Anthropic — “Developing Enterprise Frontier Safeguards with our customers” (1 September 2026)
Tag: S-2026-09-01-anthropic-enterprise-frontier-safeguards Type: article (vendor announcement — Anthropic news post, 1 Sep 2026, fetched in full; Help Net Security report, 2 Sep 2026, fetched in full; CNBC and Quartz headlines from search only) Author(s): Anthropic (primary); Anamarija Pogorelec, Help Net Security (independent trade press) Date of source: 2026-09-01 Date ingested: 2026-09-14 Authority weight: medium — primary vendor announcement (architecture, pricing, platform list and quoted parties are reliable as statements of intent; detection-efficacy claims are marketing); Help Net Security adds critical framing (policy reversal; unstated window length; self-selected design group) but no independent testing. Note for readers: this scan is run by an Anthropic model; the item is weighted and labelled exactly as any other vendor announcement. Raw file: /_raw_sources/S-2026-09-01-anthropic-enterprise-frontier-safeguards.md
What it claims
Anthropic announced Enterprise Frontier Safeguards (EFS) on 1 September 2026, described as combining “the privacy of zero data retention (ZDR) with state-of-the-art safeguards for detecting misuse” by “storing data in cloud infrastructure controlled by the customer, not Anthropic”. The context it gives: with Fable 5 (“Mythos-class” models) Anthropic had introduced 30-day data retention because sophisticated misuse “can involve many tasks spread across multiple sessions and accounts” and cannot be detected by analysing each interaction and discarding it; regulated enterprises “found it difficult to use models with data retention”, so EFS was designed with them.
The architecture as described has three opt-in components, each independent of model behaviour, pricing or rate limits: customer-owned storage of the activity data used for monitoring (Amazon S3, Azure Blob Storage or Google Cloud Storage) under the customer’s “own encryption keys, access policies, and audit logging”; customer-managed encryption keys; and fully automated review — Anthropic’s automated systems “analyze a rolling window of traffic for signals of serious misuse, including attempts to develop offensive cyber or biological capabilities and signs of stolen or leaked credentials”, with flags routed “directly to the customer” and “no human review by Anthropic employees … required”. Anthropic does not charge for EFS; the customer pays its cloud provider for storage, reads, writes and egress.
Support is planned across Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, “Google’s Agent Platform” and Microsoft Foundry, with “equivalent controls” via cloud partners. Rollout is phased “starting later this fall”, with eligible customers receiving ZDR on Fable 5 and 5.1 in the interim.
Design collaborators: “more than 100 customers” across FS, healthcare, manufacturing, telecom, law, retail and public sector; the Analysis and Resilience Center for Systemic Risk (ARC) — eight members, whose roster includes the CISOs of Goldman Sachs, Morgan Stanley, Citi, Bank of America and Wells Fargo; Comcast, KPMG, Mastercard, Salesforce and Visa; “a quarter of the Fortune 100, every US global systemically important bank”. Quoted supporters identifiable from the text include Wells Fargo’s CISO, ARC’s CEO, FIS, Stripe, Rogo, Snowflake, Cognition and Factory.
Help Net Security frames the same facts as a reversal: ZDR was “the arrangement most regulated buyers wanted”, Anthropic “dropped it for its most capable tier … and moved to a 30-day retention window”, which “stalled the buyers”; EFS restores customer custody. It notes Anthropic does not argue 30 days is the number the detection “math demands”, does not state how long the rolling monitoring window runs, that the design group is “self-selected … not a survey of the market”, and that for a regulated firm “the alert queue is now yours to staff”. CNBC’s headline (1 Sep) reads “Anthropic changes data retention policy after pushback from customers”.
Notable quotes
- “EFS works by storing data in cloud infrastructure controlled by the customer, not Anthropic.” — Anthropic, para 1
- “who holds the data, who holds the keys, what automated review can and cannot see, and under what conditions a human is ever permitted to look” — Scott DePasquale, ARC (quote block)
- “We keep custody of our data while Anthropic operates the detection.” — Munish Kumar Sharma, Wells Fargo CISO (quote block)
- “Those flags go directly to the customer and their people take it from there – no human review by Anthropic employees is required.” — Anthropic, “On automated and human review”
- “If you run security for a regulated firm, that means the alert queue is now yours to staff.” — Help Net Security, para 3
What’s speculative vs. asserted
Asserted (reliable as vendor statements of design/intent): the three opt-in components; customer-cloud storage options; no Anthropic human review; no charge; platform list; phased rollout timing; ZDR interim; the named design collaborators and quoted parties.
Vendor-asserted / marketing: “state-of-the-art safeguards”; efficacy of cross-session correlation; that the design “held up across industries”.
Independent framing (Help Net Security / CNBC): policy reversal after regulated-customer pushback; the unstated monitoring-window length; the self-selected nature of the design cohort.
Not stated (gaps): rolling-window length; retention period and deletion of logs in the customer cloud; export format or immutability of flags/records; any regulatory standard, certification or auditor involvement; EU/UK data-residency detail; whether “Google’s Agent Platform” means Vertex AI; how “eligible customers” is defined.
Vault inference (not in source): that customer-held usage logs, keys and audit trails bear on DORA ICT third-party and data-location expectations, GDPR controller duties, EU AI Act Art. 12 record-keeping and SS1/23 ongoing-monitoring evidence; that the shift also transfers alert-triage and legal-discovery burden to the bank. No EU/UK regulator or standard is mentioned by either source.
Topics this feeds
- AI Governance Platforms — a frontier-model provider moving usage-evidence custody and misuse-review to the customer, co-designed with US G-SIB CISOs; a new “model-provider assurance layer” claimant alongside the hyperscaler and pure-play loci.
- Anthropic — company page created from this source (page-creation trigger: Anthropic already referenced in 10+ earlier Source pages as harness/model context).
- Operational Resilience and Third Party Risk — vendor-side data-custody and monitoring arrangements as a DORA/third-party-register consideration for frontier-model providers.
Open questions raised
- How long is the rolling monitoring window, and what is the customer’s retention/deletion obligation for the logs once they sit in the bank’s own cloud — do they become records subject to the bank’s own retention schedules and regulatory discovery?
- Are the misuse flags and the underlying activity records exportable in a standard, tamper-evident form that an internal auditor or supervisor could rely on, or are they proprietary telemetry?
- Will EU/UK regulated firms get equivalent controls with EU-region storage, and will any EU/UK bank, insurer or asset manager be named — the announcement’s FS references are all US?
- Does “no human review by Anthropic employees” mean Anthropic retains no ability to inspect flagged content at all, or only that review is not required by default — and how is that verified?
- Will Microsoft, Google and other frontier-model providers match customer-held-evidence arrangements, making it a buying criterion in FS model-provider selection?