Anthropic has announced Enterprise Frontier Safeguards (EFS), a new offering for enterprise customers[1]. It is designed to preserve the privacy of zero data retention (ZDR) while still running misuse detection. The key is where the data lives: the activity data used for monitoring sits in cloud infrastructure the customer controls, not Anthropic's. The rollout begins in phases later this fall.
The wall that 30-day data retention ran into
The starting point is the 30-day data retention Anthropic introduced with Fable 5[1]. The purpose was detection, not training data. The company reiterates that it has never trained on enterprise data without explicit permission.
Why retain anything at all? By Anthropic's account, sophisticated misuse does not fit inside a single exchange; it spreads across multiple sessions and accounts. Analyzing each interaction on its own and discarding the data immediately makes correlation over time impossible. The company says it has observed attempts ranging from ordinary abuse such as fraud to sophisticated cyberattacks in which agents autonomously engage in destructive behavior[1].
For customers in regulated industries, however, a model that leaves logs outside their walls was hard to adopt. The shift has been reported as a response to pushback from customers[2]. EFS is Anthropic's answer to that bind.
Data moves to the customer's cloud, detection stays with Anthropic
Under EFS, activity data used for monitoring can be stored in the customer's own cloud account. Amazon S3, Azure Blob Storage, and Google Cloud Storage are supported, with encryption keys, access policies, and audit logging all under the customer's control[1].
Adding one more trusted data vendor is heavy work in itself. Enterprises have to notify their own customers about the vendor, update contracts, and satisfy internal storage and audit requirements. Keeping the data where it already sits is a design choice that removes that work entirely.
Coverage includes Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google's Agent Platform, and Microsoft Foundry. Customers working through AWS, Google Cloud, or Microsoft Azure get controls equivalent to those available when accessing Claude directly from Anthropic[1].
Customer-owned storage, customer-managed encryption keys, and fully automated review are each opt-in, so an organization enables only what it needs. Enabling them changes neither model behavior, API pricing, nor rate limits[1].
No Anthropic employee reads the logs
The second axis is who reviews a flag.
Safety monitoring under EFS is automated, with no human review by Anthropic employees. Automated systems analyze a rolling window of traffic for signals of serious misuse, including attempts to develop offensive cyber or biological capabilities and signs of stolen or leaked credentials. Flags go directly to the customer, and the customer's own people take it from there[1].
This matters because regulated industries define precisely who may see what. Privileged legal material, non-public information, and drug-safety reports are categories where an outsider looking at the content is itself the problem. If a company already has trained and cleared staff, routing review to them is the faster path.
Designed with more than 100 customers
EFS was built in collaboration with more than 100 customers, spanning financial services, healthcare, manufacturing, telecom, law, retail, and the public sector. Anthropic says the conversations covered a quarter of the Fortune 100 and every US global systemically important bank[1].
One of the groups involved was the Analysis and Resilience Center for Systemic Risk (ARC), whose members include the chief information security officers of Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo. Anthropic also worked with leaders at Comcast, KPMG, Mastercard, Salesforce, and Visa[1].
Listing customer names is standard practice in an announcement, but here it carries some weight. Separating who holds the data from who holds the keys, and defining what automated review can and cannot see, is work that does not take shape without people who know what regulators demand. How well the result meets those standards will be judged once the rollout begins.
OpenAI is answering the same question differently
Competitors are working on the same problem in parallel. OpenAI has said it will continue to offer zero data retention for frontier models and is previewing a system called Private Safety Processing[3]. It detects patterns across related interactions while giving OpenAI staff no access to the underlying content, surfacing only a limited signal indicating the category of risk.
Anthropic keeps the data on the customer's side and runs detection from outside it; OpenAI retains nothing and tries to make detection work cryptographically. The directions differ, but the goal is the same: not leaving regulated industries outside the reach of frontier models. The competitive axis in enterprise AI is widening from how capable a model is to how easily it can be operated.
Summary
Enterprise Frontier Safeguards is a structural answer to the tension between retaining data for monitoring and preserving customer data sovereignty. Data stays in the customer's cloud, the customer holds the keys, and only the results of automated detection travel from Anthropic to the customer. Anthropic does not charge for EFS itself; customers who elect cloud storage are billed by their cloud provider for storage as well as reads, writes, and data egress[1]. Whether frontier models can be brought into production without adding contractual and audit overhead is what this fall's rollout will test.
Source: https://www.anthropic.com/news/enterprise-frontier-safeguards
Source: https://www.cnbc.com/2026/09/01/anthropic-data-retention.html
Source: https://openai.com/index/offering-zero-data-retention-for-frontier-models/
