On September 1, 2026, Anthropic announced Enterprise Frontier Safeguards, or EFS, an offering aimed at a problem that has quietly shaped every enterprise AI contract: whether a company can get the privacy of zero data retention and the safety of misuse monitoring at the same time. For years those two things pulled in opposite directions. EFS is Anthropic's attempt to stop making customers choose, and it arrived as a replacement for a data-retention policy that had drawn complaints from exactly the regulated customers Anthropic most wants to keep.
The mechanism is worth understanding on its own terms, because it is a design choice other frontier vendors will be asked about next.
The tradeoff every enterprise AI deal runs into
Two things enterprises want from a model vendor are, in their simplest forms, incompatible.
The first is zero data retention. A bank, a hospital or a law firm often needs a contractual guarantee that the vendor does not keep prompts and outputs. Under strict zero data retention, the vendor processes a request and holds nothing afterward. That is the posture regulated industries reach for by default.
The second is misuse monitoring. Frontier vendors watch for patterns that suggest their models are being used to do harm, and useful detection often needs to look across sessions and over time, not just at one request in isolation. That requires keeping some record of activity, which is precisely what zero data retention forbids.
So the standard enterprise negotiation became a straight trade. Choose zero data retention and give up the vendor's safety net, or accept retention and let the vendor hold your data. For a regulated customer, neither answer is comfortable.
The tradeoff EFS is built to break
Standard retention buys detection by holding your data. Zero data retention protects privacy by giving up detection. EFS aims to keep both.
| Dimension | Standard retention | Zero data retention | EFS |
|---|---|---|---|
| Misuse detection | Yes | No | Yes |
| Where activity data lives | Vendor | Nowhere | Customer cloud |
| Who holds the keys | Vendor | Not applicable | Customer |
| Who runs human review | Vendor | No review | Customer |
Source: reporting on Anthropic Enterprise Frontier Safeguards, September 2026. Simplified for comparison.
What EFS actually changes
EFS reframes the question from what data is kept to who holds it. Instead of Anthropic storing the activity data its safeguards produce, the customer stores it, in the customer's own cloud account, under the customer's own encryption keys and access policies. Anthropic keeps the detection logic. The customer keeps custody.
Concretely, activity data lands in infrastructure the customer controls, whether that is Amazon S3, Azure Blob Storage or Google Cloud Storage, billed to the customer by the cloud provider like any other storage. Anthropic's misuse detection runs and can flag suspected abuse, but the record of what happened, the keys to read it and the human review of any flag sit with the customer, not the vendor.
AnthropicThe split is the whole idea. Detection is a capability that benefits from staying central and current at the vendor. Custody is a liability that regulated customers want to hold themselves. EFS separates the two so that neither has to be surrendered to get the other.
EFS splits detection from custody
The safeguard logic stays with Anthropic. The data it produces lands in storage the customer owns.
- Misuse detection models
- Cross-session pattern analysis
- The safeguard that flags abuse
- Where the data lives (S3, Azure Blob, GCS)
- The encryption keys
- Access policy and human review
Source: Anthropic Enterprise Frontier Safeguards announcement, September 2026.
Anthropic says it co-developed EFS with more than 100 customers before launch, including a cluster of large financial institutions, and that it does not charge for the feature itself, with customers instead paying their own cloud provider for the storage, reads, writes and egress the data generates. The rollout is phased, beginning in the fall of 2026 rather than switching on for everyone at once.
EFS reframes the question from what data is kept to who holds it. Anthropic keeps detection. The customer keeps custody.
The core design choice behind Enterprise Frontier Safeguards
Why this arrived now
EFS did not appear in a vacuum. It replaces an earlier data-retention policy that generated pushback, particularly from regulated industries whose compliance teams could not accept a vendor holding their activity data. Read charitably, EFS is a direct answer to that feedback: rather than argue about retention windows, Anthropic moved the data out of its own perimeter entirely. Read more skeptically, it is a way to keep running safety monitoring on enterprise traffic while removing the customer's strongest objection to it. Both descriptions fit the same facts, and which one an observer emphasizes tends to track how they feel about vendor-side monitoring in general.

The parts that are genuinely resolved, and the parts that are not
It is worth being precise about what EFS settles. It settles custody. A customer that adopts EFS can tell its regulator that activity data lives in its own cloud, under its own keys, with its own access controls, which is a materially stronger position than trusting a vendor's retention promise. That is a real improvement for compliance, and it is not a cosmetic one.
What EFS does not remove is the monitoring itself. Detection still runs on the customer's traffic, because that is the point of a safeguard. EFS changes where the resulting data is stored and who can read it, not whether the analysis happens. An organization that objects to vendor-side misuse analysis on principle is not fully served by EFS, because the analysis is still Anthropic's. What it gains is control over the artifacts that analysis produces.
There is also a quieter shift in responsibility. Holding your own activity data means securing it, managing keys, setting retention and access policy, and absorbing the storage and egress costs. For a large bank with a mature cloud practice, that is routine. For a smaller enterprise, custody is a benefit that comes with operational weight it did not previously carry. EFS moves a burden as much as it removes one, and whether that trade is worth it depends on how regulated and how capable the customer is.
What it signals for the rest of the market
The most durable thing about EFS may be the pattern rather than the product. It is an example of a frontier vendor conceding that, for serious enterprise customers, control over data is not a feature to be granted grudgingly but a precondition for the deal. That principle generalizes well beyond one vendor's misuse logs. The same instinct that makes a bank want its Claude activity data in its own bucket makes any serious organization want its prompts, its outputs and its records of AI use to sit somewhere it controls and can move.
That is the same reasoning that favors keeping the application layer portable rather than fused to a single provider. Platforms built so that an organization's data and workflows are not trapped inside one vendor's systems, the way Metir AI keeps the underlying model a swappable choice rather than a fixed dependency, extend the logic of EFS from safety logs to the whole stack. EFS answers one specific version of the data-control question. The broader version, who holds the data your AI use generates, is one every enterprise buyer is now learning to ask before signing.
What to watch next
Three signals will show whether EFS becomes a norm or stays a differentiator. The first is whether other frontier vendors ship a comparable customer-custody option, which would turn data location from a competitive edge into table stakes. The second is how quickly the co-development banks move from design partner to production user, since a named reference in regulated finance is what makes the rest of that sector follow. The third is whether regulators start treating customer-held activity data as an expectation rather than a bonus, which would push the whole industry toward the split EFS describes. For now, EFS is a concrete answer to a tradeoff enterprises have lived with for years, and the answer is that you should not have to pick.
Sources:
- Anthropic Announces Enterprise Frontier Safeguards, Customer-Held Data (Unite.AI, Sept 2026)
- Anthropic changes data retention policy after pushback from customers (CNBC, Sept 1, 2026)
- Anthropic's Enterprise Frontier Safeguards lets your Claude logs stay in your cloud (Help Net Security, Sept 2, 2026)
- Anthropic Introduces Enterprise Frontier Safeguards (EFS): Zero-Data-Retention Privacy Plus Cross-Session Misuse Detection (MarkTechPost, Sept 2, 2026)
- Anthropic's EFS Lets Banks Keep Claude Logs in Their Own Clouds (AI Weekly, Sept 2026)
Image credits
Header and in-body photograph: server racks in a data center by Carl Lender, via Wikimedia Commons, licensed under CC BY 2.0.