metir
metir
Docs
Download on App StoreGet it on Google PlayLoginSign Up
Back to Blog
Anthropic
Enterprise AI
Data Privacy
AI Governance
Claude

Anthropic's Enterprise Frontier Safeguards, Explained

Anthropic replaced a contested data-retention policy with Enterprise Frontier Safeguards, which keeps misuse detection at Anthropic while activity data lives in the customer's own cloud. A neutral look at the privacy-versus-monitoring tradeoff it is trying to break.

Metir AI TeamSeptember 2, 20268 min read
Anthropic's Enterprise Frontier Safeguards, Explained

On September 1, 2026, Anthropic announced Enterprise Frontier Safeguards, or EFS, an offering aimed at a problem that has quietly shaped every enterprise AI contract: whether a company can get the privacy of zero data retention and the safety of misuse monitoring at the same time. For years those two things pulled in opposite directions. EFS is Anthropic's attempt to stop making customers choose, and it arrived as a replacement for a data-retention policy that had drawn complaints from exactly the regulated customers Anthropic most wants to keep.

The mechanism is worth understanding on its own terms, because it is a design choice other frontier vendors will be asked about next.

Sept 1, 2026EFS announcedreplacing the prior retention policy
100+Enterprise customersco-developed the design
$0Anthropic's charge for EFScustomers pay their own cloud bill
3Supported cloudsS3, Azure Blob, Google Cloud Storage

The tradeoff every enterprise AI deal runs into

Two things enterprises want from a model vendor are, in their simplest forms, incompatible.

The first is zero data retention. A bank, a hospital or a law firm often needs a contractual guarantee that the vendor does not keep prompts and outputs. Under strict zero data retention, the vendor processes a request and holds nothing afterward. That is the posture regulated industries reach for by default.

The second is misuse monitoring. Frontier vendors watch for patterns that suggest their models are being used to do harm, and useful detection often needs to look across sessions and over time, not just at one request in isolation. That requires keeping some record of activity, which is precisely what zero data retention forbids.

So the standard enterprise negotiation became a straight trade. Choose zero data retention and give up the vendor's safety net, or accept retention and let the vendor hold your data. For a regulated customer, neither answer is comfortable.

The tradeoff EFS is built to break

Standard retention buys detection by holding your data. Zero data retention protects privacy by giving up detection. EFS aims to keep both.

DimensionStandard retentionZero data retentionEFS
Misuse detectionYesNoYes
Where activity data livesVendorNowhereCustomer cloud
Who holds the keysVendorNot applicableCustomer
Who runs human reviewVendorNo reviewCustomer

Source: reporting on Anthropic Enterprise Frontier Safeguards, September 2026. Simplified for comparison.

What EFS actually changes

EFS reframes the question from what data is kept to who holds it. Instead of Anthropic storing the activity data its safeguards produce, the customer stores it, in the customer's own cloud account, under the customer's own encryption keys and access policies. Anthropic keeps the detection logic. The customer keeps custody.

Concretely, activity data lands in infrastructure the customer controls, whether that is Amazon S3, Azure Blob Storage or Google Cloud Storage, billed to the customer by the cloud provider like any other storage. Anthropic's misuse detection runs and can flag suspected abuse, but the record of what happened, the keys to read it and the human review of any flag sit with the customer, not the vendor.

Anthropic logoAnthropic
AWS logoAWS
Azure logoAzure
Google Cloud logoGoogle Cloud
EFS lets an enterprise keep its Claude activity data in its own AWS, Azure or Google Cloud account, under its own keys, rather than in Anthropic's systems.

The split is the whole idea. Detection is a capability that benefits from staying central and current at the vendor. Custody is a liability that regulated customers want to hold themselves. EFS separates the two so that neither has to be surrendered to get the other.

EFS splits detection from custody

The safeguard logic stays with Anthropic. The data it produces lands in storage the customer owns.

Stays with Anthropic
  • Misuse detection models
  • Cross-session pattern analysis
  • The safeguard that flags abuse
Stays with the customer
  • Where the data lives (S3, Azure Blob, GCS)
  • The encryption keys
  • Access policy and human review
Detection output flows one way, from Anthropic into the customer-controlled bucket. Custody never moves back.

Source: Anthropic Enterprise Frontier Safeguards announcement, September 2026.

Anthropic says it co-developed EFS with more than 100 customers before launch, including a cluster of large financial institutions, and that it does not charge for the feature itself, with customers instead paying their own cloud provider for the storage, reads, writes and egress the data generates. The rollout is phased, beginning in the fall of 2026 rather than switching on for everyone at once.

“

EFS reframes the question from what data is kept to who holds it. Anthropic keeps detection. The customer keeps custody.

The core design choice behind Enterprise Frontier Safeguards

Why this arrived now

EFS did not appear in a vacuum. It replaces an earlier data-retention policy that generated pushback, particularly from regulated industries whose compliance teams could not accept a vendor holding their activity data. Read charitably, EFS is a direct answer to that feedback: rather than argue about retention windows, Anthropic moved the data out of its own perimeter entirely. Read more skeptically, it is a way to keep running safety monitoring on enterprise traffic while removing the customer's strongest objection to it. Both descriptions fit the same facts, and which one an observer emphasizes tends to track how they feel about vendor-side monitoring in general.

Rows of server racks and cabling inside a data center hall
Under EFS, the activity data Anthropic's safeguards produce is written to storage the customer owns and controls, rather than to Anthropic's own systems. Photo: Carl Lender, CC BY 2.0, via Wikimedia Commons.

The parts that are genuinely resolved, and the parts that are not

It is worth being precise about what EFS settles. It settles custody. A customer that adopts EFS can tell its regulator that activity data lives in its own cloud, under its own keys, with its own access controls, which is a materially stronger position than trusting a vendor's retention promise. That is a real improvement for compliance, and it is not a cosmetic one.

What EFS does not remove is the monitoring itself. Detection still runs on the customer's traffic, because that is the point of a safeguard. EFS changes where the resulting data is stored and who can read it, not whether the analysis happens. An organization that objects to vendor-side misuse analysis on principle is not fully served by EFS, because the analysis is still Anthropic's. What it gains is control over the artifacts that analysis produces.

There is also a quieter shift in responsibility. Holding your own activity data means securing it, managing keys, setting retention and access policy, and absorbing the storage and egress costs. For a large bank with a mature cloud practice, that is routine. For a smaller enterprise, custody is a benefit that comes with operational weight it did not previously carry. EFS moves a burden as much as it removes one, and whether that trade is worth it depends on how regulated and how capable the customer is.

What it signals for the rest of the market

The most durable thing about EFS may be the pattern rather than the product. It is an example of a frontier vendor conceding that, for serious enterprise customers, control over data is not a feature to be granted grudgingly but a precondition for the deal. That principle generalizes well beyond one vendor's misuse logs. The same instinct that makes a bank want its Claude activity data in its own bucket makes any serious organization want its prompts, its outputs and its records of AI use to sit somewhere it controls and can move.

That is the same reasoning that favors keeping the application layer portable rather than fused to a single provider. Platforms built so that an organization's data and workflows are not trapped inside one vendor's systems, the way Metir AI keeps the underlying model a swappable choice rather than a fixed dependency, extend the logic of EFS from safety logs to the whole stack. EFS answers one specific version of the data-control question. The broader version, who holds the data your AI use generates, is one every enterprise buyer is now learning to ask before signing.

What to watch next

Three signals will show whether EFS becomes a norm or stays a differentiator. The first is whether other frontier vendors ship a comparable customer-custody option, which would turn data location from a competitive edge into table stakes. The second is how quickly the co-development banks move from design partner to production user, since a named reference in regulated finance is what makes the rest of that sector follow. The third is whether regulators start treating customer-held activity data as an expectation rather than a bonus, which would push the whole industry toward the split EFS describes. For now, EFS is a concrete answer to a tradeoff enterprises have lived with for years, and the answer is that you should not have to pick.

Sources:

  • Anthropic Announces Enterprise Frontier Safeguards, Customer-Held Data (Unite.AI, Sept 2026)
  • Anthropic changes data retention policy after pushback from customers (CNBC, Sept 1, 2026)
  • Anthropic's Enterprise Frontier Safeguards lets your Claude logs stay in your cloud (Help Net Security, Sept 2, 2026)
  • Anthropic Introduces Enterprise Frontier Safeguards (EFS): Zero-Data-Retention Privacy Plus Cross-Session Misuse Detection (MarkTechPost, Sept 2, 2026)
  • Anthropic's EFS Lets Banks Keep Claude Logs in Their Own Clouds (AI Weekly, Sept 2026)

Image credits

Header and in-body photograph: server racks in a data center by Carl Lender, via Wikimedia Commons, licensed under CC BY 2.0.

Ready to experience AI that adapts to you?

metir brings together the world's best AI models in one seamless experience. Start for free today.

Get Started Free
metir

Agentic Operating System for Professionals buried in meetings, emails and docs.

© 2026 metir. All rights reserved.

Product

  • Features
  • Pricing
  • Research
  • Docs
  • Blog
  • Enterprise

Company

  • Docs
  • Support
  • Careers

Legal

  • Terms of Service
  • Privacy Policy

Personalisation is powerful. Privacy is non-negotiable.

Status: All systems operational