Back to News
SecurityAI Understanding briefing

Anthropic announces customer-controlled safeguards for frontier AI deployments

Anthropic says Enterprise Frontier Safeguards will let eligible organizations store monitoring data in their own cloud environments while using automated detection for serious AI misuse.

By 5 min readRead the primary source
Source-page capture accompanying Anthropic announces customer-controlled safeguards for frontier AI deployments
The short version

Anthropic says Enterprise Frontier Safeguards will let eligible organizations store monitoring data in their own cloud environments while using automated detection for serious AI misuse.

What happened

Anthropic announced Enterprise Frontier Safeguards, a planned enterprise service that combines zero data retention with automated monitoring for serious misuse of its frontier models. The company says customer data will remain in infrastructure controlled by the customer, with rollout beginning in phases later this fall.

Anthropic says Enterprise Frontier Safeguards, or EFS, is designed to combine zero data retention with safeguards that detect serious misuse. Under the planned architecture, activity data used for monitoring can be stored in a customer’s own cloud account, including Amazon S3, Azure Blob Storage or Google Cloud Storage. Customers can use their own encryption keys, access policies and audit logging. Anthropic says the service will be supported across Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google’s Agent Platform and Microsoft Foundry.

The company says EFS was developed with more than 100 customers across financial services, healthcare, manufacturing, telecommunications, law, retail and the public sector. Anthropic also names Amazon Web Services, Google Cloud and Microsoft Azure as cloud partners. It says the design involved security, compliance, product and delivery teams, including members of the Analysis and Resilience Center for Systemic Risk and companies such as Comcast, KPMG, Mastercard, Salesforce and Visa. These are statements from Anthropic and participating organizations; the source does not independently verify their assessments.

Anthropic says the system will analyze a rolling window of traffic for signals of serious misuse, including attempts to develop offensive cyber or biological capabilities and signs of stolen or leaked credentials. Alerts will go directly to the customer, whose personnel can investigate them. Anthropic says no human review by Anthropic employees is required. Customer-owned storage, customer-managed encryption keys and fully automated review are described as optional controls. The company says EFS will not change model behavior, API pricing or rate limits, and that Anthropic will not charge for the service, although customers may incur ordinary cloud storage, read, write and data-egress fees. The announcement presents these controls as parts of the planned service rather than as changes to the underlying models. Its description links storage, encryption, access and alert handling to the customer’s existing cloud environment. Anthropic’s stated scope therefore covers both the monitoring function and the way resulting records are handled by participating organizations.

Source details: anthropic.com

Why it matters

The service addresses a central problem for regulated organizations: detecting misuse across multiple AI sessions may require retaining activity data, while privacy and compliance rules can restrict where that data is stored and who can review it.

The announcement addresses a tension created by more capable AI systems. Anthropic says models such as Claude Fable 5.1 have greater intelligence and agentic capabilities, increasing the potential for both misuse and autonomous misbehavior. The company says sophisticated abuse can involve many tasks spread across sessions and accounts, making it harder to identify through isolated, immediately discarded interactions. A monitoring system that correlates activity over time may therefore provide information that a strict zero-retention setup cannot.

That capability creates a separate privacy and compliance problem. Regulated organizations may have limits on which vendors can hold sensitive records and which people may view privileged legal material, non-public information or drug-safety reports. EFS is intended to let those organizations keep logs in infrastructure they already control and apply their existing keys, permissions and audit systems. If implemented as described, that could reduce the need to add Anthropic or another outside data custodian to an organization’s list of trusted vendors.

The practical significance remains contingent on performance and governance. The source contains endorsements from executives at Wells Fargo, Stripe, Snowflake, Cognition, Factory and other organizations, but it provides no independent testing of detection accuracy, false-positive rates, latency or coverage. It also does not establish that customer-controlled storage eliminates every privacy or security risk. The service shifts important responsibilities toward customers, including access control, investigation, retention decisions and responses to alerts. The proposed arrangement also separates the act of detecting signals from the custody of the records used in that process. In Anthropic’s description, the customer retains control over storage, keys, permissions and review. That separation is the basis for the service’s claimed fit with organizations that need monitoring while limiting outside access to sensitive activity data.

What to watch next

The key unknowns are how effective the monitoring will be, how eligibility will be determined, and how customers will respond to alerts. Anthropic has not provided detection-performance measures, detailed technical specifications, or a firm availability date.

The first issue is deployment. Anthropic says EFS will roll out in phases, starting later this fall, with the goal of becoming broadly available later in the fall. The announcement does not give a specific date, define all eligibility requirements or say how many customers will receive access in each phase. It also says the company is working to support third-party offerings serving eligible customers, but gives no timetable or list of those offerings.

The second issue is technical transparency. Anthropic has not described the monitoring models, the precise retention window, the thresholds for generating a flag, the information transmitted to Anthropic during detection or the safeguards against manipulation of the monitoring process. The source also does not say how alerts are prioritized, whether customers can audit the detection system, or how the service handles activity that crosses cloud accounts or organizational boundaries.

The third issue is accountability after a flag. Customer personnel, rather than Anthropic employees, are expected to conduct any human review. That may help organizations meet internal confidentiality requirements, but it also means outcomes will depend on each customer’s staffing, training, escalation rules and willingness to act. Follow-up reporting should examine real-world availability, customer investigations, false positives, missed misuse, cloud costs and whether the architecture delivers meaningful safety gains without undermining the privacy guarantees it is meant to preserve. The announcement leaves those operational questions open while describing the intended responsibilities of Anthropic and its customers. Availability, configuration and investigation practices will determine whether the proposal works consistently across the listed products and cloud environments. Those details will also show how the service’s privacy, security and safety objectives interact in practice.

Related guides & quizzes

AI EthicsAI AgentsAI Models ExplainedFuture of AITest what you know — try a free AI quizLook up an AI term in our glossary
Found this useful?