Anthropic's Enterprise Frontier Safeguards: Claude Logs Stay in Your Cloud, Detection Stays With Anthropic

Anthropic's Enterprise Frontier Safeguards: Claude Logs Stay in Your Cloud, Detection Stays With Anthropic
Anthropic's Enterprise Frontier Safeguards: Claude Logs Stay in Your Cloud, Detection Stays With Anthropic (Image with AI)
 

Anthropic's Enterprise Frontier Safeguards: Claude Logs Stay in Your Cloud, Detection Stays With Anthropic

A New Answer to an Old Enterprise Problem

For nearly two years, the biggest obstacle to deploying frontier AI models inside heavily regulated industries hasn't been capability — it's been custody. Banks, insurers, and other regulated firms have wanted the most advanced Claude models for coding, research, and internal automation, but corporate security and compliance teams have consistently balked at one detail: where does the data go once a prompt leaves the building? This week, Anthropic tried to resolve that tension with a new offering called Enterprise Frontier Safeguards, or EFS. The idea is simple to state and genuinely difficult to build: let the customer keep full physical and legal custody of their own activity logs, while still letting Anthropic's automated systems watch that data closely enough to catch sophisticated misuse before it turns into a real-world incident.

The announcement lands at a moment when the debate over AI data retention has become sharper rather than softer. Earlier this year, when Anthropic shipped its Fable 5 model line, it moved away from the zero-data-retention (ZDR) posture that many enterprise customers had grown to rely on, introducing a 30-day retention window instead. The company's stated justification wasn't training data collection — Anthropic has been clear that it does not train on enterprise data without explicit customer permission — but detection quality. According to the company, the most dangerous kinds of misuse rarely show up in a single prompt or a single session. They spread across many tasks, multiple sessions, and sometimes multiple accounts, and a system that scans one interaction in isolation and then immediately deletes it has no way to notice a pattern stitched together over days or weeks. Zero-day retention, in other words, was safe for privacy but blind to slow-moving abuse.

That trade-off was a hard sell to exactly the customers Anthropic most wants to keep: systemically important financial institutions bound by strict regulatory obligations around data handling, vendor risk, and third-party access. For those companies, simply adding Anthropic as a new place where sensitive logs might sit for a month wasn't a minor technicality — it meant renegotiating contracts, notifying their own customers and regulators, and satisfying internal audit requirements that treat every new data holder as a new attack surface. Several banks reportedly pushed back hard enough that Anthropic went back to the drawing board with them directly.

How Enterprise Frontier Safeguards Actually Works

EFS splits the problem into two separate questions: where does the data physically live, and who looks at it when something suspicious is flagged. On the first question, Anthropic's answer is that the customer's own cloud environment becomes the storage location. Activity data used for misuse monitoring can be kept in the customer's Amazon S3 bucket, Azure Blob Storage account, or Google Cloud Storage bucket, encrypted under keys the customer controls, governed by the customer's own access policies, and captured in the customer's own audit logs. Anthropic never takes physical custody of that data at all — it simply runs its detection models against data sitting inside infrastructure the customer already owns and already trusts.

On the second question — who reviews an alert once the automated systems flag something — the answer under EFS is the customer, by default. Anthropic's detection systems continuously analyze a rolling window of activity for signals associated with serious misuse: attempts to develop offensive cyber capabilities, indications of biological weapons research, or signs that account credentials have been stolen or leaked. When a pattern like that surfaces, the alert routes straight to the customer's own security team rather than to a human reviewer inside Anthropic. That is a meaningful shift in operating model — Anthropic keeps building and running the detection logic, but the customer inherits the job of actually triaging what the system finds.

Coverage is broad by design. Anthropic has named Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, the Claude Platform on AWS, Google's Agent Platform, and Microsoft Foundry as the intended surfaces for EFS, with the stated goal of equivalent controls regardless of whether a customer buys access directly from Anthropic or through one of its cloud partners. Amazon has independently confirmed its side of the arrangement for Bedrock and the Claude Platform on AWS, describing a setup where safeguards data lands in the customer's own AWS account under the customer's keys and policies, with automated review and no requirement for Anthropic staff to look at anything. That independent confirmation matters because it shows the architecture isn't just a slide in a press release — at least one major cloud partner has built toward it. It doesn't, however, prove the system is ready across every named platform simultaneously.

Anthropic has also structured EFS so that its individual pieces are optional rather than bundled. Customer-owned storage, customer-managed encryption keys, and fully automated review are each opt-in controls that an organization can turn on separately depending on what its own compliance posture requires. Turning any of them on is explicitly designed not to change how the underlying Claude models behave, what customers pay for API usage, or what rate limits apply. That separation is a deliberate signal to enterprise buyers: this is a data-governance layer bolted on top of the product, not a different, degraded version of the product itself.

Who Asked For This — and What It Cost Them

The customers named in Anthropic's rollout are not incidental logos. Wells Fargo's Chief Information Security Officer, Munish Kumar Sharma, was quoted describing the arrangement as giving his team what they'd specifically asked for: logs that stay inside an environment Wells Fargo manages, under keys Wells Fargo manages, while Anthropic continues to operate the actual detection logic. That framing — custody with the customer, detection with the vendor — is the entire thesis of EFS in one sentence, and it's notable that a bank's own security chief is the one Anthropic chose to make that case publicly.

Wells Fargo wasn't operating alone. Scott DePasquale, president and CEO of the Analysis and Resilience Center (ARC), an industry group whose membership includes Goldman Sachs, Morgan Stanley, Citigroup, Bank of America, and Wells Fargo, said eight member institutions worked directly with Anthropic to define the technical and contractual conditions required to run frontier-scale models inside a systemically important bank. That's a striking degree of direct involvement from the buy side of the market — this wasn't a feature Anthropic designed in isolation and then pitched to banks after the fact. It was, by Anthropic's own account and the customers' own accounts, co-designed with the institutions that had the most regulatory exposure and the least tolerance for ambiguity about where their data sits.

The commercial terms are also worth noting. Anthropic is not charging a separate fee for EFS itself. Instead, the costs shift toward the customer in two ways: cloud providers bill separately for the storage, read/write operations, and egress associated with keeping monitoring data in the customer's own account, and any staffing needed to actually triage alerts becomes the customer's responsibility rather than Anthropic's, since human review defaults to the customer's own team. Anthropic hasn't published an estimate of what either of those costs might run to in practice, which leaves security leaders to model that expense internally before they can fully evaluate whether EFS is a net win compared with the retention policy it replaces.

Availability, and What Isn't Settled Yet

As of the announcement, Enterprise Frontier Safeguards is not something a customer can turn on today. Anthropic has described a phased rollout aimed at broader availability later this fall, with initial access handled on a request basis rather than opened to every enterprise customer at once. In the interim, eligible customers can run Claude Fable 5 and Fable 5.1 under the older zero-data-retention arrangement, which sidesteps the whole EFS question by simply not keeping activity data at all — at the cost of the cross-session detection capability that motivated Anthropic to move away from ZDR for its most capable models in the first place.

There are open questions that the announcement itself doesn't resolve. No independent, published results exist yet showing how effectively EFS actually detects misuse once data is stored in a customer's own cloud rather than Anthropic's; the claims so far are Anthropic's own description of the architecture and design intent, not third-party validation of detection performance. It's also unclear how the model interacts with regulatory frameworks outside the United States, or how smaller enterprise customers without a dedicated security operations team will handle the alert-triage responsibility that larger banks are equipped to absorb. And because human review defaults to the customer rather than to Anthropic, organizations that want a fully hands-off experience will need to weigh whether staffing an alert queue is something they're prepared to take on in exchange for keeping their logs at home.

What is clear is the direction of travel. Anthropic is treating data custody as a negotiable, modular layer that can be reshaped around a customer's specific compliance obligations, rather than a single fixed policy applied uniformly to everyone. Whether that flexibility becomes the new standard for how frontier AI vendors work with regulated industries, or remains a bespoke arrangement built for a handful of systemically important banks, will likely depend on how smoothly the fall rollout goes and how the economics look once customers actually see their own cloud bills.


FAQs

1. What is Enterprise Frontier Safeguards (EFS)? It's Anthropic's new architecture that lets misuse-monitoring data stay stored in a customer's own cloud account (AWS, Azure, or Google Cloud) under the customer's own encryption keys, while Anthropic's automated systems still run detection against that data.

2. Does EFS bring back zero data retention? Not exactly. It replaces the 30-day retention window introduced with Fable 5 by moving the retained data into customer-controlled storage rather than eliminating retention altogether, since Anthropic says cross-session detection needs some retained history to work.

3. Who reviews the alerts EFS generates? By default, the customer's own security team reviews flagged activity. Anthropic's systems generate the alerts, but human review inside Anthropic is not part of the standard EFS flow.

4. Which products will support EFS? Anthropic has named Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, the Claude Platform on AWS, Google's Agent Platform, and Microsoft Foundry as planned coverage areas.

5. When can customers actually start using it? EFS was announced but not generally available as of the announcement. Anthropic says rollout will happen in phases, with broader availability targeted for later in fall 2026.

Post a Comment

0 Comments