TL;DR
Anthropic announced Enterprise Frontier Safeguards (EFS) on 1 September 2026 after consulting 100+ customers, combining zero data retention with misuse detection rather than making customers choose between them.
Activity data used for monitoring "can be stored in the customer's own cloud account", under "their own encryption keys, access policies, and audit logging".
No Anthropic employee reads it. EFS "has automated safety monitoring, no Anthropic human review required", and "those flags go directly to the customer and their people take it from there".
Anthropic doesn't charge for Enterprise Frontier Safeguards.
Developed with 100+ customers consulted. Broad availability targeted for later this fall, with zero data retention offered on Fable 5 and 5.1 for eligible customers in the interim.
What was the trade-off before this?
Pick one: keep your data out of the vendor's systems, or get safety monitoring on how your people use the model. Not both.
That was a real constraint for regulated buyers, and it produced a familiar deadlock. A bank or a health system says its prompts cannot leave its own boundary. The vendor says misuse detection requires seeing the traffic. Legal and security each hold a defensible position, procurement stalls, and the deployment shrinks to the use cases nobody worried about.
EFS is an attempt to dissolve that rather than split it. The monitoring still happens. The data it runs on sits in the customer's cloud account, encrypted with the customer's keys, and the alerts go to the customer's staff.
Where does the data actually live?
In infrastructure the customer already controls. Anthropic states that customers "have the ability to store data on their existing cloud infrastructure", and that activity data used for monitoring "can be stored in the customer's own cloud account" under "their own encryption keys, access policies, and audit logging".
3 separate controls, and the third is the one security teams will care about most. Access policies decide who can reach it. Encryption keys decide whether anyone else can read it. Audit logging decides whether you can prove either. A control you cannot evidence is not a control you can take to an auditor, and this is the part vendors most often leave out.
Who reads the alerts?
Nobody at Anthropic, which is the structurally interesting claim.
EFS "has automated safety monitoring, no Anthropic human review required", and "those flags go directly to the customer and their people take it from there". That inverts the normal arrangement, where a vendor's trust and safety team is the first reader of anything flagged in your account. It is the same direction of travel as Microsoft binding agents to the tenant's own roles and audit trails rather than to a vendor console.
It also moves work. If the flags arrive at your security team, your security team needs a runbook for them. A flag with no owner is a ticket that ages. Any organisation adopting this should decide, before switching it on, who triages an alert at 2am and what their options are. The capability removes a privacy objection and creates a staffing question in the same move, and only one of those is Anthropic's to answer.
What is it going to cost?
Nothing. "Anthropic doesn't charge for Enterprise Frontier Safeguards."
That is worth stating plainly because the alternative shape is so common. Safety and compliance features are frequently the upsell that moves a customer from a standard tier to an enterprise one, and pricing them separately is how a vendor monetises exactly the buyer who has the least choice. Not charging removes that, and it also removes a negotiation from every renewal.
How does it compare with what the ERP vendors are shipping?
Different layer, same question, and reading them together is more useful than reading either alone. This week we compared how 4 ERP vendors govern agents and found each had picked a different control point.
Controls what. Data sits where. Who sees the alert
Anthropic EFS. Misuse of the model. The customer's own cloud. The customer's staff
Microsoft Agent Governance Toolkit. Whether a tool call proceeds. The tenant, same audit trails as users. The tenant's admins
SAP Joule Studio runtime. What a sandboxed agent can reach. SAP's runtime boundary. Built-in observability
Workday Agent System of Record. An agent's role and data access. The Workday tenant. The workforce owner
The pattern across all 4 vendors: the alert is moving toward the customer, and so is the data. Two years ago the default was the opposite in every one of these products. That is a genuine industry shift and it is happening at the model layer and the application layer at the same time.
What should an enterprise buyer actually check?
Confirm which platforms are covered for you. Anthropic names 7 platforms: Claude Code, Claude Enterprise, Claude Platform, Amazon Bedrock, AWS, Google Agent Platform and Microsoft Foundry. Multi-cloud shops should check each path they use, not just the primary one.
Assign the flag owner before you enable it. The design sends alerts to your people. Decide which people, with which runbook, and what authority they have to act.
Ask what happens between now and general availability. Broad availability is targeted for later this fall, with zero data retention available on Fable 5 and 5.1 for eligible customers in the interim. Those are two different postures and a deployment plan should say which one it assumes.
Check the retention number against your own policy. Anthropic cites a 30-day data retention policy from Fable 5 onwards. If your obligations require shorter, that is a conversation to have before the pilot rather than after.
FAQ
Does zero data retention mean no monitoring at all?
No. That is the point of the announcement. Monitoring runs on activity data held in the customer's own cloud account rather than in Anthropic's systems.
Will Anthropic staff see flagged conversations?
Anthropic states EFS requires no Anthropic human review and that flags go directly to the customer.
Is it an extra cost?
Anthropic states it does not charge for Enterprise Frontier Safeguards.
Is it available now?
Broad availability is targeted for later this fall, with an interim zero-data-retention offering on Fable 5 and 5.1 for eligible customers.
Does this apply if we use Claude through a cloud marketplace?
Anthropic names Amazon Bedrock, AWS, Google Agent Platform and Microsoft Foundry among supported platforms. Confirm your specific path.
The last mile
Anthropic automates the detection and hands you the flag. That is the right division: the vendor is better placed to spot the pattern, and you are the only one who knows whether it matters in your business.
Which is the same shape the ERP story keeps arriving at. A system can record that something happened and even that it looked unusual. Deciding what the optimal response is, for this business, on this account, today, is the part that does not automate. The ERP is the system of record. Turning it into a system of intelligence is the layer Cognilium works in, and the model vendors are now converging on the same boundary from the other side.
Share this article
Weekly AI engineering brief
One email a week. New model releases, agent patterns, and lessons from production systems we ship.
No spam, no client data sales. Unsubscribe any time.

Ali Ahmed
AI Solutions Engineer, Cognilium AI
Ali Ahmed
AI Solutions Engineer, Cognilium AI
Ali Ahmed is an AI Solutions Engineer at Cognilium AI.
