Anthropic Introduces Enterprise Frontier Safeguards (EFS): Zero-Data-Retention Privacy Plus Cross-Session Misuse Detection Anthropic introduced Enterprise Frontier Safeguards (EFS), an architecture that gives regulated enterprise customers zero-data-retention privacy while enabling cross-session misuse detection by storing monitoring data in customer-controlled cloud infrastructure. EFS, developed with more than 100 customers including financial, healthcare, and public sector organizations, along with AWS, Google Cloud, and Microsoft Azure, will roll out in phases with broad availability expected later this fall. The design moves storage and human review to the customer while keeping automated detection with Anthropic, addressing the tension between privacy and security for regulated industries. Enterprise AI buyers have been stuck between two things they both need. Regulated teams need a zero data retention ZDR guarantee, so no prompt or agent transcript sits on a vendor’s servers. Security teams need misuse detection, which historically required the vendor to hold that same data long enough to correlate it. This week, Anthropic announced Enterprise Frontier Safeguards https://www.anthropic.com/news/enterprise-frontier-safeguards EFS , an architecture that tries to give both. EFS stores monitoring data in cloud infrastructure the customer controls, not Anthropic’s. Detection stays with Anthropic. Custody, keys, and human review stay with the customer. Is it deployable today? Not yet. EFS rolls out in phases with the goal of broad availability later this fall, and access is request-based https://claude.com/form/enterprise-frontier-safeguards . Until it ships, eligible customers can run Claude Fable 5 and Fable 5.1 under ZDR. The technical problem EFS is solving Anthropic’s stated reason for retention is detection quality, not training data. The company introduced 30-day data retention starting with Fable 5, and says plainly that it has never trained on enterprise data without explicit permission. The argument for holding data is narrow and worth restating. The most sophisticated misuse Anthropic has observed spreads across many tasks, sessions, and accounts, including cases involving stolen or misappropriated enterprise credentials. Running an automated classifier on each interaction and instantly discarding it cannot catch that shape of attack. Correlation needs a window. Anthropic has documented https://www.anthropic.com/news/disrupting-AI-espionage this pattern in its own espionage disruption work. Regulated customers understood the security logic and still could not adopt it. So Anthropic moved the window rather than removing it. What EFS actually changes Anthropic built EFS with more than 100 customers across financial services, healthcare, manufacturing, telecom, law, retail, and the public sector, together with AWS, Google Cloud, and Microsoft Azure. Contributors included the Analysis and Resilience Center for Systemic Risk, whose membership includes CISOs at Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo, plus teams at Comcast, KPMG, Mastercard, Salesforce, and Visa. Anthropic says the design conversations covered a quarter of the Fortune 100 and every US global systemically important bank. Three design decisions came out of that process : Storage moves to the customer : Activity data used for monitoring can live in the customer’s own cloud account, under their encryption keys, access policies, and audit logging. Enterprises told Anthropic that onboarding another trusted data vendor triggers customer notifications and contract updates, so the architecture avoids creating one. Review moves to the customer : When monitoring detects a pattern worth attention, the signal goes directly to the customer. Anthropic’s position is that automated review handles the scan; a person still adds value confirming real misuse and clearing false positives, and in regulated environments that person must be cleared for privileged legal material, non-public information, or drug-safety reports. EFS runs automated safety monitoring with no Anthropic human review required. Detection stays with Anthropic : Automated systems analyze a rolling window of traffic for serious misuse, specifically attempts to build offensive cyber or biological capability and signs of stolen or leaked credentials. Where this sits in the model roadmap EFS is one of three enterprise concessions shipped alongside Claude Fable 5.1 and Mythos 5.1 https://www.anthropic.com/claude-fable-and-mythos-5-1 . The other two are pricing and precision. Fable 5.1 cut cache reads by 75% to $0.25 per million tokens, which works out to roughly 25% lower cost on typical workloads and up to about 45% on highly agentic ones. Its cybersecurity safeguards now produce around 60% fewer interventions per Claude Code session than Fable 5’s, partly because Fable 5.1 is permitted to identify software vulnerabilities without developing exploits for them. Key Takeaways - EFS pairs ZDR-equivalent privacy with automated detection that spans sessions and accounts. - Activity data lands in the customer’s own S3, Azure Blob, or Google Cloud Storage bucket. - Flags route to the customer; no Anthropic human review is required. - Customer-owned storage, customer-managed keys, and automated review are each opt-in. - Anthropic charges nothing for EFS; the customer’s cloud provider bills storage and egress. Check out Technical details here . Also, feel free to follow us on and don’t forget to join our Twitter https://x.com/intent/follow?screen name=marktechpost and Subscribe to 150k+ML SubReddit https://www.reddit.com/r/machinelearningnews/ . Wait are you on telegram? our Newsletter https://magic.beehiiv.com/v1/f5e63dd4-5653-4f09-83e2-321a8b1ba526?email={{email}} now you can join us on telegram as well. https://t.me/machinelearningresearchnews Need to partner with us for promoting your GitHub Repo OR Hugging Face Page OR Product Release OR Webinar etc.? Connect with us https://forms.gle/wbash1wF6efRj8G58 Michal Sutter is a data science professional with a Master of Science in Data Science from the University of Padova. With a solid foundation in statistical analysis, machine learning, and data engineering, Michal excels at transforming complex datasets into actionable insights.