Productspublished

Anthropic’s EFS Puts Misuse-Monitoring Data in Customer Clouds, Not Its Own

The planned controls seek to preserve the longer-term activity patterns needed for safety monitoring while giving enterprises custody of the underlying records and their review process.

By 3 min read
Anthropic’s EFS Puts Misuse-Monitoring Data in Customer Clouds, Not Its Own
Anthropic’s EFS Puts Misuse-Monitoring Data in Customer Clouds, Not Its Own

Listen to this story

The audio brief

About 1:35
0:001:35
Read transcript
Anthropic plans to put its most sensitive AI misuse-monitoring data in the customer’s own cloud account, rather than storing it itself. The system, called Enterprise Frontier Safeguards, or EFS, is designed to preserve zero data retention while still spotting activity that may only become suspicious across multiple sessions or accounts. That matters because Anthropic says reviewing each interaction in isolation, then deleting it immediately, can miss longer-term patterns. EFS instead monitors a rolling window of traffic for signals such as attempts to develop offensive cyber or biological capabilities, and exposed or stolen credentials. Automated flags go directly to the customer’s staff. Anthropic says its employees do not need to review the material. Customers can store the activity in Amazon S3, Azure Blob Storage, or Google Cloud Storage, using their own encryption keys, access policies, and audit logs. Storage, key management, and automated review are separate opt-in controls. Anthropic will not charge for EFS, although cloud providers may charge for storage, data operations, and egress. The system is planned for Claude Code, Claude Enterprise, Claude Platform, Amazon Bedrock, Google’s Agent Platform, and Microsoft Foundry. Phased deployment is planned for later this fall, with broad availability targeted for fall 2026. Until then, eligible customers will receive zero data retention on Fable 5 and Fable 5.1. The key test is whether customer teams can turn automated warnings into dependable interventions.

Story brief

3 key points

Anthropic plans Enterprise Frontier Safeguards (EFS), an opt-in monitoring system intended to preserve zero data retention while still detecting misuse patterns across sessions. Customers would store activity in their own S3, Azure Blob, or Google Cloud accounts, using their keys and access controls; automated flags would go to customer staff, with no Anthropic employee review required. Phased rollout is planned for...

  1. 01

    EFS monitors a rolling traffic window for signals including offensive cyber or biological activity and exposed credentials.

  2. 02

    Storage, encryption-key control, and automated review are separate opt-in controls; EFS itself carries no Anthropic fee.

  3. 03

    Cloud providers may still charge for storage, data operations, and egress.

Anthropic has introduced Enterprise Frontier Safeguards, a planned security layer that pairs zero data retention with automated checks for serious AI misuse. Activity data stays in cloud infrastructure controlled by the customer, while detected signals go to the customer’s personnel rather than requiring Anthropic employee review.

The rollout will begin in phases later this fall, with broad availability targeted for later in fall 2026. Eligible customers will receive zero data retention on Fable 5 and Fable 5.1 until EFS is ready, Anthropic says.

A different answer to the retention problem

Anthropic introduced 30-day data retention with Fable 5 because it says sophisticated misuse can be spread across sessions and accounts. Reviewing each interaction in isolation and discarding it immediately cannot expose that kind of pattern, according to the company. Anthropic says the retention policy was for safety monitoring, not training on enterprise data.

EFS keeps the monitoring context but shifts control of its storage. Customers can keep activity data in their own Amazon S3, Azure Blob Storage, or Google Cloud Storage accounts, under their own encryption keys, access policies, and audit logging.

The provider detects; the customer decides

The automated system examines a rolling window of traffic for signals such as efforts to develop offensive cyber or biological capabilities, and signs of stolen or leaked credentials. Flags are sent directly to the customer, whose staff can review the material; Anthropic says no human review by its employees is required.

How the controls will be sold and deployed

  • Customer-owned storage, customer-managed encryption keys, and fully automated review are separate opt-in controls.
  • Anthropic says EFS does not change model behavior, API pricing, or rate limits, and that it will not charge for EFS itself. Cloud providers may charge for storage, reads, writes, and data egress.
  • Anthropic plans support for Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google’s Agent Platform, and Microsoft Foundry.

Anthropic says it developed EFS with more than 100 customers across industries including financial services, healthcare, manufacturing, telecom, law, retail, and the public sector. The practical question is whether customer teams can convert automated flags into reliable action as EFS reaches those environments.

Editorial analysis

Our Read

Our read: EFS turns a policy problem into an infrastructure design choice. Enterprises that need to keep sensitive records under their own keys and access rules can still use automated pattern detection, rather than choosing between strict data custody and cross-session monitoring. That is a sharper proposition than a promise not to train on data. The next test is operational: Anthropic plans a phased rollout across its products and three cloud ecosystems, while customers themselves will need to assess and respond to the alerts the system produces.

Sources

  1. anthropic.comDeveloping Enterprise Frontier Safeguards with our customers