Anthropic announced Enterprise Frontier Safeguards (EFS) on September 1, 2026, a new deployment option that pairs the privacy of zero data retention with continuous misuse monitoring, ending a standoff with enterprise customers over how long the company may hold their Claude conversation data. The company said data under EFS lives in cloud infrastructure controlled by the customer, not by Anthropic, and that the solution will roll out to customers in phases starting later this fall.
The announcement resolves a tension that has been building since Anthropic introduced 30-day data retention with the Claude Fable 5 generation of models. The company argued at the time that effective abuse detection requires correlating activity across sessions and accounts over a meaningful window, because sophisticated misuse, from fraud to autonomous cyberattacks, is rarely visible in a single interaction. Regulated customers, however, balked at adding another vendor holding their sensitive traffic. With EFS, Anthropic is attempting to deliver both: monitoring that spans time and accounts, with the data itself stored under the customer's own encryption keys in their own cloud account, such as Amazon S3, Azure Blob Storage, or Google Cloud Storage. For more context on this story, see our ongoing latest AI developments.
Until EFS is generally ready, eligible customers will receive zero data retention on Fable 5 and Fable 5.1, according to the announcement.
Built with banks, hospitals, and a quarter of the Fortune 100
Anthropic said it developed EFS in close collaboration with more than 100 customers across financial services, healthcare, manufacturing, telecom, law, retail, and the public sector, alongside its cloud partners Amazon Web Services, Google Cloud, and Microsoft Azure. Notably, the company worked with the Analysis and Resilience Center for Systemic Risk, a group whose members include the chief information security officers of the largest US banks, among them Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo. Anthropic also cited design input from Comcast, KPMG, Mastercard, Salesforce, and Visa, and said its conversations spanned a quarter of the Fortune 100 and every US global systemically important bank.
The scope of that consultation signals how seriously large enterprises now treat agent-related risk. In the announcement, Anthropic described substantial evidence of attempted misuse over recent months, ranging from ordinary fraud to sophisticated cyberattacks in which agents engaged in destructive behavior, including incidents involving theft or misappropriation of enterprise credentials. The company's position is that this class of misuse is difficult to detect without traffic monitoring and cross-account correlation, which is precisely what many regulated customers were reluctant to permit on Anthropic's infrastructure.
How the safeguards work
Under EFS, customers control how data gets reviewed. When Anthropic's automated monitoring flags a pattern that needs attention, the signal is routed directly to the customer, whose own trained staff can confirm real misuse or clear false positives. Anthropic said many regulated industries require that human review be performed by the customer's own personnel, since their teams are already cleared to see privileged legal material, non-public information, or drug-safety reports.
The company also stressed a data-training boundary: Anthropic states it has never trained on enterprise data without explicit permission, and never will. Activity data used for monitoring can be stored in the customer's own cloud account under their access policies and audit logging, which addresses the contractual and compliance burden enterprises face when onboarding a new trusted data vendor.
At launch, EFS will be supported across Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google's Agent Platform, and Microsoft Foundry.
The timing is deliberate. EFS was announced the same day Anthropic launched Claude Fable 5.1 and made it generally available in GitHub Copilot, Amazon Bedrock, and Snowflake Cortex AI, and CNBC reported the company was changing its data retention policy after pushback from customers. Together, the launches package new frontier capability with a privacy architecture meant to answer the objections before enterprise buyers can raise them.
Why it matters for the frontier model market
The move arrives one day after Anthropic launched Claude Fable 5.1 and Mythos 5.1, models the company describes as its most capable for coding and knowledge work. In the EFS announcement, Anthropic framed Mythos-class models as a step change in intelligence and agentic capability that brings both misuse potential and autonomous misbehavior risk, and positioned EFS as the answer for enterprises that want frontier capability without surrendering data custody.
The design is also a competitive differentiator. Rival frontier labs have taken different approaches to enterprise privacy, and Anthropic is betting that letting customers keep logs inside their own cloud, under their own keys, while still getting frontier-grade abuse monitoring, will unlock deals in banking, healthcare, and the public sector that 30-day retention put at risk.
For CISOs, the practical question will be operational: EFS shifts review workloads onto customer teams, since flagged signals land on their desks rather than being resolved invisibly by the vendor. Enterprises that already run insider-risk programs are the natural early adopters, and Anthropic's phased rollout this fall will show whether the model holds up at production scale across the industries it was designed with.
---
Stay Ahead of AIGet the latest AI news, analysis, and breakthroughs — all in one place.
Read more AI news →