Anthropic Launches Enterprise Frontier Safeguards to Shift AI Data Custody to Customers
The new framework allows regulated industries to monitor AI misuse while maintaining total control over sensitive activity data.
Anthropic has introduced Enterprise Frontier Safeguards (EFS), a new framework designed to let organizations monitor AI misuse without the provider retaining sensitive activity data. The move aims to eliminate the privacy and compliance hurdles that have historically slowed the adoption of frontier AI models in highly regulated sectors.
Under the EFS system, monitoring data is stored directly in cloud infrastructure controlled by the customer, such as Google Cloud Storage, Amazon S3, or Azure Blob Storage. To ensure security, this data is protected using the customer's own encryption keys. EFS combines zero data retention (ZDR) with automated safeguards to detect high-risk misuse patterns, specifically targeting the development of biological capabilities or offensive cyber attacks. When the system flags suspicious activity, the alert is sent directly to the customer's internal team for review, removing the need for human reviewers at Anthropic to access the data.
The Shift Toward Customer Custody
This announcement follows a similar trend by OpenAI to limit data retention while maintaining abuse detection. The industry is moving toward a model of "provider-side zero data retention alongside customer-custodied retention," a shift specifically tailored for the finance and healthcare industries. These sectors often face strict governance requirements that make traditional AI data handling unacceptable.
According to Jaishiv Prakash, a director analyst at Gartner, this shift is critical because it "neutralizes the compliance barriers that have prevented highly regulated enterprises from adopting frontier AI models."
Operational Trade-offs
While EFS removes a significant regulatory barrier, it shifts the operational burden of security from the provider to the user. Enterprises will now be responsible for the triage of alerts and the subsequent incident response, necessitating investments in specialized staffing and AI-specific runbooks.
Furthermore, analysts warn that data custody is not the same as total control. Sanchit Vir Gogia, chief analyst at Greyhound Research, noted that "custody should not be confused with visibility," pointing out that Anthropic still operates the detector and defines the underlying safety framework. This means enterprises must continue to trust the provider's detection logic even if they own the resulting data.
Rollout and Availability
Anthropic will not charge for the EFS feature, although customers must cover their own cloud infrastructure costs. The framework will be supported across a wide array of platforms, including Claude Enterprise, Claude Code, the Claude Platform, Microsoft Foundry, Google’s Agent Platform, and Amazon Bedrock.
The feature is scheduled to roll out in phases to eligible customers, with the goal of broad availability later this fall.