Anthropic

Type: company Sector: frontier AI model provider (US; models: Claude Fable / Mythos, Opus, Sonnet, Haiku; agent products: Claude Code, Cowork) — not an AI-governance/assurance tooling vendor; tracked for the model-provider-side assurance arrangements it offers regulated buyers and for its role as the harness/platform that third-party governance tools target First seen: 2026-07-14 (S-2026-07-14-credo-agent-governor-launch — Claude Code as Credo Agent Governor’s first supported harness) Last updated: 2026-09-14

Created 2026-09-14 from S-2026-09-01-anthropic-enterprise-frontier-safeguards (daily AI-governance vendor-intelligence scan; Anthropic announcement and Help Net Security report fetched in full). Page-creation trigger: Anthropic already appeared in three earlier Source pages as the platform other vendors govern (Credo AI, Drata, Obsidian Security). Neutrality note: the scan that created this page is run by an Anthropic model; the page applies the vault’s standard treatment — vendor claims labelled as such, independent corroboration recorded where it exists, no endorsement. Scope note: only AI-governance-relevant items are tracked; model-capability news, incidents and policy positions are out of scope unless a source ties them to assurance tooling.

Snapshot

Anthropic enters this wiki from two directions. As a platform others govern: Credo AI’s Agent Governor research preview (Jul 2026) installs governance-as-code onto the Claude Code harness first [S-2026-07-14-credo-agent-governor-launch]; Drata’s AI Agent Governance (Aug 2026) ships “first and deepest for Anthropic” with OpenAI/Vertex/Bedrock coverage “in active development” [S-2026-08-04-drata-ai-agent-governance]; Obsidian Security extended agent-access governance to Claude Code and Cowork [S-2026-08-04-obsidian-security-series-d]. As a model provider offering its own assurance arrangement: on 1 September 2026 it announced Enterprise Frontier Safeguards (EFS) — misuse-detection activity data for its most capable models stored in the customer’s own cloud (S3 / Azure Blob / GCS) under customer-managed keys and audit logging, automated cross-session misuse monitoring whose flags route to the customer’s own reviewers with no Anthropic human review, all opt-in and unpriced, phased from “later this fall” — co-designed with 100+ customers including the ARC systemic-risk centre whose members include the CISOs of the largest US banks, and quoted by Wells Fargo’s CISO, FIS, Stripe and Rogo [S-2026-09-01-anthropic-enterprise-frontier-safeguards]. Trade press frames EFS as a reversal of the 30-day retention policy introduced with Fable 5 after regulated-customer pushback, and notes the monitoring-window length is unstated [S-2026-09-01-anthropic-enterprise-frontier-safeguards]. For an FS reader the significance is that custody of model-usage evidence and misuse triage moves to the bank — useful for DORA/GDPR/Art. 12-type record control, but also a new operational and discovery burden — and that the named references are all US [inference].

Positions / Claims they advance

  • Detection of sophisticated misuse requires retained, cross-session data — “it is not sufficient to run automated analysis on each interaction separately and then instantaneously discard the data” — which is why 30-day retention was introduced with Fable 5 [S-2026-09-01-anthropic-enterprise-frontier-safeguards]. (Help Net Security notes the announcement does not argue 30 days is the number the detection requires.)
  • Regulated customers should hold the data, the keys and the review — EFS stores monitoring data in the customer’s cloud account under the customer’s encryption keys, access policies and audit logging; flags go to the customer; “no human review by Anthropic employees is required” [S-2026-09-01-anthropic-enterprise-frontier-safeguards].
  • Assurance controls should not change model behaviour, pricing or limits, and should be free — the three EFS components are opt-in and unpriced; cloud storage/egress is billed by the customer’s provider [S-2026-09-01-anthropic-enterprise-frontier-safeguards].
  • Equivalent controls across direct and cloud-partner routes — Claude Code, Claude Enterprise, Claude Platform, Amazon Bedrock, Claude Platform on AWS, “Google’s Agent Platform”, Microsoft Foundry [S-2026-09-01-anthropic-enterprise-frontier-safeguards].
  • Anthropic “has never trained on enterprise data without explicit permission, and never will” [S-2026-09-01-anthropic-enterprise-frontier-safeguards] (vendor statement).

Relationships

  • relates-to → AI Governance Platforms — EFS adds a model-provider assurance layer (customer-held usage evidence, provider-operated detection) to the list of loci claiming agent/model control and evidence [S-2026-09-01-anthropic-enterprise-frontier-safeguards][inference].
  • relates-to → Operational Resilience and Third Party Risk — who holds logs and keys for a frontier-model provider is a DORA ICT third-party register and data-location consideration [inference].
  • relates-to → Credo AI — Credo’s Agent Governor targets the Claude Code harness first [S-2026-07-14-credo-agent-governor-launch].
  • relates-to → Drata — Drata AI Agent Governance ships Anthropic-first [S-2026-08-04-drata-ai-agent-governance].
  • relates-to → Obsidian Security — agent-access governance extended to Claude Code and Cowork [S-2026-08-04-obsidian-security-series-d].
  • relates-to → Mistral — peer frontier-model provider whose EU-sovereignty positioning is the closest analogue to EFS’s data-custody pitch, but from an EU base [S-2026-07-21-microsoft-mistral-sovereign][inference].
  • relates-to → AWS / Google Cloud — cloud partners through which EFS controls are to be delivered “equivalently” [S-2026-09-01-anthropic-enterprise-frontier-safeguards].

Tracked changes

  • 2026-07-14 — Named as the first supported harness (Claude Code) for Credo AI Agent Governor research preview [S-2026-07-14-credo-agent-governor-launch].
  • 2026-08-04 — Drata AI Agent Governance launched “first and deepest for Anthropic”; Obsidian Security extended coverage to Claude Code and Cowork [S-2026-08-04-drata-ai-agent-governance][S-2026-08-04-obsidian-security-series-d].
  • 2026-09-01Enterprise Frontier Safeguards announced: customer-held monitoring data and keys, automated-only misuse review, opt-in, unpriced, phased rollout from autumn 2026; designed with ARC (US G-SIB CISOs) and 100+ customers; ZDR granted on Fable 5/5.1 in the interim; trade press frames as a retention-policy reversal [S-2026-09-01-anthropic-enterprise-frontier-safeguards].

Open Questions

  • Rolling-window length, customer-side retention/deletion obligations, and export/immutability of flags and records are unstated — can EFS logs serve as SS1/23 / EU AI Act Art. 12 evidence, or are they security telemetry only? [S-2026-09-01-anthropic-enterprise-frontier-safeguards][inference]
  • Will EU/UK regulated firms get EU-region equivalents and will any EU/UK FS institution be named? All FS references are US [S-2026-09-01-anthropic-enterprise-frontier-safeguards].
  • Does “no human review required” mean no provider access at all, and how is that verifiable by the customer’s second line or an external auditor? Not stated [S-2026-09-01-anthropic-enterprise-frontier-safeguards].
  • Will Microsoft, Google, OpenAI and Mistral match customer-held-evidence arrangements, making it a selection criterion in FS model-provider due diligence? [inference]
  • Third-party governance tools (Credo, Drata, Obsidian) govern the Claude harness from outside while EFS governs usage data from the provider side — who reconciles the two evidence streams in a bank’s control framework? [inference]

Sources