Anthropic introduces EFS to protect AI data
Anthropic announces Enterprise Frontier Safeguards, a system that combines zero data retention with automated detection of misuse. Companies will be able to store records in their own cloud infrastructure, with their own keys and access permissions, while Anthropic's systems look for signs of fraud, attacks and compromised credentials.

Anthropic has announced Enterprise Frontier Safeguards (EFS), a system that lets companies use its most advanced models without giving Anthropic control over the data they generate. Activity is stored in each customer's cloud infrastructure, not on Anthropic's systems.
The goal is to resolve a common conflict for regulated companies: they need strict privacy, but also tools capable of detecting fraud, attacks and dangerous uses of AI. EFS aims to provide both.
What changes with Enterprise Frontier Safeguards
Until now, companies had to choose between zero data retention, known as ZDR, and more comprehensive monitoring systems. The problem is that detecting a sophisticated attack often requires analyzing information over several days and linking activity across different sessions and accounts.
Anthropic began applying 30-day data retention with Fable 5, according to the company, not to train its models but to identify patterns of abuse. Anthropic says it has never trained on enterprise data without explicit permission and will not do so.
EFS changes the architecture. Activity logs can be stored in the company's cloud account, for example in Amazon S3, Azure Blob Storage or Google Cloud Storage. The customer retains its encryption keys, access permissions and audit logs.
That means a bank can keep records in its own environment, under its own policies, while Anthropic's automated systems analyze signals of potential misuse.
What it can detect
The system looks for patterns associated with serious uses of the models, such as:
- Attempts to develop offensive cyber or biological capabilities.
- Stolen or leaked credentials.
- Attacks that unfold across multiple sessions and accounts.
- Anomalous behavior from agents capable of acting autonomously.
When a relevant signal appears, the alert is sent directly to the customer. Anthropic does not need to conduct a human review of the data: the company's team decides how to investigate the case and who can access the information.
This point is especially important for sectors such as banking, healthcare and legal services, where an outside party might not be authorized to view privileged information, medical data or non-public financial information.
Designed with more than 100 companies
Anthropic says it developed EFS alongside more than 100 customers from sectors including financial services, healthcare, manufacturing, telecommunications, retail, law and government. It also worked with Amazon Web Services, Google Cloud and Microsoft Azure.
The organizations it names as participants include Wells Fargo, Comcast, KPMG, Mastercard, Salesforce, Visa, Snowflake and Stripe. The collaboration involved security, regulatory compliance, product and operations teams.
The central message from these companies was straightforward: they want to use frontier models without adding another provider to safeguard their sensitive data or forcing their teams to give up their internal controls.
Where it will be available
EFS will roll out gradually, and the company expects to expand availability later in the fall. It will be compatible with:
- Claude Code and Claude Enterprise.
- Claude Platform.
- Amazon Bedrock and Claude Platform on AWS.
- Google Agent Platform.
- Microsoft Foundry.
Customer-managed storage, customer-managed encryption keys and fully automated review will be optional. They will not change model behavior, API pricing or usage limits.
Anthropic will not charge for EFS. If a company stores the data in its own cloud account, it will pay its provider for storage, read and write operations and data egress, as it does for any other resource.
Until EFS is ready, eligible customers will receive zero data retention for Fable 5 and Fable 5.1, according to the announcement.
For you, the change matters most if you work with regulated or confidential information: AI will be able to analyze activity to detect abuse, but the records will remain inside the environment controlled by your organization. The next step will be seeing whether this model can maintain effective detection without requiring companies to give up custody of their data.