On September 1, Anthropic announced Enterprise Frontier Safeguards, an architecture in which Claude activity logs are stored in customer-controlled cloud infrastructure rather than Anthropic’s. Automated misuse detection is intended to continue alongside that arrangement.
For regulated organisations, this addresses a concrete conflict. Security teams need an agent activity record, but they may be unwilling to give the model provider a retained copy of sensitive prompts and outputs.
EFS remains an announced architecture rather than a broadly available capability. Phased access begins later this fall, so it cannot yet be treated as proven across a wide range of corporate systems.
Where the data will live
Anthropic says activity data can stay in a customer account on AWS, Google Cloud or Microsoft Azure. The company can use customer-managed encryption keys and govern staff access to its logs.
Customer-controlled storage is not the same as operating without cloud services. Requests are still processed by an external model provider, while the cloud platform bills the customer for storage, reads, writes and data transfer.
How misuse detection stays in the design
EFS is intended to analyse activity automatically and flag signs of prohibited use. Customer-owned storage, customer-managed keys and automated review are separate opt-ins; Anthropic says they do not change API prices or rate limits.
As TechCrunch explained, clients control how monitoring takes place even though the system continues looking for misuse by people or agents. That is not the absence of analysis: it changes where data is retained and who controls access to the result.
Questions to settle before adoption
A corporate buyer needs four precise answers: which events are recorded, how long they remain, what signal can trigger human review and who can export or delete the log. “Zero retention by the provider” does not answer those questions by itself.
EFS must also be separated from the model release. Anthropic’s Claude Fable page describes Fable 5.1 and its prices, while the safeguards have their own availability schedule. Buying model access does not automatically provide EFS.
An architectural promise awaiting operational evidence
Axios framed the system as an attempt to resolve the conflict between misuse safeguards and corporate privacy requirements. Its reporting notes that security and data terms have become as important to a model release as capability and price.
For a buyer, the decisive test starts with the first deployments: can a company reconstruct an agent’s full chain of actions without giving the provider a permanent copy of business data? Until technical terms and operating experience are public, EFS is a substantial promise, but still a promise.



