Anthropic Introduces Enterprise Frontier Safeguards for Privacy-Focused AI Security
Anthropic is introducing Enterprise Frontier Safeguards, combining zero data retention with automated misuse detection while allowing enterprises to store monitoring data in their own cloud infrastructure.
Xcademia Team
Xcademia Research Team

Anthropic is introducing Enterprise Frontier Safeguards (EFS), a new solution designed to combine the privacy of zero data retention (ZDR) with automated safeguards for detecting serious misuse of advanced AI models.
The company says EFS is designed around a customer-controlled data architecture. Instead of storing monitoring data in infrastructure controlled by Anthropic, customers can store that data in their own cloud environment.
Enterprise Frontier Safeguards will roll out to customers in phases, with broader availability targeted for later this fall. Anthropic says eligible customers will receive ZDR on Fable 5 and Fable 5.1 until EFS is ready.
The solution was developed in collaboration with more than 100 customers across industries including financial services, healthcare, manufacturing, telecommunications, law, retail and the public sector.
Anthropic also says it worked with cloud partners including Amazon Web Services, Google Cloud and Microsoft Azure.
EFS is planned to support Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google's Agent Platform and Microsoft Foundry.
The Enterprise AI Security Challenge
Anthropic says the development of more capable AI models brings both increased usefulness and increased potential for misuse.
The company describes its latest generation of advanced models, including Claude Fable 5.1, as having significantly increased intelligence and agentic capabilities.
According to Anthropic, attempted misuse observed in recent months has ranged from conventional abuse such as fraud to sophisticated cyberattacks in which AI agents can autonomously engage in destructive activity.
The company also says some observed incidents involved theft or misappropriation of enterprise credentials.
Detecting this type of activity can be difficult when suspicious behavior unfolds over multiple sessions and accounts.
Anthropic argues that analyzing each interaction independently and immediately discarding the associated data may not be sufficient for detecting more sophisticated misuse.
Instead, identifying patterns across time and accounts can require retaining activity data for a meaningful period.
Why Anthropic Introduced 30-Day Retention
Anthropic says it introduced a 30-day data-retention policy with Fable 5 because effective misuse detection can require correlation across multiple sessions and accounts.
The company says this decision was not motivated by a desire to train on enterprise data.
Anthropic states that it has never trained on enterprise data without explicit permission and says it will not do so.
However, the company says many enterprises, particularly those operating in regulated industries, found data retention difficult to reconcile with their privacy and compliance requirements.
This created a tension between two requirements:
Privacy
Organizations want control over sensitive enterprise data and may require zero data retention.
Security
Organizations also want monitoring that can identify sophisticated misuse occurring across sessions and accounts.
Enterprise Frontier Safeguards is designed to address both requirements.
EFS Was Developed With Enterprise Customers
Anthropic says it developed EFS through direct collaboration with more than 100 customers.
The company worked with security, product, compliance and delivery teams to understand the operational requirements surrounding AI monitoring and data management.
One organization involved in the collaboration was the Analysis and Resilience Center for Systemic Risk (ARC).
Anthropic says ARC members include chief information security officers from major US banks, including Goldman Sachs, Morgan Stanley, Citi, Bank of America and Wells Fargo.
The company also says it worked with leaders at organizations including Comcast, KPMG, Mastercard, Salesforce and Visa.
According to Anthropic, the discussions covered a quarter of the Fortune 100, every US global systemically important bank and virtually every regulated industry.
The company used this feedback to shape EFS around three major enterprise concerns:
Monitoring
Data storage
Automated and human review

Customer-Controlled Data Storage
Data storage is a central part of Anthropic's EFS design.
The company says enterprises often face significant administrative and compliance requirements when adding another trusted data vendor.
Organizations may need to notify customers, update contracts and satisfy internal requirements around data protection, storage and auditing.
EFS is therefore designed so that customers can store monitoring data within infrastructure they already control.
Activity data used for monitoring can be stored in the customer's own cloud account.
Anthropic gives examples including:
Amazon S3
Azure Blob Storage
Google Cloud Storage
Customers can maintain control over their data storage and management.
The architecture is intended to allow organizations to use their existing:
Encryption keys
Access policies
Audit logging
Cloud infrastructure
This approach means the monitoring data does not need to become an additional data repository controlled by Anthropic.
Automated Monitoring With Customer-Controlled Review
Another core component of EFS is how monitoring results are handled.
Anthropic says enterprises have long used monitoring to manage insider-risk concerns and increasingly want similar capabilities for AI agents.
However, organizations may have regulatory requirements governing who can access sensitive information.
Examples mentioned by Anthropic include:
Privileged legal material
Non-public information
Drug-safety reports
In these environments, organizations may prefer their own trained and authorized personnel to review security-related flags.
EFS is designed around automated safety monitoring without requiring human review by Anthropic employees.
Anthropic says its automated systems analyze a rolling window of traffic for signals of serious misuse.
The company specifically identifies signals such as:
Attempts to develop offensive cyber capabilities
Attempts to develop offensive biological capabilities
Signs of stolen or leaked credentials
When monitoring identifies a relevant signal, the resulting flag goes directly to the customer.
The customer's own personnel can then investigate and determine the appropriate response.
How Enterprise Frontier Safeguards Works
Anthropic says the controls are designed to operate consistently whether customers access Claude directly through Anthropic or through a cloud partner.
Customers using Amazon Web Services, Google Cloud or Microsoft Azure will receive equivalent controls, while their activity data is stored in their own cloud account.
The company says it is also working to support third-party offerings serving customers eligible for EFS.
The architecture centers around three optional capabilities:
Customer-Owned Storage
Customers can store activity data in their own cloud environment.
Customer-Managed Encryption Keys
Customers can use encryption controls managed within their own environment.
Fully Automated Review
Automated systems can review activity for signals of serious misuse without requiring human review by Anthropic employees.
Anthropic says each of these controls is opt-in, allowing organizations to enable the capabilities they need.

EFS Across Anthropic and Cloud Platforms
Anthropic says Enterprise Frontier Safeguards will be supported across multiple access and deployment environments.
The announced support includes:
Claude Code
Claude Enterprise
Claude Platform
Amazon Bedrock
Claude Platform on AWS
Google's Agent Platform
Microsoft Foundry
The company says the controls are designed to work in the same way whether customers access Claude directly from Anthropic or through cloud partners.
For customers using AWS, Google Cloud or Microsoft Azure, activity data can remain in their respective cloud accounts.
This is intended to allow organizations to apply the EFS approach without moving monitoring data into a separate Anthropic-controlled storage environment.
EFS Does Not Change Model Behavior or Pricing
Anthropic says the EFS controls do not change:
Model behavior
API pricing
Rate limits
The customer-owned storage, customer-managed encryption keys and fully automated review capabilities are optional.
Anthropic also says it does not charge customers for Enterprise Frontier Safeguards.
However, if a customer chooses to store data in its own cloud account, the applicable cloud provider charges for the storage and related resource usage.
Anthropic specifically notes that these costs can include:
Storage
Reads
Writes
Data egress
These are billed by the cloud provider in the same way as other cloud resources.
What the New Model Means for Regulated Enterprises
The announcement highlights a broader industry shift toward giving enterprises more control over how AI security monitoring data is stored and reviewed.
For organizations operating under strict regulatory or contractual requirements, the location and governance of monitoring data can be as important as the security capability itself.
EFS places those controls closer to the enterprise's existing security and compliance architecture.
Instead of requiring organizations to introduce another externally controlled data repository, the model allows monitoring activity data to remain within infrastructure already governed by the customer.
This could be particularly relevant for sectors where access to sensitive information is tightly controlled.
However, the practical implementation will depend on how individual organizations configure and govern the optional controls.
Additional details were not disclosed in the announcement.
Why Cross-Session Monitoring Matters
Anthropic's explanation for EFS centers on the changing nature of AI-assisted misuse.
Traditional security monitoring can often examine an individual event or interaction.
More sophisticated AI-enabled activity may involve multiple steps distributed across different sessions and accounts.
A single interaction might not appear suspicious when viewed independently.
Correlating activity over time can provide additional context.
Anthropic says this is why retaining activity data for a meaningful period can be necessary for certain forms of misuse detection.
EFS is designed to provide that monitoring capability while allowing the resulting data to remain under customer control.
Automated Monitoring and Human Oversight
Anthropic's approach also separates automated detection from human investigation.
The automated systems identify patterns that may indicate serious misuse.
The resulting signals are sent to the customer.
The customer's own security or compliance personnel can then decide whether the activity represents genuine misuse, a false positive or another situation requiring investigation.
This model is particularly relevant to organizations where internal policies or regulations restrict which individuals can access certain information.
Anthropic says EFS does not require human review by Anthropic employees.
The company therefore positions customer-controlled review as an important part of the solution for regulated environments.

Enterprise Frontier Safeguards Availability
Anthropic says EFS will roll out to customers in phases.
The company aims to make the solution broadly available later this fall.
Eligible customers will receive ZDR on Fable 5 and Fable 5.1 until EFS is ready, according to Anthropic.
Organizations interested in Enterprise Frontier Safeguards can request access through Anthropic's access-request process.
The announcement does not provide a specific public availability date.
A Different Approach to Enterprise AI Safety
Enterprise Frontier Safeguards represents an approach in which AI safety monitoring and enterprise data governance are designed together.
The development reflects growing demand for AI systems that can be monitored for serious misuse while remaining compatible with organizational privacy, security and compliance requirements.
Anthropic's announcement focuses on three principles:
Detect misuse
Automated monitoring looks for patterns associated with serious misuse.
Keep data under customer control
Customers can store activity data within their own cloud infrastructure and apply their own controls.
Keep sensitive review with the customer
Monitoring signals are delivered to customers so their own personnel can investigate them.
The combination is intended to address a specific challenge faced by enterprises adopting increasingly capable AI systems.
What Enterprises Should Watch
The EFS announcement raises several considerations for organizations deploying advanced AI systems.
Data governance
Organizations need to understand where AI activity data is stored, who can access it and how long it remains available.
Monitoring requirements
Security teams may need monitoring capabilities that can correlate activity across sessions and accounts rather than examining interactions individually.
Encryption and access controls
Customer-managed encryption keys and customer-controlled access policies can align AI monitoring with existing enterprise security frameworks.
Human review
Organizations operating in regulated sectors may need clearly defined processes determining who can review sensitive AI activity.
Cloud integration
The support for AWS, Google Cloud and Microsoft Azure provides a path for organizations to keep activity data within existing cloud environments.
Operational costs
While Anthropic says it does not charge for EFS, customers choosing cloud-based storage remain responsible for cloud-provider charges associated with storage and related operations.
Conclusion
Anthropic is introducing Enterprise Frontier Safeguards as an enterprise-focused approach to AI safety monitoring that combines zero data retention with automated misuse detection.
The solution is designed to allow customers to keep monitoring data within their own cloud infrastructure, under their own encryption keys, access policies and audit controls.
Anthropic says its automated systems can analyze a rolling window of activity for signals of serious misuse, including attempted development of offensive cyber or biological capabilities and indications of stolen or leaked credentials.
When relevant signals are detected, they are sent directly to customers for review. Anthropic says EFS does not require human review by its employees.
The company developed the solution with more than 100 customers across regulated and non-regulated industries, as well as cloud partners AWS, Google Cloud and Microsoft Azure.
EFS will initially roll out in phases, with broader availability targeted for later this fall.
The announcement highlights a broader industry shift toward treating AI safety, enterprise privacy and data governance as connected requirements rather than separate concerns.
For enterprises adopting increasingly capable AI agents, the ability to monitor potential misuse while retaining control over sensitive activity data could become an important part of AI security architecture.
Additional details were not disclosed in the announcement.
Source: Anthropic
About the Author