Anthropic announced Enterprise Frontier Safeguards (EFS), a solution designed to help companies use advanced models with security monitoring without giving up control of their data. The proposal combines the privacy of zero data retention, known as ZDR, with systems capable of detecting signs of abuse over time.
The difference lies in where the logs are stored: they remain in the cloud infrastructure controlled by each customer, not in Anthropic’s systems. EFS will begin rolling out in phases, and the company expects to make it broadly available later in fall 2026.
The dilemma between privacy and security
Frontier models, such as Claude Fable 5.1, can carry out more complex tasks and act as agents with greater autonomy. That creates opportunities for companies, but it also increases the risks: fraud, cyberattacks, credential misuse and autonomous behaviors that are difficult to detect.
The problem is that some attacks do not happen in a single conversation. They can develop across multiple sessions, different accounts and several days. If every interaction is analyzed and deleted immediately, identifying the full pattern becomes much more difficult.
For that reason, Anthropic began applying 30-day data retention with Fable 5. The company says this measure is not intended to train its models with business information. According to its policy, it has never used business data for training without explicit permission and says it will not do so.
EFS aims to solve a specific tension: companies need to detect complex abuse, but they must also keep their data within environments they control.
How Enterprise Frontier Safeguards works
With EFS, customers can store the activity data used for monitoring in their own cloud account, such as Amazon S3, Azure Blob Storage or Google Cloud Storage.
They can also protect that information with their own encryption keys, access policies and audit logs. In other words, the company retains custody of the storage and decides who can access the data.
Anthropic’s system analyzes a rolling window of activity to identify signs of serious misuse, such as:
- Attempts to develop offensive cyber capabilities.
- Signals related to dangerous biological capabilities.
- Stolen or leaked credentials.
- Anomalous patterns spanning multiple sessions and accounts.
When the system detects a relevant signal, the alert is sent directly to the customer. No human review by Anthropic employees is required. Each organization’s security team decides how to investigate the case and what actions to take.
Optional controls for each company
Customer-managed storage, customer-managed encryption keys and fully automated review are optional features. Organizations can activate only the controls they need.
Anthropic says these features do not change the model’s behavior, API pricing or usage limits. The company will not charge for EFS either, although the customer’s cloud provider will bill for storage, read and write operations and the corresponding data egress.
A design created with more than 100 companies
Anthropic developed EFS together with more than 100 customers from sectors including banking, healthcare, manufacturing, telecommunications, legal services, retail and government.
Participants included organizations and leaders from companies such as Comcast, KPMG, Mastercard, Salesforce and Visa. Anthropic also worked with the Analysis and Resilience Center for Systemic Risk, whose members include security leaders from major U.S. banks.
The collaboration aimed to answer very specific questions: who stores the data, who controls the keys, what can the automated system analyze, and under what circumstances can a person review an alert?
These questions are especially important for regulated sectors, where certain data may include privileged legal information, pharmaceutical safety reports, nonpublic financial information or intellectual property.
Availability in Claude and cloud platforms
Enterprise Frontier Safeguards will be compatible with:
- Claude Code.
- Claude Enterprise.
- Claude Platform.
- Amazon Bedrock.
- Claude Platform on AWS.
- Google Agent Platform.
- Microsoft Foundry.
Customers using Anthropic through AWS, Google Cloud or Microsoft Azure will have equivalent controls. In those cases, activity data will be stored in the organization’s own cloud account, within the environment it already uses and manages.
While EFS is being prepared, eligible customers will receive zero data retention on Fable 5 and Fable 5.1 to make the transition easier.
Why it matters for enterprise adoption
For years, many companies have treated artificial intelligence as a limited experiment. Not necessarily because the model was not useful, but because security, compliance and privacy could not accept just any architecture.
EFS aims to change that conversation. A financial company, hospital or law firm does not necessarily have to choose between using an advanced model and keeping control of its information. It can keep records in its own infrastructure, apply its internal policies and receive automated alerts about possible abuse.
This does not eliminate every risk. A monitoring system can generate false positives, miss new types of behavior or require careful configuration. But it represents an important shift: security no longer depends only on contractual promises and is also supported by the technical architecture.
EFS will begin rolling out in phases, with the goal of reaching broad availability later in fall 2026. Interested companies will be able to request access through the form published by Anthropic.
When AI enters sensitive areas, the question is no longer just how intelligent the model is. It also matters who controls the data, who can see an alert and what happens when the system detects something concerning. Anthropic is trying to answer those questions through the design itself, together with the organizations that will have to deal with the consequences in the real world.
Original source
https://www.anthropic.com/news/enterprise-frontier-safeguards
