Model safety is becoming an enterprise architecture layer, not just a provider policy
Anthropic's Enterprise Frontier Safeguards split custody: the provider runs misuse detection, the customer holds the data, keys and review. Who does what, and what it costs you.
Listen to this article · 6 min
AI-generated narration of the full article.

Regulated enterprises have been caught in a contradiction. Detecting serious misuse of a frontier model, such as stolen credentials or a cyberattack spread across many sessions, requires keeping data long enough to correlate it. Many of those same enterprises cannot let a model provider retain their data at all.
On September 1, Anthropic announced an attempt to resolve that contradiction with architecture rather than policy. Whatever you think of the specific product, the design pattern is worth understanding, because it moves real responsibilities onto the customer’s side.
What Anthropic announced
According to Anthropic, Enterprise Frontier Safeguards (EFS) combines the privacy of zero data retention with misuse detection by storing monitoring data in cloud infrastructure the customer controls:
- Activity data used for monitoring can live in the customer’s own cloud account, such as Amazon S3, Azure Blob Storage or Google Cloud Storage, under the customer’s encryption keys, access policies and audit logging.
- Automated systems analyze a rolling window of traffic for signals of serious misuse. Flags go directly to the customer, and no human review by Anthropic employees is required.
- Customer-owned storage, customer-managed keys and fully automated review are each opt-in. Anthropic says none of them change model behavior, API pricing or rate limits.
- Anthropic does not charge for EFS. The cloud provider bills storage, reads, writes and egress.
Context matters. Anthropic introduced 30-day data retention starting with Fable 5, and says many regulated customers found that difficult. EFS is its answer. It was developed, Anthropic says, with more than 100 customers across financial services, healthcare, manufacturing, telecom, law, retail and the public sector.
Status: EFS is rolling out in phases, starting later this fall. Eligible customers receive zero data retention on Fable 5 and Fable 5.1 until it is ready. Planned support covers Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Claude Platform on AWS, Google’s Agent Platform and Microsoft Foundry.
The pattern: a custody split
EFS is one instance of a broader shift. At DevDay on September 29, OpenAI described its own approach under “Private Intelligence”, including zero data retention with automated safety reviews. The details differ, but the direction is the same: safety monitoring is being redesigned so that it can coexist with strict data custody.
The model that emerges looks like this:
| Responsibility | Provider | Enterprise |
|---|---|---|
| Detection logic | Operates it | Configures what it opts into |
| Monitoring data | Does not hold it (in this design) | Stores, encrypts, controls access |
| Review of flags | Automated | Human review by its own cleared staff |
| Incident response | Supplies signals | Owns triage and remediation |
| Cost of storage | None | Pays its cloud provider |
This is a fair trade for many regulated organizations. It is also a trade. Custody comes with duties.
- Model traffic
- Automated misuse detection
- Monitoring data in customer storage
- Flags sent to the customer
- Review and response by customer staff
- Provider: Automated misuse detection
- Customer: Monitoring data in customer storage · Flags sent to the customer · Review and response by customer staff
Operated by the providerHeld and run by the customer
What moves onto your side
A monitoring data store. Someone has to own the storage account: retention period, encryption keys, who can read it, and how access is audited. It becomes one of your more sensitive data sets.
A review function. Flags go to your people. You need to decide who is cleared to review potentially sensitive content, under which rules, and within what timeframe. Several Anthropic customers quoted in the announcement point to this as the reason they wanted EFS: their reviewers must be their own staff.
An incident process. A flag about stolen credentials or offensive cyber activity is a security incident. It should arrive in your security operations workflow, not in an inbox.
Multi-cloud consistency. If you use models through more than one cloud, you want the same controls and the same review process everywhere. Anthropic says controls are designed to be equivalent across its direct offering and cloud partners; verify it for the surfaces you actually use.
What it does not do
EFS is not a compliance certification, and Anthropic does not present it as one. It gives you a structure in which your existing obligations can be met more easily. Deciding whether it meets yours remains a job for your security, privacy and legal teams.
What to do now
- Register interest if you are eligible and track the phased rollout; do not plan around dates that have not been published.
- Design the storage account now: which cloud account, which keys, which retention, which access policy.
- Name the review team and write the triage runbook before flags start arriving.
- Route flags into your SOC tooling and test the path with a simulated event.
The larger point is that “is this model safe to use?” is no longer a question only the provider can answer. More and more, the answer depends on how the enterprise has built its side of the system. See our 2026 stack guide for where this sits among the other controls.