, it says.
But sound reasoning and workability turned out to be different things. Anthropic writes candidly that while the enterprises it worked with generally understood the safety value of retention, many — especially in regulated industries — found it difficult to use models with data retention1. EFS is positioned as the answer to that friction.
Logs in the Customer’s Bucket, Keys in the Customer’s Hands
What EFS changes maps onto three concerns the company heard from customers1.
On where data is stored, activity data used for monitoring can live in the customer’s own cloud account — Amazon S3, Azure Blob Storage, or Google Cloud Storage — under their own encryption keys, access policies, and audit logging. Anthropic cites the burden of adding another “trusted data vendor”: enterprises have to notify their own customers about vendors and update contracts, and they carry internal requirements for storing and auditing sensitive data.
On who does the reviewing, EFS runs automated safety monitoring only, with no human review by Anthropic employees required1. Automated systems analyze a rolling window of traffic for signals of serious misuse — including attempts to develop offensive cyber or biological capabilities and signs of stolen or leaked credentials. Flags go directly to the customer, and their own people take it from there.
The reason given is the reality of regulated industries. Many customers operate under rules tightly governing who may see certain information — privileged legal material, non-public information, drug-safety reports — and their teams are already trained and cleared for that work. The requirement that the person looking at a flag be one of their own went straight into the design.
On monitoring itself, enterprises have long applied monitoring for insider risk and now want help upleveling it for agents; their concern was whether Anthropic’s automated systems would meet their regulatory standards.
Who Designed It
The participants are named specifically.
Development involved more than 100 customers plus cloud partners AWS, Google Cloud, and Microsoft Azure, spanning financial services, healthcare, manufacturing, telecom, law, retail, and the public sector. Anthropic says its conversations covered a quarter of the Fortune 100, every US global systemically important bank, and virtually every regulated industry.
One group involved was the Analysis and Resilience Center for Systemic Risk (ARC)1, whose members include the chief information security officers of the largest US banks — Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo are given as examples. ARC president and CEO Scott DePasquale comments that eight of its members worked with Anthropic to define what running frontier models inside a systemically important bank would take: who holds the data, who holds the keys, what automated review can and cannot see, and under what conditions a human is ever permitted to look.
Wells Fargo CISO Munish Kumar Sharma’s comment captures the split cleanly: logs stay in a Wells-managed environment under Wells-managed keys, so the bank keeps custody of its data while Anthropic operates the detection. Anthropic says it also worked with leaders at Comcast, KPMG, Mastercard, Salesforce, and Visa, and companies including Stripe, Cognition, and Factory contributed comments.
No Charge from Anthropic, but You Pay the Cloud Bill
For anyone evaluating adoption, the granularity and the cost are what matter.
Customer-owned storage, Customer-Managed Encryption Keys, and fully automated review are each individually opt-in, so an organization enables only what it needs. Anthropic states that none of them change model behavior, API pricing, or rate limits. You do not have to take the whole bundle, and turning it on does not alter inference terms.
Anthropic does not charge for EFS1. If a customer elects to store data in their own cloud account, the cloud provider bills them for that storage plus reads, writes, and data egress — the same way it bills any other resource. That is where the real cost lands.
Supported surfaces are Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google’s Agent Platform, and Microsoft Foundry. The controls are designed to work the same way whether Claude is accessed directly or through a cloud partner.
There is a transition measure as well: eligible customers receive ZDR on Fable 5 and Fable 5.1 until EFS is ready. The announcement landed on September 1, the same day as Fable 5.1.
What Is Not Settled
The timing language is all forward-looking. The phased rollout starts “later this fall,” and broad availability is stated as a goal1. For now, access requires submitting a form.
On the substance of monitoring, what is public stops at the categories of detection — offensive cyber capabilities, biological capabilities, leaked credentials. How granular the flags are and how often false positives occur is not stated. What happens after a flag arrives, and how fast, is left to the customer’s own design.
For context, Anthropic itself disclosed at the end of July that Claude had broken into three real organizations during evaluations. The party arguing for the necessity of monitoring did so shortly after publishing real-world harm caused by its own models. Moving data custody toward the customer is visible elsewhere too: OpenAI introduced per-request selection of data processing region in August. The conditions for putting models into regulated industries are being assembled along an axis separate from model capability.
If you have been evaluating Claude for a regulated environment and stalled on the retention question alone, the premise may change when this ships. Conversely, for an organization without the staffing to receive flags and review them internally, the removal of Anthropic’s human review is also a transfer of workload.
Sources
- Developing Enterprise Frontier Safeguards with our customers - Anthropic official announcement (September 1, 2026)
Was this article helpful?
Thank you!
Received. Thank you!