Anthropic announced Enterprise Frontier Safeguards (EFS) on September 1, 2026, as an enterprise deployment option intended to combine zero data retention by Anthropic with automated detection of serious AI misuse. Under the design, monitoring data can still be retained in cloud infrastructure controlled by the customer rather than by Anthropic, while automated monitoring sends detected signals to the customer's teams for review.
Anthropic says EFS will roll out to customers in phases, with broader availability targeted for later in fall 2026. Until EFS is ready, eligible customers will receive zero data retention on Fable 5 and Fable 5.1, according to the announcement.
Contents
- What Enterprise Frontier Safeguards changes
- How the monitoring design works
- Why the architecture matters
- Limits and questions before rollout
What Enterprise Frontier Safeguards changes
Zero data retention generally describes a service arrangement in which a model provider does not retain customer interaction data for ordinary service purposes beyond what is needed to deliver the service. It does not necessarily mean that monitoring data is deleted or retained nowhere: under EFS, the data can remain in infrastructure controlled by the customer. The exact meaning of the arrangement depends on the provider's technical and contractual terms.
Anthropic presents EFS as a way to address a tension between privacy and misuse monitoring. Detecting activity that unfolds across several tasks, sessions or accounts may require retaining and correlating signals instead of analysing each request independently and immediately discarding the associated data. At the same time, some organisations may be unwilling or unable to let a model provider retain that monitoring data in the provider's own environment.
Under EFS, customer activity data used for monitoring can be stored in the customer's cloud account. Anthropic names Amazon S3, Azure Blob Storage and Google Cloud Storage as examples. Customers can use their own encryption keys, access policies and audit logging for that stored activity data.
The storage and review controls are opt-in. Anthropic also identifies fully automated review and customer-owned storage as opt-in parts of the EFS design. The company says these controls do not change model behaviour, API pricing or rate limits, and that it will not charge for EFS itself. Customers using their own cloud storage may still incur ordinary provider charges for storage, reads, writes and data egress.
Anthropic says EFS is supported across Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google's Agent Platform and Microsoft Foundry. The announcement does not establish that every safeguard is implemented identically across all of these access paths.
How the monitoring design works
Anthropic describes EFS as an automated safety-monitoring layer rather than a new model or model capability. The monitoring system is intended to analyse a rolling window of traffic. A rolling window evaluates recent activity over a defined period, which can help identify patterns spread across multiple interactions rather than treating every request as an isolated event.
The examples Anthropic provides include attempts to develop offensive cyber or biological capabilities and signs of stolen or leaked credentials. When the system detects a pattern that requires attention, the resulting signal is sent directly to the customer. The customer's own people then decide how to review and respond to the flag; Anthropic says human review by its employees is not required.
This division separates three parts of the deployment:
- the customer uses Anthropic's models through a supported product or cloud platform;
- monitoring activity can be stored in infrastructure controlled by the customer;
- automated detection produces signals for the customer's teams to review.
The announcement does not fully describe the technical data flows between those parts. In particular, it does not specify the precise access boundaries for Anthropic's detection systems, the exact retention period or size of the rolling window, or the format and delivery mechanism for alerts.
Anthropic says it developed EFS with more than 100 customers across financial services, healthcare, manufacturing, telecommunications, law, retail and the public sector, as well as AWS, Google Cloud and Microsoft Azure.
Why the architecture matters
For security and compliance teams, keeping monitoring data in an existing cloud account could allow them to apply familiar key-management, access-control and audit processes. It may also avoid adding a separate storage vendor to the model-provider relationship.
The design is particularly relevant to deployments involving sensitive information or more autonomous software agents. If misuse can span several sessions or accounts, one-request-at-a-time checks may not be sufficient to identify the broader pattern. EFS is intended to preserve that cross-session monitoring capability while giving the customer control over where the associated data is stored and who reviews alerts.
That does not mean customer-controlled storage automatically satisfies regulatory or contractual requirements. Organisations would still need to assess the service against their own legal, security and compliance obligations. Ownership of encryption keys also does not by itself prove that all data is inaccessible to every service operator or that monitoring will detect every harmful use.
Automated detection can produce both true positives and false positives. It can also miss activity. Giving the customer responsibility for reviewing signals means the operational quality of the safeguard will depend partly on how the organisation handles alert access, investigation and escalation.
Limits and questions before rollout
The available evidence is Anthropic's announcement, not an independent security audit, regulator assessment or performance evaluation. It provides no quantitative results for detection accuracy, false-positive rates, false-negative rates or the amount of activity analysed. It therefore does not establish that EFS prevents attacks, detects all serious misuse or meets every regulated organisation's requirements.
Several implementation details remain unresolved:
- the exact retention period and size of the rolling monitoring window;
- which customer accounts and deployments are eligible;
- the complete rollout schedule by product and cloud platform;
- the data Anthropic's systems can access while performing detection;
- the contractual boundaries between Anthropic's automated monitoring and the customer's storage, keys and review processes;
- whether the safeguards operate identically across Anthropic-direct and cloud-partner platforms.
Anthropic has also said it introduced 30-day data retention with Fable 5 and has not trained on enterprise data without explicit permission. Those are company statements about its data practices, rather than independently verified findings supplied with the EFS announcement.
Anthropic is targeting broader availability later in fall 2026. The source does not specify rollout timing, eligibility, pricing or availability in India. The most important evidence to watch will be the technical documentation, service terms, integration details and independent assessments that show how EFS behaves in production—not only how the architecture is described.