Anthropic Releases Enterprise Frontier Safeguards to Route Customer Logs into Customer-Owned Cloud Storage
Regulated enterprises have faced a specific conflict with frontier AI: effective safety monitoring requires storing logs across sessions, but financial, healthcare, and government procurement rules restrict which parties may hold that data. Anthropic's new Enterprise Frontier Safeguards (EFS), announced September 1, 2026, addresses that conflict by separating data custody from detection capability.
What EFS does
Under EFS, operator conversation logs route directly to the customer's own Amazon S3, Azure Blob Storage, or Google Cloud Storage bucket, encrypted under keys the customer controls, per Anthropic's announcement. Anthropic's automated detection pipeline reads those logs for patterns signaling misuse, including attempts to develop offensive cyber or biological capabilities and signs of stolen or leaked credentials. Flagged patterns go to the customer's own security team. No Anthropic employee reads the underlying content.
Three controls are independently opt-in: customer-owned storage, customer-managed encryption keys, and fully automated review. None change model behavior, API pricing, or rate limits. Anthropic does not charge for EFS itself. Customers who elect to store logs in their own cloud account pay their cloud provider's standard storage and egress rates. EFS will be available on Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google's Agent Platform, and Microsoft Foundry.
Why Anthropic built it this way
When Anthropic introduced 30-day data retention with Fable 5, the rationale was safety detection. Sophisticated misuse, including autonomous cyberattacks distributed across many sessions and accounts, cannot be caught by analyzing each interaction in isolation. Correlation across time and accounts requires logs to persist for a meaningful window.
That requirement created a procurement barrier. Regulated institutions, particularly systemically important banks and covered healthcare providers, cannot easily designate a new third-party data vendor without notifying customers and updating contracts. EFS removes Anthropic from the custody chain while keeping the detection window intact. Logs stay in the customer's environment under the customer's keys. Anthropic's detection system scans them in place, reading only the signals that cross a policy threshold.
Eligible customers receive zero data retention on Fable 5 and Fable 5.1 as a bridge arrangement until EFS reaches their deployment in the phased fall 2026 rollout.
Named design partners
Anthropic says EFS was developed with more than 100 enterprise customers across financial services, healthcare, manufacturing, telecom, law, retail, and the public sector, per Anthropic. The collaboration covered a quarter of the Fortune 100 and every US global systemically important bank.
The Analysis and Resilience Center for Systemic Risk (ARC) contributed architecture requirements. ARC members include chief information security officers at Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo. Other named organizations that shaped the design include Comcast, KPMG, Mastercard, Salesforce, Visa, Stripe, Snowflake, and Coinbase.
Wells Fargo CISO Munish Kumar Sharma said EFS keeps Wells Fargo logs "in a Wells-managed environment under Wells-managed keys" while Anthropic operates the detection side. Stripe Head of Security Matthew Kemelhar stated that EFS will allow Stripe to retain conversation logs in "Stripe's AWS environment, with access and review governed by Stripe's security controls." ARC CEO Scott DePasquale noted that ARC members helped define "who holds the data, who holds the keys, what automated review can and cannot see."
What to watch
EFS is in phased rollout with broad availability targeted for fall 2026. The architecture question competitors now face is whether to release comparable customer-key logging systems. If regulated-industry customers begin publishing procurement decisions that cite EFS as a compliance enabler, that would signal the architecture works outside the design-partner cohort.
Sources
- Anthropic: Developing Enterprise Frontier Safeguards with our customers: primary announcement, September 1, 2026
- SecurityWeek: Anthropic Enterprise Frontier Safeguards: tier-2 coverage
