Policy

Anthropic Lets Customers Hold Frontier AI Monitoring Data in Their Own Clouds

Anthropic's Enterprise Frontier Safeguards pairs automated misuse detection with customer-owned storage, encryption keys and review. The architecture is meant to resolve the conflict between zero data retention and monitoring advanced models for sustained abuse.

By Michael C ·

Anthropic Lets Customers Hold Frontier AI Monitoring Data in Their Own Clouds

Anthropic is preparing to let eligible enterprises use its most capable models while keeping monitoring data inside cloud accounts the customers control. Enterprise Frontier Safeguards, or EFS, combines automated detection of serious misuse with customer-owned storage, encryption keys and human review. The product will roll out in phases beginning later this fall. It is an attempt to solve a conflict created by frontier models: detecting sustained abuse requires memory across sessions, while regulated organizations often cannot allow a model provider to retain their sensitive conversations.

Anthropic developed the system with more than 100 customers across finance, healthcare, manufacturing, telecommunications, law, retail and the public sector, as well as Amazon Web Services, Google Cloud and Microsoft Azure. The company says its consultations covered a quarter of the Fortune 100 and every U.S. global systemically important bank. That participation does not independently validate the product, but it shows how strongly data custody has constrained frontier-model adoption.

The architecture separates detection from custody. Activity data can be stored in Amazon S3, Azure Blob Storage or Google Cloud Storage under the customer's access policies, audit logs and encryption keys. Anthropic's automated systems analyze a rolling window for patterns such as offensive cyber or biological work and signs of stolen credentials. Flags go to the customer's security team. Anthropic says no review by its employees is required.

Enterprise Frontier Safeguards keeps activity data under customer-controlled storage, encryption and access policies while automated systems look for serious misuse.
Enterprise Frontier Safeguards keeps activity data under customer-controlled storage, encryption and access policies while automated systems look for serious misuse.

Zero Retention Was Not Enough for Frontier Monitoring

Zero data retention is attractive because it minimizes what a provider can expose, inspect or reuse. It is weaker at detecting a campaign distributed across accounts and time. A single request may appear benign while hundreds form an exploit chain or signal stolen credentials. Anthropic introduced 30-day retention with Fable 5 for that reason, saying the data was used for safety rather than training. Regulated customers still faced contractual and legal barriers.

EFS changes where the record lives rather than pretending the record is unnecessary. That is a more credible response to the underlying problem. It also transfers responsibility. Customers must configure storage, keys, access and retention correctly. They must fund the associated reads, writes and egress. Most importantly, they must staff the team that receives a high-severity flag and decides whether it represents misuse, a compromised identity or legitimate sensitive work.

Anthropic says customer-owned storage, customer-managed encryption and fully automated review are opt-in. The controls do not change model pricing, rate limits or behavior, and Anthropic does not charge separately for EFS. Optionality helps companies fit the product to their obligations. It can also produce inconsistent security if an organization enables the model but postpones the monitoring components that make access acceptable.

The product will work across Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Google's Agent Platform and Microsoft Foundry. Equivalent controls across those routes are essential because enterprises increasingly use the same model through multiple vendors. A weak cloud path would undermine the stricter direct service. Contracts need to identify which party operates detection, who can change it and how incidents move between customer, model provider and cloud provider.

Customer security and compliance teams remain responsible for reviewing flags and deciding whether activity is authorized, harmful or compromised.
Customer security and compliance teams remain responsible for reviewing flags and deciding whether activity is authorized, harmful or compromised.

Human Review Moves Inside the Institution

Anthropic's design recognizes that the person permitted to inspect a flag matters. Legal documents may be privileged. Drug-safety reports, financial records and critical-infrastructure data may be restricted to cleared employees. Sending those materials to a provider's reviewer can create a second exposure even when the review is well intentioned. EFS keeps that judgment with the customer's own trained personnel.

Internal review is not automatically independent. A business unit may have incentives to dismiss a flag or continue a valuable workflow. Strong governance should define escalation thresholds, preserve evidence and involve compliance or security officers who are not responsible for shipping the project. Boards and regulators may also need aggregate reporting about significant events and the effectiveness of monitoring.

Automated detection must be evaluated for both misses and false alarms. A system that flags ordinary research too often will be bypassed. One that recognizes only obvious prompts will miss campaigns split across tools and accounts. Anthropic should provide customers with validation methods, change logs and metrics segmented by risk type. Because the detector handles sensitive context, its own access and update process should be auditable.

The launch also sets a policy precedent. Frontier-model providers have often argued that retention and centralized monitoring are necessary for safety. Regulated customers have argued that central retention can itself be unsafe. EFS shows that these goals need not be collapsed into one provider-controlled database. Technical architecture can distribute authority while preserving detection, though it cannot eliminate the governance choices around it.

Eligibility will matter. Anthropic says access will roll out gradually with broad availability as a goal later in the fall. If EFS becomes a prerequisite for frontier models, smaller companies may face cloud and staffing costs they cannot absorb. Providers should offer managed patterns that preserve customer control without requiring every organization to build a security operations program from scratch.

Data location is only one part of privacy. The detector still processes activity, and customers need to understand which components run in their account, which code Anthropic can update and what metadata leaves the environment. Network diagrams, threat models and independent assessment should accompany the product. Customer-managed keys are valuable, but they do not answer every question about who can execute software against the protected data.

Retention periods should match the threat rather than defaulting silently. A longer window can reveal a campaign spread over weeks, while it increases the amount of sensitive material exposed to an account compromise. Organizations may need different periods for code, legal work and ordinary business use. EFS should let policy follow workspace and data class, with deletion that can be verified after the window closes.

The distinction between activity data and enterprise content may blur. A monitoring record can include prompts, model responses, tool names, user identities and derived risk scores. Even when the underlying document remains elsewhere, that metadata can reveal investigations, clients or strategic projects. Security teams should classify and protect monitoring stores as sensitive systems in their own right rather than treating them as routine logs.

Cross-cloud consistency will be tested during incidents. If a campaign spans direct Claude access, Bedrock and another platform, separate logs may prevent the pattern from being recognized. Customers need a way to correlate identity and activity across those routes without centralizing all content at Anthropic. Common identifiers and customer-controlled aggregation could preserve the architectural split while improving detection across the full estate.

Regulators may view the system as evidence that privacy and misuse monitoring can coexist, raising expectations for other providers. They should avoid prescribing one vendor's architecture. The principle is more general: retain only what detection requires, keep custody aligned with legal responsibility, automate analysis where possible and put consequential review in accountable hands. Different technical designs can satisfy that principle if their controls are testable.

The product does not end the debate over retention; it makes the tradeoff more legible. Customers can see where activity data sits, who holds the keys, which automated system reads it and who receives the result. That clarity is more valuable than a blanket promise of privacy or safety. Frontier AI is moving into institutions where both claims must survive audit, and architecture is becoming the place where those promises are tested.

Topics: Anthropic, Enterprise Frontier Safeguards, privacy, AI governance, cloud security