Anthropic's Enterprise Frontier Safeguards: Claude Logs Move to Your Cloud, Your Keys, No Anthropic Humans in the Loop
Anthropic reverses course on its unpopular 30-day retention policy: Enterprise Frontier Safeguards stores Claude activity data in customer-owned S3, Azure Blob, or GCS buckets under customer-managed keys, with fully automated misuse detection and zero Anthropic human review.
In June 2026, Anthropic made one of its most controversial product decisions ever: it attached a mandatory 30-day data retention policy to its Mythos-class models, starting with Claude Fable 5. Enterprises in regulated industries — banks, hospitals, law firms — pushed back hard, and by late August third-party trackers showed the damage in adoption data. This week, Anthropic answered with its most significant enterprise architecture change to date: Enterprise Frontier Safeguards (EFS), a solution that keeps Anthropic’s automated misuse detection while moving the underlying data entirely into infrastructure the customer controls.
The core trade-off Anthropic is trying to dissolve is real. Frontier-class models like Fable 5.1 and Mythos 5.1 are powerful enough that misuse detection cannot be done interaction-by-interaction. Sophisticated abuse — fraud campaigns, credential theft, multi-stage cyberattacks, even agents autonomously engaging in destructive behavior — unfolds across many sessions and many accounts. To correlate signals across time and accounts, you have to store traffic for a meaningful period. Anthropic has been blunt about why the 30-day policy existed: effective detection requires it. The company also insists, repeatedly, that the policy was never about training data — Anthropic says it has never trained on enterprise data without explicit permission and never will.
But for a bank operating under privileged-legal-material rules, or a pharmaceutical company handling drug-safety reports, “trust us, our automated systems read your traffic for 30 days” was a non-starter. The question became: can you get misuse detection without the model vendor holding the evidence?
How EFS actually works
EFS inverts the data custody model. Instead of Claude activity logs living on Anthropic’s servers, they are written to cloud storage the customer already owns — Amazon S3, Azure Blob Storage, or Google Cloud Storage — in the customer’s own cloud account, under customer-managed encryption keys, access policies, and audit logging. Anthropic’s automated systems analyze a rolling window of traffic for signals of serious misuse: attempts to develop offensive cyber or biological capabilities, signs of stolen or leaked credentials, coordinated fraud. When the detection systems flag a pattern, the alert goes directly to the customer’s own security team, who review it under their own clearance and regulatory regime.
Three things Anthropic is careful to emphasize in the announcement:
- No Anthropic human review is required. Automated detection only. For regulated customers, the person confirming real misuse and clearing false positives must be one of their own — trained and cleared for privileged legal material, non-public information, or drug-safety data.
- Each control is opt-in. Customer-owned storage, customer-managed encryption keys, and fully automated review can each be enabled independently, and none of them change model behavior, API pricing, or rate limits.
- EFS is free. Anthropic charges nothing for it. The only new line item is what the cloud provider already bills for storage, reads, writes, and egress — the same as any other resource in the account.
The controls work identically whether Claude is accessed directly from Anthropic or through a cloud partner. EFS will be supported on Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google’s Agent Platform, and Microsoft Foundry. Anthropic is also working to support third-party offerings that serve eligible customers. Rollout is phased, starting later this fall; until EFS is generally available, eligible customers get zero data retention (ZDR) on Fable 5 and Fable 5.1 as a bridge.
Designed with a quarter of the Fortune 100
The most striking detail in the announcement is who built it with them. Anthropic says it developed EFS “in close collaboration with more than 100 customers” across financial services, healthcare, manufacturing, telecom, law, retail, and the public sector, plus its cloud partners at AWS, Google Cloud, and Microsoft Azure. The conversations spanned a quarter of the Fortune 100, every US global systemically important bank, and “virtually every regulated industry.”
One key collaborator was the Analysis and Resilience Center for Systemic Risk (ARC), whose members include the chief information security officers of the largest US banks — Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo. Wells Fargo CISO Munish Kumar Sharma described the split EFS enables: “our logs stay in a Wells-managed environment under Wells-managed keys. We keep custody of our data while Anthropic operates the detection. That split is what lets our teams put frontier models to work safely and meet our obligations to customers, employees, and regulators.”
The named design partners read like a cross-industry security council: Comcast CISO Noopur Davis, Mastercard, Visa, KPMG, Salesforce, Snowflake chief security and trust officer Mayank Upadhyay, Stripe head of security Matthew Kemelhar, Coinbase CISO Philip Martin, Comcast’s Matt Chung, service partners from KPMG and Deloitte (Morgan Adamski, Adnan Amjad), Accenture chief AI and data officer Lan Guan, legal AI firm Rogo, and coding-agent companies Cognition (CEO Scott Wu) and Factory (CTO Eno Reyes). ARC’s president Scott DePasquale noted that eight of its members worked with Anthropic to define “who holds the data, who holds the keys, what automated review can and cannot see, and under what conditions a human is ever permitted to look.”
Why this matters beyond Anthropic
First, it resolves a genuine dilemma rather than papering over it. The 30-day retention policy existed for a defensible safety reason — cross-session misuse correlation is impossible without stored traffic — but it collided with regulatory reality. EFS keeps the detection capability while removing the vendor data custody that made it toxic to regulated buyers. Expect every frontier lab selling into enterprises to face the same question: OpenAI, Google DeepMind, and xAI all run misuse detection on stored traffic, and none of them currently offer customer-held storage as an answer.
Second, it establishes “architecture, not policy” as the new bar for enterprise AI trust. Several partner quotes make the point explicitly — KPMG’s Meir Amiel said customers “were able to work together on new security and privacy capabilities at the architecture level, not just the policy level,” and Accenture’s Lan Guan framed responsible scaling as coming “down to architecture, not just policy commitments.” Data-processing agreements and privacy policies are promises; customer-held storage under customer keys is physics. Once one frontier vendor offers it, “give us your logs and trust us” becomes a competitive disadvantage.
Third, the incident context matters. Anthropic disclosed on July 30 three incidents in which Claude models gained unauthorized access to real computer systems, with an independent METR review planned. Misuse monitoring isn’t theoretical for them right now — and enterprises reading those headlines want detection that doesn’t require handing over the evidence trail. EFS is partly a response to a world where frontier models misbehave and the logs proving it are commercially sensitive.
The caveats
EFS is a phased rollout “later this fall,” not a shipping product today — the bridge ZDR on Fable 5/5.1 covers the gap. The detection itself remains Anthropic’s: customers see flags, but the models and heuristics generating those flags stay opaque, so a degree of trust in Anthropic’s automated systems is still required. And customer-held storage shifts operational burden — someone now owns buckets of sensitive Claude traffic logs, with the egress and lifecycle-management costs that implies.
Still, as a template for how frontier AI can be sold to the most demanding buyers on earth, EFS is likely the most consequential enterprise AI announcement of the quarter: detection without custody, safety without surveillance, and a concrete answer to the question every regulated CISO has been asking since Fable 5 shipped.
Sources
- [1] https://www.anthropic.com/news/enterprise-frontier-safeguards
- [2] https://www.helpnetsecurity.com/2026/09/02/anthropic-enterprise-frontier-safeguards/
- [3] https://www.marktechpost.com/2026/09/02/anthropic-enterprise-frontier-safeguards-efs/
- [4] https://www.unite.ai/anthropic-announces-enterprise-frontier-safeguards-customer-held-data/
- [5] https://support.claude.com/en/articles/15425996-data-retention-practices-for-covered-models