Anthropic just solved one of the most stubborn blockers to enterprise AI adoption — and it took co-designing a solution with over 100 companies, including the CISOs of the largest US banks, to get there. The company is announcing Enterprise Frontier Safeguards (EFS), a framework that gives regulated enterprises the ability to run Anthropic’s most capable models while keeping their data inside infrastructure they already control. No more choosing between frontier intelligence and data sovereignty. That tradeoff is, at least architecturally, gone.
Why This Problem Existed in the First Place
When Anthropic introduced 30-day data retention with Claude Fable 5, the logic was sound: sophisticated cyberattacks don’t reveal themselves in a single session. Detecting credential theft, coordinated abuse across accounts, or an agent quietly doing something destructive requires looking at patterns across time. You can’t do that if you’re deleting data the moment a conversation ends.
But here’s the tension that immediately surfaced: the enterprises best positioned to deploy frontier AI — banks, hospitals, law firms, telecoms — are also the ones most constrained by data regulations. A Goldman Sachs or a Wells Fargo can’t simply add Anthropic as a “trusted data vendor” without triggering a cascade of compliance work: customer notifications, contract amendments, internal audits, and sign-off from regulators who already have strong opinions about where sensitive data lives.
So you had capable models on one side, compliance walls on the other, and a growing pile of enterprise deployments stuck in pilot purgatory. Enterprise Frontier Safeguards is Anthropic’s answer to that stalemate.
It’s also worth understanding what EFS is not fixing: Anthropic has never trained on enterprise customer data without explicit permission. That wasn’t the problem. The problem was custody — who holds the logs, under whose keys, reviewable by whom.
How Enterprise Frontier Safeguards Actually Works
The core architecture is a clean split: Anthropic operates the detection logic, customers own the data environment. Activity data used for safety monitoring gets written to the customer’s own cloud storage — Amazon S3, Azure Blob Storage, or Google Cloud Storage — under their own encryption keys and access policies. Anthropic’s automated systems analyze traffic patterns without the data ever leaving the customer’s account.
When the automated monitoring detects something concerning — attempts to synthesize offensive cyber capabilities, signs of stolen credentials being used, patterns of coordinated misuse across sessions — those flags go directly to the customer’s security team. Anthropic employees don’t review flagged content. The customer’s own cleared, trained staff handles it from there.
Three controls are available, all opt-in:
- Customer-owned storage: Activity logs live in the customer’s cloud account, not Anthropic’s infrastructure. Cloud provider storage costs apply, billed through the customer’s existing AWS, Azure, or GCP relationship.
- Customer-Managed Encryption Keys (CMEK): Customers hold the keys. Anthropic can’t decrypt the data even in theory.
- Fully automated review: No Anthropic human ever looks at flagged content. The automated system surfaces signals; the customer’s team decides what to do next.
None of these controls change model behavior, API pricing, or rate limits. Anthropic doesn’t charge for EFS itself — just the underlying compute you were already paying for.
EFS will be supported across Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google’s Agent Platform, and Microsoft Foundry. Rollout begins later this fall, with eligible customers receiving zero data retention on Fable 5 and Fable 5.1 in the interim.
Who Built This and Why That Matters
The list of organizations Anthropic consulted reads like a who’s-who of institutional caution: Goldman Sachs, Morgan Stanley, Citi, Bank of America, Wells Fargo, Comcast, KPMG, Mastercard, Salesforce, Visa, Stripe, Snowflake, and Cognition, among others. The conversations covered a quarter of the Fortune 100 and every US global systemically important bank.
That’s not a typical customer advisory panel. That’s Anthropic essentially saying: we can’t design this unilaterally. The Analysis and Resilience Center for Systemic Risk (ARC), whose members include the chief information security officers of the largest US banks, had eight members directly involved in defining what it would take to run frontier models inside a systemically important bank.
The result shows. Munish Kumar Sharma, CISO at Wells Fargo, put it bluntly: “The logs are under our control; they don’t go anywhere else unless we want them to.” That’s not marketing language — that’s a structural guarantee built into the architecture, not a policy commitment that could change with a terms-of-service update.
Noopur Davis, EVP and Chief Information Security and Product Privacy Officer at Comcast, noted something telling: “As a company that runs critical infrastructure, the capability of models is important. Just as important are solutions that allow us to keep our data in our own account.” In other words, model quality is table stakes now. What closes the deal is trust architecture.
What This Means Competitively
This is where things get interesting for the broader market. OpenAI and Google have enterprise offerings, but neither has announced an equivalent architecture where monitoring data physically never leaves the customer’s cloud account. OpenAI’s enterprise agreements offer data handling commitments, but the structural control EFS provides — customer-held keys, customer-owned storage, no human review by the provider — represents a meaningfully different posture.
For context, OpenAI’s Astra recently hit a notable cybersecurity threshold, showing the arms race on AI security capabilities is accelerating across the board. But capability is different from custody. EFS is squarely about the latter.
Google’s Agent Platform is actually listed as an EFS-supported surface, which is notable — Anthropic isn’t trying to win enterprise deals by keeping customers away from cloud providers. It’s positioning Claude as the model layer that works within whatever infrastructure the customer already trusts. That’s a smart move given how deeply AWS, Azure, and GCP are embedded in enterprise security architectures.
There’s also a timing element here. Fable 5.1 is Anthropic’s current frontier offering, described as a “Mythos-class” model representing a significant jump in both intelligence and agentic capability. More capable agents operating autonomously across longer time horizons create more surface area for both misuse and accidental misbehavior. EFS is, in part, Anthropic’s acknowledgment that the security requirements for a truly agentic AI are categorically different from what was needed for a chat assistant.
This connects to a broader trend we’ve been tracking: as AI models take on more autonomous, multi-step work in production environments, the security and compliance conversation shifts from “what can the model do” to “who controls what the model touches.” Multi-agent frameworks are shipping across the industry, and the governance layer hasn’t kept pace — until moves like this one.
What This Means for Different Enterprise Buyers
The practical impact varies significantly by industry:
- Financial services: Every US global systemically important bank was part of the design process. EFS is purpose-built for non-public information handling rules, privileged communications, and the regulatory scrutiny that comes with being systemically important. This likely unblocks deployments that have been stalled for over a year.
- Healthcare: Patient data under HIPAA has always been a friction point for AI adoption. Customer-managed encryption keys and no-human-review-by-provider directly addresses the most common compliance objections in this space.
- Legal: Attorney-client privilege is absolute. The fact that EFS eliminates Anthropic employee access to flagged content removes a structural concern that no policy commitment could fully address.
- Developers and platform builders: Companies like Cognition (autonomous engineering agents) and Factory (code-focused AI) are explicitly listed as design partners. For platforms handling customer code and IP, EFS means they can offer frontier model access without asking customers to accept their data leaving a controlled environment.
- Mid-market enterprises: The opt-in structure matters here. Organizations that don’t need all three controls don’t have to implement them. A company without strict regulatory obligations can use EFS selectively — just CMEK, for instance — without a full compliance overhaul.
Frequently Asked Questions
What exactly is Enterprise Frontier Safeguards?
EFS is a security architecture for Anthropic’s enterprise customers that combines automated safety monitoring with customer-controlled data storage. Instead of activity logs going to Anthropic’s infrastructure, they’re written to the customer’s own cloud storage (S3, Azure Blob, or GCS) under the customer’s encryption keys. Anthropic runs detection logic against that data but employees never review flagged content directly.
Does EFS cost extra?
Anthropic doesn’t charge for EFS itself. If you opt into customer-owned storage, you’ll pay your cloud provider’s standard storage and data transfer rates — the same as any other resource in your AWS, Azure, or GCP account. API pricing and rate limits are unchanged.
When is EFS available and who qualifies?
Rollout begins later in fall 2026, in phases. Enterprises can request access via Anthropic’s form. In the meantime, eligible customers get zero data retention on Fable 5 and Fable 5.1 as a bridge. It’s supported on Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Google’s Agent Platform, and Microsoft Foundry.
How does this compare to what OpenAI or Google offer enterprises?
Both competitors offer enterprise data handling commitments through policy and contractual agreements. EFS goes further structurally: the data physically lives in infrastructure the customer controls, under keys they hold, with no pathway for Anthropic employees to access flagged content. It’s the difference between a promise and an architecture. Whether competitors respond with equivalent structural controls is the question to watch over the next few months.
Anthropic has effectively reframed the enterprise AI conversation: the question is no longer whether Claude is capable enough, but whether the infrastructure around it is trustworthy enough. Given that Anthropic has consistently invested in trust-building measures that go beyond what competitors require, EFS feels like a natural extension of that posture — just applied to enterprise security rather than model alignment. If the rollout executes cleanly and the customer list expands beyond the design partners, this could set the bar that every serious enterprise AI provider has to clear.